Suggested answer

Files have their own sharing surface. A file is linked to a record or a user through a ContentDocumentLink, and two fields on that link do the work:

1. ShareType: Viewer, Collaborator, or Inferred, where Inferred derives the permission from access to the linked record.
2. Visibility: whether the link is exposed to internal users, all users, or only shared users.

The relationship to record sharing is the part that catches people out. Access to a file posted on a record generally follows access to the record, but a file can also be shared directly with users or libraries, which means it can end up more widely accessible than the record it was uploaded against.

In a security review I always check files separately: a confidentiality requirement that is carefully implemented on Opportunity records means very little if the contract PDFs are in a library everyone can read.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.