Soru

Zorluk: Çok zorRole Hierarchy and Sharing Rules

A financial enterprise uses a custom object named Compliance_Audit__c to track sensitive regulatory investigations. The Organization-Wide Default (OWD) sharing setting for Compliance_Audit__c is configured as Private. Compliance auditors lower in the role hierarchy own these records, while regional managers receive record access via criteria-based sharing rules. Management requires that corporate executives positioned above regional managers in the Role Hierarchy must not automatically gain access to these audit records, even when access is granted to regional managers. What administrative action should be taken on the Compliance_Audit__c object to restrict automatic upward record exposure while preserving manual and rule-based sharing?

  1. Deselect the 'Grant Access Using Hierarchies' checkbox within the Organization-Wide Sharing Defaults for the custom object.Cevap
  2. B
    Disable the object-level 'Read' permission on the custom object profile assigned to corporate executive users.
  3. C
    Modify the Organization-Wide Default (OWD) sharing setting for the custom object from Private to Controlled by Parent.
  4. D
    Remove the corporate executive roles from the organizational Role Hierarchy tree.

Cevap

Deselect the 'Grant Access Using Hierarchies' checkbox within the Organization-Wide Sharing Defaults for the custom object.
For custom objects in Salesforce, the 'Grant Access Using Hierarchies' setting is configurable. When deselected, users higher in the role hierarchy no longer inherit automatic access to records owned by or shared with subordinates, meeting the security requirement while preserving criteria-based sharing rule functionality.

Adım Adım Çözüm

1
Analyze the access requirement
The requirement mandates blocking automatic upward access inheritance via the role hierarchy for a custom object with Private OWD.
By default, Salesforce standard objects and custom objects grant access to managers higher in the role hierarchy whenever a subordinate owns or is granted access to a record.
2
Identify the standard sharing control for custom objects
For custom objects, the 'Grant Access Using Hierarchies' setting can be edited in Organization-Wide Sharing Defaults.
Disabling this option prevents superior role positions from inheriting record access automatically through hierarchy traversal.
3
Verify secondary impact on sharing rules
Criteria-based and owner-based sharing rules remain fully functional for designated target groups or roles.
Turning off hierarchy access only stops implicit vertical propagation; explicit sharing rules continue to operate as configured.

Anahtar Kavram

Role Hierarchy and Sharing Rules Access Control
Bu soruyu puanla