What is the difference between object permissions, field-level security, and record-level sharing, and in what order do they apply?
Suggested answer
They are three independent layers, and a user needs all three to see data.
1. Object permissions decide whether the user can touch the object at all — Create, Read, Edit, Delete, plus View All and Modify All. Granted on profiles and permission sets.
2. Field-level security decides which fields of that object the user can read or edit. Also on profiles and permission sets, and enforced through the UI, reports, search, and the API.
3. Record-level sharing decides which rows the user sees, through the mechanisms in the sharing model.
In practice object permissions are evaluated first — no Read on Case means no cases regardless of sharing — then record access determines the row set, then FLS determines which columns come back.
The distinction I stress in design reviews is that page layouts are not in this list. A field removed from a layout is still returned by the API and by reports. If a field must be hidden, it has to be hidden with field-level security.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.