Suggested answer

When Salesforce evaluates whether a user can access a record, it follows this sequence:

1. System Access: System administrators and users with "View All Data" / "Modify All Data" permissions bypass all record-level access controls.
2. OWD: If Public Read/Write, all users have access. If Private, only the owner and higher role users can access by default.
3. Role Hierarchy: Users above the record owner in the hierarchy gain the access level defined by OWD (if "Grant Access Using Hierarchies" is enabled).
4. Sharing Rules: Criteria-based or ownership-based rules extend access to additional users/groups beyond what OWD and hierarchy provide.
5. Manual Sharing: Record owners or admins can share individual records with specific users or groups.
6. Apex Managed Sharing: Programmatic sharing logic via Share objects.

Important: Sharing can only expand access beyond OWD — it cannot restrict it below OWD. Object-level permissions (Profile/Permission Set) are evaluated first; even with record access, a user without the object's Read permission cannot see any records.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.