I am looking to implement a Role Hierarchy to lock down certain fields within our org. Starting with Opportunities and 1 team in North America. This will eventually grow to include global teams and other objects. I think I have a good foundtion but would like a second pair of eyes before I embark on this. I will give an example of the roles.
- GM -GM should be able to see and edit all opportunities.
- SVP - SVP should be able to see and edit all opportunities.
- East RVP should see all opportunities but only be able to edit all fields that are owned by the East team.
- West RVP should see all opportunities but only be able to edit all fields that are owned by the East team.
- East AE should see all opportunities but only be able to edit some fields that are owned by themselves. For example, East AE should not be able to edit Finance/Legal fields on the record they own but can edit all other fields.
- West AE should see all opportunities but only be able to edit some fields that are owned by themselves. For example, East AE should not be able to edit Finance/Legal fields on the record they own but can edit all other fields.
The steps I believe I should take are below but I greatly appreciatate any help.
- OWD should be updated to be more restrictive. Based on scenario we are currently working towards Opportunity Object should be Visible/Read Only.
- Determine profiles of each tier. Should remove edit permissions for those lower tiers on the profile to certain fields.
- Opportunity should be set to read only permission then if a user owns a record they can edit it but we only want them to be able to edit certain fields depending on their role?
- Roles will open up individuals records not fields so we actually need to use group permissions sets to achieve this. However even if they own a record we still want some fields not editable based on their role.
- Group permission sets - We will need to create the permission set to grant user edit access 50% of all fields on on the opportunity. Then another one granting sales users to another 25%. And another granting Finance 25% of the fields. Add those permissions sets to the necessary group permission set. Add the users to the group permission sets instead of assigning all individual permission sets to the users.
- I'm still not positive how we would open up edit ability based on who owns the record, it appears we can only open it up by the record as a whole not individual fields but I would like input on this. We are interested in reporting by teams so the rule of roles is still important to us.
6 件の回答
Hi John,
Looks like you have a pretty thorough understanding on how sharing works and what you need to setup. The one question that stood out is how to restrict edit based on ownership you can do this based on the OWD setting Private and if all users should see the Opportunities in that role but only edit if they own you should then add a sharing rule per role set to read only. Private will also allow Users in roles above others to edit records. Your role structure should look something like the below (Note indents equals role sitting underneath the previous one)Management (GM and SVP can use this one or you can choose to seperate it)
East RVP
East AE
West RVP
West AE
Sharing rule would be for the East AE role and West AE role will be able to read only all Opportunities