Skip to main content
Munira Majmundar (ICF) 님이 ADM201 Study Group에 글을 올렸습니다

Topic #Clarification needed on the privileges of Record Owners:

 

My understanding is that:

Record owners have full access to the records that they own. 

Full access means that they could read, edit, delete and share that record.

 

To confirm this I created a record of an object and then assigned ownership of that record to a user that only had Read object level access. Then I logged in as the owner.

The owner could only see the record and not edit. When I added edit object permissions, they could then edit.

 

So, do object level permissions always filter out records and restrict what a user can do to that record, even if owned by the user?

댓글 1개
  1. 2015년 10월 2일 오후 2:57

    Ok... got the answer. Mayank Srivastava helped me think through this. Here is the 9 yard - worth a read!

    Munira, think of Profile permissions to be the baseline permissions in Salesforce. They control what you can or cannot do with records. If an owner user's profile has Read access to an object's recod, they can only Read it. If they have Read +Edit , they can Read and Edit the record and not do anything further (Create , Delete).

    "Record owners have full access to the records that they own" - This is in regards to the Sharing Setting. So it an be interpreted as:

    Record owners have full access to the records that they own and what they can do with the record is defined by their Profile object permissions.

    So, you can give a user full access to Cases for Public Read/Write/Transfer but if their Profile permissions only grants them Read permission, the sharing rule won't be able to bypass that.

    My improved understanding after Mayank's help:

    Thanks Mayank, as always.

    Thinking aloud:

    Literature on Salesforce has been hammering in my mind that Record Owner has FULL ACCESS to the Record they own. FULL ACCESS literally means - Create, Read, Edit and Delete right on a Record. Logical and common sense.

    But this monkey wrench - Object Permissions of CRED needed by the Record Owner, in conjunction with the Record Owner's "FULL ACCESS", to work - will take some time to get absorbed :(

    Although Record Owner has "FULL ACCESS" to the Records they own, Object Permissions on a User's profile determine what a Record Owner can do with the records they create and own (hmm... counterintuitive).

    So, basically, in other words, Record Owner's "FULL ACCESS" privilege is worth a cent only if they ALSO have CRED permission for that particular Object on their Profile!!

    I think that Layers of Rooms analogy (one room inside another) is at work here:

    What one can do with a Record, even if one is owner/creator of that Record, will depend on what object permissions for the object, in which that record resides, one has on the Profile!

    Thanks Mayank again!! GREAT help!!

0/9000