ADM-201 · Question #322
The Human Resources department at Northern Trail Outfitters wants employees to provide feedback about their managers using a custom object in Salesforce. It is important that managers are unable to…
The correct answer is B. Uncheck Grant Access Using Hierarchies. To prevent managers from viewing feedback records submitted by their staff on a custom object, the administrator must set the object's Organization-Wide Defaults to Private and uncheck 'Grant Access Using Hierarchies'.
Question
The Human Resources department at Northern Trail Outfitters wants employees to provide feedback about their managers using a custom object in Salesforce. It is important that managers are unable to see the feedback records from their staff. How should an administrator configure the custom object to meet this requirement?
Options
- ADefine a criteria-based sharing rule.
- BUncheck Grant Access Using Hierarchies.
- CConfigure an owner-based sharing rule.
- DSet the Default External Access to Private.
How the community answered
(34 responses)- A15% (5)
- B74% (25)
- C9% (3)
- D3% (1)
Why each option
To prevent managers from viewing feedback records submitted by their staff on a custom object, the administrator must set the object's Organization-Wide Defaults to Private and uncheck 'Grant Access Using Hierarchies'.
A criteria-based sharing rule is used to *grant* additional access to records beyond the OWD, not to restrict access that is otherwise inherited through the role hierarchy.
Unchecking 'Grant Access Using Hierarchies' for the custom object's Organization-Wide Defaults (OWD) prevents users in higher roles, such as managers, from automatically gaining access to records owned by users below them in the role hierarchy, thereby securing staff feedback from their managers.
An owner-based sharing rule also *grants* additional access to records based on their owner, and does not restrict the default hierarchical access for managers.
Setting the Default External Access to Private applies to guest users or external portal/community users, and does not control internal access based on the role hierarchy for employees.
Concept tested: Salesforce record sharing and role hierarchy
Source: https://help.salesforce.com/s/articleView?id=sf.security_org_wide_defaults_options.htm&type=5
Topics
Community Discussion
No community discussion yet for this question.