Skip to main content

#Sharing Setting토론 중인 항목 2개

Hi Trailblazers,

I'm facing an issue with Experience Cloud

and would appreciate your help. 

 

Scenario

Portal users create Tasks directly from the Experience Cloud portal. They do not have access to the Salesforce org.

They can access an Account record, but they can only see the Tasks they created themselves. They cannot see Tasks created by other users (internal users or other portal users), even though those Tasks are related to the same Account.

Current Setup

  • Activity OWD = Controlled by Parent
  • Portal users have access to the Account record.
  • Tasks are related to the Account (WhatId = Account).
  • Portal users have the required object and field permissions.

Issue

  • If a portal user creates a Task for an Account from the Experience Cloud portal, they can see that Task in the portal.
  • If another user creates a Task for the same Account, the portal user cannot see it in the Activities related list. They only see the Tasks they created.

Is this the expected behavior with Activity OWD = Controlled by Parent

, or is there any additional sharing or configuration required to allow portal users to see all Tasks related to the Account? 

 

Any guidance would be greatly appreciated.  

Thank you! 

 

#Experience Cloud  #Salesforce Developer  #Salesforce  #Tasks  #Sharing Setting

답변 6개
0/9000

Hi,

I want to create a permission set that allows those who own it to edit the profile pictures of all users.

Indeed, I looked in the object settings > user but the fields linked to the profile photo are not there.

Do you know how to do it ?

Thanks a lot for your help,

#Object Permissions #Trailhead #User Management #Sharing Setting

답변 4개
  1. 2023년 10월 20일 오전 9:24

    Hi @Julien SALENSON

    Thank you very much for this response.

    I don't necessarily need to modify in bulk but just allow certain users to modify the profile photos of other users (like what an administrator can already do)

0/9000
0/9000

Hi all,

my org-wide sharing is private on the opportunity.

 

Now I have created a sharing rule that share (Read/Write) opportunity with a public group.

 

I can assign to this public group using one of these profiles A or B

A is read-only on the opportunity

B is read/edit on the opportunity

 

The effect is that a user (in this pubic group) with profile A can only see the opportunities shared with the group. Instead, a user (in this pubic group) with profile B can see the opportunities shared with the group AND edit them.

 

Can you confirm?

 

I hope so!

 

Now, in case of a user with profile A (read-only) is correct he can't edit opportunities owned?

 

tks

댓글 3개
0/9000

Introducing BRAND 🔥  *NEW* 🔥  Getting Started with Security and Access

 (Feel Free to Download)

************************************************************************************************

Salesforce provides a flexible, layered data sharing design that allows you to expose different data sets to different sets of users, so users can do their job without seeing data they don't need to see. Use permission sets and profiles to specify the objects and fields users can access. Use organization-wide sharing settings, user roles, sharing rules to specify the individual records that users can view and edit.

 

***Be sure to Check Page 2 for our complete content catalogue. Join *Answers Connect* Group, Download the File👇 and keep blazing new trails!

 

Resource Included:

1. The Organization (Login Access, IP Restrictions) (Video)

2. Restrict Where and When User can Log In to Salesforce (Article)

3. Set Trusted IP Ranges for your Organization (Article)

4. Object Permissions (Article | Video)

  • ”View All” and “Modify All” Permissions Overview (Article)
  • Comparing Security Models (Article)
  • Field Permission (Article)

5. Profiles (Article)

  • Standard Profiles (Article)
  • Manage Profile Lists (Article)
  • Clone Profiles (Article)
  • Work in the Enhanced Profile User Interface Page (Article)
  • Work with Assigned Apps in the Enhanced Profile User Interface (Article)
  • Assign Record Type and Page Layouts in the Enhanced Profile User Interface (Article)
  • Edit Object Permissions in Profiles (Article)

6. Permission Sets (Article)

  • Create Permission Sets (Article)
  • Assign Permission Sets to a Single User (Article)
  • Standard Permission Sets (Article)
  • Use Permission Set Lists (Article)

7. Sharing Settings (Article)

  • Organization-Wide Defaults (Article)
  • Sharing Rules (Article)
  • Control Access Using Hierarchies (Article)

8. Field Level Security (Article)

  • Set Field Permission in Permission Sets and Profiles (Article)
  • Set Field-Level Security for a Single Field on All Profiles (Article)

Trailhead, and more…

댓글 6개
0/9000

Sharing Custom Object over Custom Junction Object

I have the requirement to share a record of a Custom Object "Trial" to multiple Contacts in a Community if they have a connection. The connection between the two object is a junction object called "Trial Contact".

  • As example, there are two Trials named "A" and "B"
    • Contact X of Account E should only see Trial "A" - 1 record in "Trial Contact"
    • Contact Y of Account F should see Trial "A" and "B" - 2 records in "Trial Contact"
    • Contact Z of Account G should only see Trail "B" - 1 record in "Trial Contact"

What is the best setup of relationships (lookup/master detail) to fullfill this requirement?

Thanks for any advice!

댓글 2개
  1. 2020년 11월 2일 오후 8:44
    @Jürg Steudler I haven't actually attempted this, but my first instinct is to create a lookup relationship on Trial Contact to Trial. To actually share, trigger creation/removal of Trial Share records based on the Trial Contact records created/deleted.
0/9000

A sharing question team - I have shared an App and a Dashboard on it to a user - both their Role and them directly, but they can't see it - they get the error message 

This dashboard doesn't exist, has been deleted, or you may not have access to it

User has access to Analytics Studio

What other sharing consideration do I need to look for? Thanks!

댓글 16개
0/9000
Neela Murthy 님이 * Experience Cloud *에 글을 올렸습니다

@Admin Communities I am looking out to share Partner owned Opportunities with non-Managers inside my Org. Is it possible for an Internal User who is not a Manager for the Partner to view and edit opportunities?

I understand there is always sharing Rules because Partner users have a different line of Role Hierarchy and only roll up to a single Account Manager. 

 

I am looking out for options like default Teams and Sharing sets in community Settings. More granular sharing of data depending on partner region.

Thanks

댓글 2개
0/9000

Happy Tuesday Trailblazers! Check out the screencast 👇 that walks you through 3 scenarios that are all related to sharing issues.

[Troubleshoot Why a User Can't See a Record: Incorrect Sharing Settings]

댓글 4개
0/9000
Abhra Bhattacharya 님이 * Salesforce Administrators *에 글을 올렸습니다

I am using a Hiring Manager (permission set) on a Standard Employee (Profile),

looking to give: Create Read Edit - Access to Records of Position(custom object), such that: 

 

Only those Position Records to which the Hiring Manager has been assigned are displayed.

 

1. I have created User: Ben Holder 

2. Assigned him to Profile: Standard Employee

3. Added him to Permission Set: Hiring Manager

4. Position Object OWD set to Private. 

5. Created Role: Hiring Manager, assigned to the user above

6. I have created Position Records; logged in from Admin. 

 

However, now when I log in as Ben Holder, I can see all Position Object Records created ever!

 

Can someone help me please?

댓글 3개
  1. 2020년 5월 19일 오후 3:19

    hi Abhra,

    I think you should be clear about roles and permission sets here . As far as I have learnt on trailhead modules ( i am not a very experienced learner here) , Roles are not always clear in a company ( for the purpose of record sharing ) , so they use " groups" instead .

    Moreover , permission sets are used to give object/field level security ,not record level security !!

    Now in your situation , if a role ( of hiring manager )is explicitly defined , then please clarify if the hiring manager wants read/write access on those records only where he himself is the manager ? any other situation changes the way we define sharing rules

0/9000