Mary is Joe's manager in the Role Hierarchy. The organization-wide default for a custom Invoice object is Public Read-Only, and Mary's profile is not granted the Read permission for the Invoice object. Which action can Mary take on Joe's invoice records?
Comprehensive and Detailed 150 to 250 words of Explanation From Platform Sharing and Visibility Architect/Course Guide/topics:
Mary has no effective access because object-level Read permission is a prerequisite for every record-level access mechanism. Public Read-Only OWD and the role hierarchy can determine which Invoice records a user may see only after the user is authorized to read the Invoice object itself. Mary's profile does not grant that permission, so neither the public OWD nor her position above Joe can make Joe's Invoice records available. Record sharing never substitutes for object CRUD. This is a core Salesforce security-order concept: object permissions establish whether a user can use an object, Field-Level Security determines which fields are available, and OWD, hierarchy, sharing rules, teams, and manual sharing determine which records are visible. Granting Read through a profile or permission set would be required before Public Read-Only or hierarchy-derived access could take effect. Study Guide reference: Permissions to Standard Objects, Custom Objects, and Fields - object CRUD, profiles, permission sets, OWD interaction, role hierarchy, and layered security evaluation.
===============
Augustine
1 day agoDaniel
7 days ago