A financial enterprise uses a custom object named Compliance_Audit__c to track sensitive regulatory investigations. The Organization-Wide Default (OWD) sharing setting for Compliance_Audit__c is configured as Private. Compliance auditors lower in the role hierarchy own these records, while regional managers receive record access via criteria-based sharing rules. Management requires that corporate executives positioned above regional managers in the Role Hierarchy must not automatically gain access to these audit records, even when access is granted to regional managers. What administrative action should be taken on the Compliance_Audit__c object to restrict automatic upward record exposure while preserving manual and rule-based sharing?
- Deselect the 'Grant Access Using Hierarchies' checkbox within the Organization-Wide Sharing Defaults for the custom object.Cevap
- BDisable the object-level 'Read' permission on the custom object profile assigned to corporate executive users.
- CModify the Organization-Wide Default (OWD) sharing setting for the custom object from Private to Controlled by Parent.
- DRemove the corporate executive roles from the organizational Role Hierarchy tree.
Cevap
Deselect the 'Grant Access Using Hierarchies' checkbox within the Organization-Wide Sharing Defaults for the custom object.
For custom objects in Salesforce, the 'Grant Access Using Hierarchies' setting is configurable. When deselected, users higher in the role hierarchy no longer inherit automatic access to records owned by or shared with subordinates, meeting the security requirement while preserving criteria-based sharing rule functionality.
Adım Adım Çözüm
Anahtar Kavram
Role Hierarchy and Sharing Rules Access Control