Admin Intermediate Flashcards
Is the security of your data protected if users get to it through the API?
Yes. Although you can configure the security and sharing model entirely using the user interface, the model works at the API level. That means any permissions you specify apply even if you query or update the data via API calls.
organization wide defaults
specify the default level of access users have to each other’s records
you use org-wise sharing settings to lock down your data to the most restrictive level, and then use the other record-level security and sharing tools to selectively give access to other users
role hierarchies
give access for users higher in the hierarchy to all records owned by users below them in the hierarchy
sharing rules
automatic exceptions to org-wide defaults for particular groups of users so they can get to records that don’t own or can’t normally see
4 levels at which you can configure access to data
organization
objects
records
fields
4 methods for controlling record level access
org-wide defaults
role hierarchy
sharing rules
manual sharing
can you delete a user?
no. but you can deactivate an account so a user can’t log in
deactivated users lose access to all records
profile vs. permission sets
profile: determines the objects a user can access and the things they can do with the object record
permission sets: grant additional permissions and access settings to a user