What is the difference between View All Data, Modify All Data, and the object-level View All and Modify All permissions?
Suggested answer
View All Data and Modify All Data are system permissions on a profile or permission set. They bypass the sharing model on every object in the org. Modify All Data additionally permits deleting records the user cannot otherwise see, and mass transfer.
View All and Modify All are object permissions, granted per object. They bypass sharing for that object only.
The design guidance follows directly: when a requirement is "this person needs to see all Invoices", the answer is View All on Invoice, not View All Data. Scoping the bypass to the object bounds the damage if the account is compromised or the permission set is over-assigned.
I also treat both as audit items rather than configuration. Any assignment of View All Data or Modify All Data should have a named owner and a stated reason, because they are invisible in the sharing tables — a user with Modify All Data will not appear in any share row, which makes access troubleshooting misleading if you forget to check.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.