A system administrator needs to restrict access so that users can only see records owned by them or their subordinates. Which sharing setting should be configured?
Trap 1: Set OWD to Public Read Only
Public Read Only grants all users access to view every record in the object regardless of ownership. This setting fails to meet the requirement of restricting access to only the user's records and their subordinates, as it effectively opens data visibility to the entire organization, violating the principle of least privilege.
Trap 2: Enable Grant Access Using Hierarchies
Enabling this setting is necessary for the role hierarchy to function, but it is not sufficient on its own. If OWD is set to Public Read/Write, access is already open to everyone. You must first restrict the base access level via OWD before the hierarchy can effectively filter record visibility.
Trap 3: Create a Permission Set for view access
Permission Sets are designed to extend functional access, such as viewing specific tabs or executing apex classes. They cannot be used to restrict record-level visibility in the manner required here. Record visibility is governed by OWD, sharing rules, and roles, not by profile or permission set-based object permissions.
- A
Set OWD to Public Read Only
Why it fails: Public Read Only grants all users access to view every record in the object regardless of ownership. This setting fails to meet the requirement of restricting access to only the user's records and their subordinates, as it effectively opens data visibility to the entire organization, violating the principle of least privilege.
- B
Enable Grant Access Using Hierarchies
Why it fails: Enabling this setting is necessary for the role hierarchy to function, but it is not sufficient on its own. If OWD is set to Public Read/Write, access is already open to everyone. You must first restrict the base access level via OWD before the hierarchy can effectively filter record visibility.
- C
Set OWD to Private
Setting OWD to Private ensures that users can only access records they own. When 'Grant Access Using Hierarchies' is enabled by default for custom objects, users higher in the role hierarchy automatically gain access to records owned by subordinates, which directly fulfills the requirement for restricted, hierarchy-based visibility control.
- D
Create a Permission Set for view access
Why it fails: Permission Sets are designed to extend functional access, such as viewing specific tabs or executing apex classes. They cannot be used to restrict record-level visibility in the manner required here. Record visibility is governed by OWD, sharing rules, and roles, not by profile or permission set-based object permissions.