How is access to Salesforce Files controlled, and how does it relate to record sharing?
Suggested answer
Files have their own sharing surface. A file is linked to a record or a user through a ContentDocumentLink, and two fields on that link do the work:
1. ShareType: Viewer, Collaborator, or Inferred, where Inferred derives the permission from access to the linked record.
2. Visibility: whether the link is exposed to internal users, all users, or only shared users.
The relationship to record sharing is the part that catches people out. Access to a file posted on a record generally follows access to the record, but a file can also be shared directly with users or libraries, which means it can end up more widely accessible than the record it was uploaded against.
In a security review I always check files separately: a confidentiality requirement that is carefully implemented on Opportunity records means very little if the contract PDFs are in a library everyone can read.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.