Suggested answer

I reach for Apex managed sharing only when the access rule cannot be expressed as a function of record data or ownership. The typical triggers are access that depends on data on a related record, on the result of an external lookup, or on a relationship that has no field on the record being shared.

Mechanically it means inserting rows into the object's __Share table with ParentId, UserOrGroupId, AccessLevel, and a RowCause set to a custom Apex sharing reason defined on the custom object. Using a custom reason matters: shares with RowCause Manual are deleted when ownership changes, whereas shares with a custom reason survive and can be recalculated in bulk by an Apex sharing recalculation class.

The cost is real. You own the recalculation logic, the bulkification, the test coverage, and the failure modes — a share that silently fails to insert is an access bug nobody notices until an audit. Custom Apex sharing reasons are also available for custom objects only.

So my rule is: try to normalise the requirement into a classification field first. If a formula or a small set of derived values can drive declarative rules, that is almost always the better long-term answer.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.