Skip to main content

Hi everyone,

I’m looking for some advice on a Salesforce security/architecture scenario. 

 

We have a group of Sales users whose Account access is granted through criteria-based sharing rules based on the entity/company they work for

. For example, users belonging to different country entities receive access to the corresponding Accounts. 

 

These users are also assigned to a Permission Set Group that grants Read access to a number of financial fields on the Account object

. 

 

The business requirement is to restrict these users from creating or modifying Reports, exporting Report data, and accessing restricted company-wide financial Reports and Dashboards.

At the same time, they must retain their existing visibility when working with an individual Account they have access to, including the relevant financial information, Invoices and Orders.

This leads to a question around the same financial fields being available through different Salesforce surfaces.

If a user has FLS Read access to these Account fields so that they can see them on the Account Record Page:

Is there any standard/native Salesforce mechanism to prevent those fields from being available in List Views, while still allowing them to be displayed on the Account Record Page?

And regarding Reports:

If the user is allowed to run a centrally provided Report, is there a standard way to prevent the financial fields from being exposed through that Report while keeping the user's existing Account-level visibility? 

 

We explored using Custom Report Types to exclude these financial fields from the layout. However, if an Inside Sales user runs a centrally provided Report built on a report type that does

include these fields (because Outside Sales and Management users share the reports and need them), Salesforce will render the data for the Inside Sales user too, as long as their FLS is active. Salesforce does not support dynamic column masking or role-based field filtering within a shared Report Type. 

 

Or is the standard Salesforce security model that FLS applies globally across all these surfaces, with Report/Dashboard folder access and export permissions providing the only standard restrictions?

I’m interested specifically in the standard Salesforce capabilities, or is this only possible per custom and if yes, how? LWCs? 

Thanks! 

 

@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects, @Data Quality & Management

 

 

#Trailhead Challenges  #Salesforce Developer  #Salesforce Admin  #Salesforce  #Data Management

5 respostas
  1. Hoje, 09:52

    The native and recommended way to do this would be to use Transaction Security Policies as they would allow you to create realtime policies that block users from for seeing data you define in list views and reports 

     

    Note: This requires the org either having Event Monitoring or Salesforce Shield (which bundles in Event Monitoring), which is an add-on product 

     

    https://help.salesforce.com/s/articleView?id=xcloud.enhanced_transaction_security_policy_types.htm&type=5

     

    https://developer.salesforce.com/docs/platform/platform-events/guide/platform-events-objects-monitoring.html

     

    https://trailhead.salesforce.com/content/learn/modules/enhanced_transaction_security/enhanced_transaction_security_basics

0/9000