Skip to main content

Hey Community. 

 

I have what I thought was quite a simple requirement for a user permission.    

 

I have user a who is assigned a profile which provides read and view all for opportunities.  I have then assigned them to a permission set which provides all those profile users the ability to edit only 5 fields but on all record types.   

 

I then have a second permission set assigned only to this specific user which allows them to create and edit funding and legacy record type opportunities with full edit permission on all fields on those records types.   

 

However, they are still able to create opportunities of any record type and have full edit which we do not want.   

 

I have been researching this and the conclusion is that SF combines those permissions, taking the 'create and full edit' from one and 'all record types' from the other.  This does not make sense to me and I cannot believe that this is not achievable through permission sets. I feel as though I am missing something obvious. 

 

Does anyone have any suggestions on how to achieve this OOB.  

 

Many thanks 

Natalie Gorman 

 

#Security  #Permissionset

3 respuestas
  1. Hoy, 9:03

    @Rahul Chauhan

    , thank you.  I've used validation rules and custom permissions to achieve other rules but I don't think this is a practical solution for this one as we are effectively saying if they try to edit and save any of the fields bar 5 on the opportunity then prevent that.  I don't believe there is a way in a validation to say allow only these 5 fields,  and thererore I would have to list all the fields that they cannot edit - is that correct?  In which case there are too many fields and the managing of this if new fields were added to the opportunity doesn't make it a sensible option.   

     

    I think the only other alternative out of the box would be to have a seperate profile which we were trying to avoid. Do you agree that is the only other option without resorting to apex or such like?

0/9000