Suggested answer

I would configure the dashboard with a running user who has the required record access. The components render using that user's access regardless of who views the dashboard, so the executives see aggregate figures without gaining any record access.

The risks are worth stating explicitly, because this is a sanctioned way to move data past the sharing model:

1. The folder access becomes the real security boundary. Whoever can open the dashboard sees the running user's data.
2. Drill-down and export can expose more than intended, so I check what a viewer can actually reach from each component.
3. The running user should be a purpose-built, governed account rather than a real person whose access changes when they move roles — otherwise the dashboard silently changes meaning.

If viewers should each see their own slice, that is a dynamic dashboard running as the logged-in user instead, which is a completely different control and should not be confused with the running-user pattern.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.