Suggested answer

Under the secure guest user access model, the guest user's organization-wide default is forced to Private and cannot be raised, and the guest user cannot own records.

Access to public data is granted through guest user sharing rules, which grant Read only. Guest users cannot be added to public groups, queues, teams, or ordinary sharing rules, and they cannot be given manual shares.

In design terms this means public data has to be a deliberate, enumerated set. I would model the publicly readable records as a distinct object or a clearly flagged subset, write a guest user sharing rule scoped to exactly that set, and then review it as a security artefact rather than as a convenience setting.

I would also note that guest user sharing rules count against the object's criteria-based sharing rule allocation, and that anything the guest user can reach should be assumed to be fully public, because it is.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.