Explain Salesforce sharing architecture including OWDs, role hierarchy, sharing rules, and Apex Managed Sharing.
Suggested answer
OWD (Organisation-Wide Defaults): Set the baseline access for all records of an object. Options: Private (only owner and those above in hierarchy), Public Read Only, Public Read/Write, Controlled by Parent. Stricter OWD = more sharing rules required but better security. OWD setting on high-volume objects (like Activities) has significant performance implications.
Role Hierarchy: Users higher in the hierarchy implicitly gain access to records owned by users below them (if "Grant Access Using Hierarchies" is enabled for the object). Does not apply to custom objects where the checkbox is disabled.
Sharing Rules (limit: 300 per object): Open up access beyond OWD for specific groups or criteria. Types: ownership-based (share records owned by Group A with Group B) and criteria-based (share records matching field criteria).
Apex Managed Sharing: Programmatic sharing using the Share object (e.g., AccountShare). Key fields: UserOrGroupId, AccessLevel (Read/Edit), RowCause (must be a custom Share Reason or the Manual value). All Apex Managed Sharing uses a custom RowCause to distinguish it from manual sharing. When the Share Reason is deleted, all associated sharing records are removed automatically.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.