Suggested answer

The role hierarchy is the right tool when the access requirement genuinely follows management lines: a manager should see what their subordinates see, transitively, and that relationship is stable.

Public groups with sharing rules are the right tool for cross-cutting access that does not follow the org chart — a compliance function, a shared service desk, a regional overlay team.

The trade-offs:

1. Hierarchy access is automatic and transitive, which is powerful but blunt: you cannot grant a manager access to one subordinate's records and not another's.
2. Every hierarchy level multiplies the share rows maintained and recalculated, so depth has a measurable performance cost.
3. Hierarchy changes are disruptive, triggering recalculation and affecting forecasting and reporting, whereas group membership changes are comparatively contained.
4. Groups are explicit and auditable — a named group with named members is easier to review than an implicit grant three levels up.

The anti-pattern I watch for is roles created purely to grant record access, with no corresponding management relationship. That is a sharing rule wearing a costume, and it should be rewritten as one.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.