Memory hook: Can use the object, can see the field, can reach the record.
Must remember
Object permissions control operations such as read/create/edit/delete. Field-level security controls field visibility/editability. Record sharing determines which records an otherwise authorized user can access. A page layout hides or arranges UI elements; it is not a substitute for field security across APIs and reports.
Profiles provide baseline settings/permissions; permission sets add access. Permission-set groups bundle permissions, and muting removes selected permissions from that group's contribution. Muting does not globally revoke the same permission granted by another source. Prefer understandable least-privilege assignments over many broad overlapping grants.
Organization-wide defaults establish baseline record access. Role hierarchy, sharing rules, teams and manual sharing can open access under supported object rules. Sharing rules generally extend access rather than restrict it. Public groups collect users/roles/groups for sharing; a role is primarily related to record visibility, not the same as a profile's object permissions.
View All/Modify All object permissions and broader administrative permissions can bypass ordinary sharing restrictions. Inspect these when a user sees unexpectedly broad data. Restriction rules, where supported, have a different filtering purpose from sharing rules; do not assume every object supports the same mechanisms.
Reports/dashboard folders control access to those analytical assets, while underlying data and running-user rules control results. Test as a representative user with all actual grants, not only by reading one profile. A user may see a record but not a sensitive field, or see a report definition with fewer rows than its author.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Hide salary through UI, reports and API | Field-level security, not merely layout removal. |
| Open records to a cross-functional group | Appropriate sharing to a public group/team. |
| Grant a small extra capability | A scoped permission set. |
Traps
- Sharing does not grant object CRUD by itself.
- Muting one group does not revoke a permission granted elsewhere.
Active recall
1. Three main data-access layers?
Object operations, field permissions and record access.
2. Role versus profile?
Record visibility hierarchy versus baseline permissions/settings.
3. Can a sharing rule make access more restrictive?
It generally opens access; use the appropriate supported restriction mechanism for a restriction requirement.
4. Why can layout hiding fail as security?
Other interfaces can still expose a field if field-level permission allows it.
5. Why test the full user?
Effective access combines multiple grants, entitlements and sharing mechanisms.