Suggested answer

I work from the record outward rather than guessing at configuration.

1. Open the record's Sharing action, which lists who has access and at what level, and the Sharing Hierarchy view, which shows what users derive through the role hierarchy.
2. Query the object's share table for that record and read the RowCause — it names the mechanism: Owner, Manual, Rule, Team, Territory, ImplicitChild, or a custom Apex sharing reason.
3. Query UserRecordAccess for that user and record to confirm the effective access level.
4. Check the user's object permissions for View All or Modify All, and their profile and permission sets for View All Data or Modify All Data, since those bypass sharing entirely and will not appear as share rows.
5. Check whether the access is implicit — a parent Account visible because they can see a child Case is expected behaviour, not a bug.

Only once I know the mechanism do I decide the remedy, because each one has a different fix and the wrong fix usually breaks access for somebody else.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.