A banking company wants their customers Date of Birth Field searchable by Banking Reps, but only editable by Customer Support Reps. Which approach is recommended to meet this requirement?
Comprehensive and Detailed 150 to 250 words of Explanation From Platform Sharing and Visibility Architect/Course Guide/topics:
Field-Level Security is the authoritative mechanism because Banking Reps must be able to see the Date of Birth value while Customer Support Reps must additionally be able to edit it. Configuring the field as Visible but Read-Only for Banking Reps and Visible/Edit for Customer Support Reps enforces the requirement across Salesforce interfaces rather than only on one page. Search layouts and page layouts are presentation controls; they cannot override restrictive FLS and should not be used as the sole security boundary. A validation rule tied to a profile name would be brittle, would not address field visibility, and would embed authorization logic in a business rule that becomes difficult to maintain. The architect should implement the field permissions through the organization's profile/permission-set strategy and verify that no other permission set grants unintended edit access. Study Guide reference: Permissions to Standard Objects, Custom Objects, and Fields - Field-Level Security, search visibility, read-only fields, profiles, permission sets, and enforceable field authorization.
===============
Billi
1 day agoRenay
7 days ago