Hi everyone,
I’m looking for some advice on a Salesforce security/architecture scenario.
We have a group of Sales users whose Account access is granted through criteria-based sharing rules based on the entity/company they work for
. For example, users belonging to different country entities receive access to the corresponding Accounts.
These users are also assigned to a Permission Set Group that grants Read access to a number of financial fields on the Account object
.
The business requirement is to restrict these users from creating or modifying Reports, exporting Report data, and accessing restricted company-wide financial Reports and Dashboards.
At the same time, they must retain their existing visibility when working with an individual Account they have access to, including the relevant financial information, Invoices and Orders.
This leads to a question around the same financial fields being available through different Salesforce surfaces.
If a user has FLS Read access to these Account fields so that they can see them on the Account Record Page:
Is there any standard/native Salesforce mechanism to prevent those fields from being available in List Views, while still allowing them to be displayed on the Account Record Page?
And regarding Reports:
If the user is allowed to run a centrally provided Report, is there a standard way to prevent the financial fields from being exposed through that Report while keeping the user's existing Account-level visibility?
We explored using Custom Report Types to exclude these financial fields from the layout. However, if an Inside Sales user runs a centrally provided Report built on a report type that does
include these fields (because Outside Sales and Management users share the reports and need them), Salesforce will render the data for the Inside Sales user too, as long as their FLS is active. Salesforce does not support dynamic column masking or role-based field filtering within a shared Report Type.
Or is the standard Salesforce security model that FLS applies globally across all these surfaces, with Report/Dashboard folder access and export permissions providing the only standard restrictions?
I’m interested specifically in the standard Salesforce capabilities, or is this only possible per custom and if yes, how? LWCs?
Thanks!
@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects, @Data Quality & Management
#Trailhead Challenges #Salesforce Developer #Salesforce Admin #Salesforce #Data Management
Hi @Lena Wong
Salesforce FLS applies globally, so if a user has Read access to a field, that field can generally be accessed through Record Pages, List Views, and Reports. There is no standard Salesforce feature to display a field on the Account Record Page while hiding the same field only from List Views or Reports. Custom Report Types can exclude fields, but they cannot dynamically hide fields based on the user's role when FLS grants access. Report and Dashboard folder permissions can restrict access to reports, but they do not provide field-level masking within a shared report. For surface-specific financial-data restrictions, a separate security/data model or a custom LWC/Apex solution would be required.