What are the most common sharing and visibility mistakes you have seen, and how do you prevent them?
Suggested answer
The ones I see repeatedly:
1. Treating page layouts as security. A field removed from a layout is still in the API and in reports. Prevented by making field-level security the only accepted answer to "hide this field".
2. Assuming with sharing enforces field-level security. It enforces record sharing only. Prevented by a code review standard requiring user-mode queries or stripInaccessible on anything returned to the client.
3. Starting with a permissive OWD and trying to claw access back with rules that cannot revoke. Prevented by starting Private and justifying every relaxation.
4. Profile sprawl — forty profiles differing in small ways. Prevented by minimal profiles plus a permission set library.
5. Roles created to grant access rather than to model management. Prevented by asking whether a public group and a sharing rule would express it more honestly.
6. Ignoring implicit sharing, then being surprised by parent Account visibility or by an account owner who cannot see child opportunities.
7. Leaving files, reports, and dashboards out of scope, so a carefully restricted object is undermined by an open folder or a running-user dashboard.
The preventive habit behind all of these is the persona matrix: writing down what each population should and should not see, then verifying it with evidence rather than assuming the configuration implies it.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.