Soru

Zorluk: ZorOrganization-Wide Defaults (OWD)

Northern Trail Outfitters uses a custom object named Executive_Sponsorship__c to manage confidential strategic client engagements. Business governance policies require that sales representatives are restricted to viewing only the records they own. Additionally, senior managers above the record owners in the role hierarchy must NOT automatically inherit view or edit privileges to these sensitive records. Which combination of Organization-Wide Default (OWD) settings on Executive_Sponsorship__c will satisfy these requirements?

  1. Set Default Internal Access to Private and deselect the 'Grant Access Using Hierarchies' checkbox on the object.Cevap
  2. B
    Set Default Internal Access to Private and leave the 'Grant Access Using Hierarchies' checkbox selected on the object.
  3. C
    Set Default Internal Access to Public Read-Only and modify manager Profiles to remove Read object permissions.
  4. D
    Set Default Internal Access to Private and assign a Permission Set Group to managers that revokes inherited sharing access.

Cevap

Set Default Internal Access to Private and deselect the 'Grant Access Using Hierarchies' checkbox on the Executive_Sponsorship__c custom object.
Setting the Default Internal Access of a custom object to Private restricts baseline record access so that non-owners cannot view records unless explicitly shared. Disabling the 'Grant Access Using Hierarchies' option (which is enabled by default for custom objects) prevents users higher in the role hierarchy from automatically inheriting access to records owned by or shared with their subordinates.

Adım Adım Çözüm

1
Determine the required baseline record visibility.
Since users should only see records they own, the Organization-Wide Default (OWD) Default Internal Access must be set to Private.
Private is the most restrictive OWD setting, preventing non-owners from viewing records unless granted access through sharing rules or manual sharing.
2
Evaluate role hierarchy sharing behavior for custom objects.
By default, Salesforce enables 'Grant Access Using Hierarchies' for all objects, allowing managers to access subordinate records.
For custom objects, administrators can deselect 'Grant Access Using Hierarchies' to prevent record access from automatically propagating up the role hierarchy.
3
Combine OWD baseline setting with hierarchy setting.
Setting OWD to Private and unchecking 'Grant Access Using Hierarchies' fulfills both security constraints.
This configuration restricts access strictly to record owners and explicitly disables management hierarchy access.

Anahtar Kavram

Organization-Wide Defaults (OWD) and Hierarchy Access Control on Custom Objects
Bu soruyu puanla