Suggested answer

I explain that sharing rules only grant, never revoke — there is no access level of None — and then I redirect the conversation to diagnosis, because the useful question is what is granting the access today.

1. If it is the organization-wide default, the fix is to tighten it and add rules for the populations that legitimately need access.
2. If it is the role hierarchy, and the object is custom, deselecting Grant Access Using Hierarchies may be right. On a standard object that option does not exist, so the answer is usually to restructure the hierarchy or accept it.
3. If it is an existing sharing rule or team, remove or narrow that rule.
4. If access must be subtracted while other legitimate grants stay in place, a restriction rule is the mechanism designed for it.
5. If it is View All Data or Modify All Data, no sharing configuration will help — those permissions have to go.

I use the record's Sharing action, the Sharing Hierarchy view, and a query on the share table to establish which of these it actually is, rather than guessing.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.