How do you design a secure and scalable Experience Cloud (Community) architecture?
Suggested answer
User licensing: Choose the right licence type for your portal users (Customer Community, Customer Community Plus, Partner Community, External Apps). Customer Community is the cheapest but most restricted (no sharing rules, role hierarchy limited). Partner Community supports full sharing model. External Apps Plus is the most flexible.
Sharing and security: Set strict OWDs for objects exposed in the community. Use sharing sets (for Customer Community) or sharing rules (for Customer Community Plus/Partner) to control record access. Never rely on page layout to hide sensitive data — enforce FLS and OWD.
Performance: Enable CDN for community assets. Use Guest User caching where appropriate for public pages. Limit the number of components on high-traffic pages. Use lazy loading for data-heavy sections.
Scale: For high-traffic communities (100K+ users), enable community caching, use Lightning Web Runtime (LWR) for performance (faster than Aura communities), and ensure Apex code invoked from community actions is optimised for concurrent users.
Security: Audit guest user permissions carefully — they are unauthenticated. Disable "Public can read" OWD settings for all sensitive objects. Regularly review community sharing and CRUD permissions.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.