Universal Containers (UC) has a custom object to track the internal net promoter score (NPS) for all of its employees. The manager is in the role above the owner and there are no sharing rules on the object. How should UC ensure that NPS records cannot be accessed by the owner's manager?
Comprehensive and Detailed 150 to 250 words of Explanation From Platform Sharing and Visibility Architect/Course Guide/topics:
For custom objects, Salesforce allows the administrator to disable automatic upward access through the role hierarchy by clearing Grant Access Using Hierarchies. With the NPS object's OWD set to Private and hierarchy access disabled, a manager does not gain access simply because the manager occupies a role above the record owner. This is the correct pattern for sensitive employee information when the reporting hierarchy itself must not imply visibility. Apex sharing should not be used to subtract access that is granted by another mechanism; Salesforce sharing is fundamentally additive. Removing all object permissions from managers would be too broad because it would block every NPS record, including records a manager might legitimately need through another explicit authorization process. The secure design establishes a restrictive baseline and then opens only the records that a specific business requirement justifies. Study Guide reference: Access to Records - Private OWD, Grant Access Using Hierarchies, custom-object hierarchy behavior, sensitive-record isolation, and least-privilege sharing.
===============
Currently there are no comments in this discussion, be the first to comment!