Security Flashcards
What controls access to applications and objects (including fields and record types)?
Profiles and Permission sets
What are the 4 capabilities available on an object via a profile?
Create
Read
Edit
Delete
What controls access to specific records?
OWD, sharing rules
What level of access can be granted at the record level?
Read or Read/Write
Do profile object permissions override the org’s sharing model or role hierarchy?
No, even with full CRED access – an object could not be edited/deleted if OWD is Read Only
What two settings are the exception when it comes to profile not being able to override sharing settings?
View All
Modify All
*these will override sharing settings and grant full access
What determines access to tabs and apps?
Profiles
What does ‘Default On’ mean for a tab?
It will be visible in the selected app
What does ‘Default Off’ mean for a tab?
It will be available to choose by user while they are customizing tabs
What does ‘Default Hidden’ mean?
Tab will not be visible for the object
What are six standard profiles?
Standard User Read Only System Administrator Marketing User Solution Manager Contract Manager
Can you assign permission sets via a user list view?
Yes
What is the purpose of permission sets?
To grant additional access to specific users so that profiles do not need to be altered/created
Can the OWD grant more access than object access defined in a user’s profile?
No
What two objects does the ‘Public/Read /Write/Transfer’ default apply to?
Leads and Cases
What is the purpose of OWD?
- The only mechanism that restricts access
- establishes default access to records NOT owned by the user
What does ‘Controlled by Parent’ mean?
Users can perform an action on a contact or order based on access on the parent object.
What does ‘Price Book: Use’ mean?
All users can view price books, add price books to opps, and add products in the price books to opps
What does ‘Price Book: View Only’ mean?
users can view price books – but only users with ‘Edit’ permission on opps or users that have been manually granted access can add price books to opps.
What does ‘Price Book: No Access’ mean?
Users do not have visibility to price books and cannot add them to opps unless it has been manually shared with them
What does ‘Activity: Private’ mean?
Only the owner of the activity and users above them in role hierarchy can edit and delete activity. Users that have read access to the record that is related to the activity can view it.
What does ‘Activity: Controlled by Parent’ mean?
Activity permissions are determined by the access the user has on the record related to the activity
What does ‘Campaign: Public Full Access’ mean?
Users can view, edit, transfer, delete, and report on all Campaign records
What does ‘Campaign Member: Controlled by Campaign’
Only users who access to the campaign are able to see the details of the campaign members related to the campaign