Suggested answer

I describe it as a series of gates, and access is granted if any one of them opens.

1. Ownership: The record owner has access, subject to object permissions.
2. Organization-wide defaults: The OWD is the baseline for everyone who is not the owner. It is the floor, and everything else only opens access further.
3. Role hierarchy: Users above the owner in the hierarchy inherit access, unless Grant Access Using Hierarchies has been deselected — which is only possible on custom objects.
4. Sharing rules: Ownership-based or criteria-based, granting to public groups, roles, roles and subordinates, or territories.
5. Teams: Account, opportunity, and case teams grant per-record access with a defined access level.
6. Manual and programmatic shares: Manual shares, and Apex managed shares written to the object's share table.
7. Implicit sharing: Platform-generated grants, most importantly read access to a parent Account when you can see a child Case, Contact, or Opportunity.
8. View All and Modify All: Object permissions that bypass all of the above for that object, and View All Data / Modify All Data which bypass it for every object.

Then I add the two things that sit outside the additive model: restriction rules, which subtract from whatever the above granted, and object and field permissions, which gate access before record sharing is even consulted.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.