Suggested answer

Big Objects deliberately omit the sharing model. There are no organization-wide defaults, no sharing rules, no manual shares, and no share table. Access is controlled by object and field permissions only — a user with permission can query the data, and a user without it cannot.

So a per-record confidentiality requirement cannot be met inside the Big Object. The options are:

1. Partition the data into separate Big Objects along the confidentiality boundary and control each with its own permission set.
2. Interpose a controlled access layer — an Apex service or Flow that applies the filtering and that users invoke instead of querying the object directly, with the object permission granted only to that layer's context.
3. Exclude the sensitive attributes from the archive altogether, keeping them in a standard object with a normal retention policy.

I would raise this early, because archiving projects tend to treat the destination as a storage decision when it is also an access-control decision.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.