Suggested answer

They move in opposite directions.

A sharing rule is additive. It grants access to a population — a public group, role, role and subordinates, or territory — either based on record ownership or on field criteria. It can never take access away.

A restriction rule is subtractive. It defines a filter on an object for a set of users, and records that fail the filter become invisible to them even if ownership, hierarchy, a sharing rule, or a team would otherwise grant access.

I use sharing rules for the normal case: a restrictive baseline opened up for the populations that need it. I use restriction rules when a genuine exclusion is required on top of grants I cannot or should not remove — typically a confidentiality or regulatory carve-out, like contractors who must never see records under litigation hold.

Restriction rules are supported on a defined set of objects rather than universally, so I check current object support before committing to a design that depends on them.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.