# Sharing model and record access

*Platform Administrator Study Guide · Configuration and Setup · Last updated September 26, 2026 · https://certifyforce.com/study-guide/platform-administrator/configuration-and-setup/sharing-model-and-record-access*

How record access is built: org-wide defaults as the restrictive baseline, then the role hierarchy, public groups, owner- and criteria-based sharing rules, account and opportunity teams and manual sharing to open it up, plus how report and dashboard folder access differs from record access.

- Certification: Salesforce Platform Administrator
- Exam section: Configuration and Setup
- Study guide: https://certifyforce.com/study-guide/platform-administrator

**Official exam objective:**

> Given a user request scenario, apply the appropriate security controls based on the features and capabilities of the Salesforce sharing model (for example: Teams, Sharing hierarchy, public groups, org-wide defaults, sharing: roles, subordinates, role hierarchy, report and dashboard folders).

## What the exam expects

- Set org-wide defaults as the most restrictive baseline an object needs, knowing every other sharing feature only adds access.
- Predict what the role hierarchy grants managers, when it fails (users in the wrong role), and when to turn off Grant Access Using Hierarchies.
- Choose between a public group, an owner-based or criteria-based sharing rule, a team, and manual sharing for a given audience and scope.
- Pick the right sharing rule target: a role, roles and their subordinates, or a public group.
- Explain that report and dashboard folder access controls who can open a report, not which rows it returns.
- Recognise when a detail object in a master-detail relationship can't have its own sharing.

## Key facts

| Fact | Detail | Source |
|---|---|---|
| Sharing features and the default | They only add access; none is stricter than the org-wide default | [Sharing Rules](https://help.salesforce.com/s/articleView?id=platform.security_about_sharing_rules.htm&type=5) |
| Set org-wide defaults | Setup, Sharing Settings; Manage Sharing permission | [Org-Wide Sharing Defaults](https://help.salesforce.com/s/articleView?id=platform.admin_sharing.htm&type=5) |
| Account Private | Opportunity and Case must be Private; Contact Private or Controlled by Parent | [Org-Wide Sharing Defaults](https://help.salesforce.com/s/articleView?id=platform.admin_sharing.htm&type=5) |
| Detail object in master-detail | Controlled by Parent; not editable | [Org-Wide Sharing Defaults](https://help.salesforce.com/s/articleView?id=platform.admin_sharing.htm&type=5) |
| Grant Access Using Hierarchies | Can be deselected only for custom objects | [Role Hierarchy](https://help.salesforce.com/s/articleView?id=platform.security_controlling_access_using_hierarchies.htm&type=5) |
| Role hierarchy | Users see records owned by or shared with roles below them | [Role Hierarchy](https://help.salesforce.com/s/articleView?id=platform.security_controlling_access_using_hierarchies.htm&type=5) |
| Roles and Internal Subordinates | The role plus all internal roles below it | [Sharing Rule Categories](https://help.salesforce.com/s/articleView?id=platform.security_sharing_data_set_categories.htm&type=5) |
| Sharing rule limit | 300 per object, including up to 50 criteria-based | [Sharing Rules](https://help.salesforce.com/s/articleView?id=platform.security_about_sharing_rules.htm&type=5) |
| Team member access | Can be greater than the org-wide default, never less | [Account Teams](https://help.salesforce.com/s/articleView?id=sales.accountteam_def.htm&type=5) |
| Manual share on owner change | Deleted by default | [Manual Sharing](https://help.salesforce.com/s/articleView?id=platform.granting_access_to_records.htm&type=5) |
| Folder access levels | Viewer, Editor, Manager | [Folder Access Levels](https://help.salesforce.com/s/articleView?id=analytics.analytics_folder_access.htm&language=en_US&type=5) |

## Check yourself

- Why must an org-wide default be the most restrictive level any user needs?
- What does a manager lose if a rep has no role assigned?
- On which objects can you turn off Grant Access Using Hierarchies, and on which can't you?
- When would you use a team or manual sharing instead of a sharing rule?
- What does Viewer access to a report folder allow, and what does it not change?

## Sources

- [Set Your Internal Organization-Wide Sharing Defaults](https://help.salesforce.com/s/articleView?id=platform.admin_sharing.htm&type=5)
- [Controlling Access Using the Role Hierarchy](https://help.salesforce.com/s/articleView?id=platform.security_controlling_access_using_hierarchies.htm&type=5)
- [Sharing Rules](https://help.salesforce.com/s/articleView?id=platform.security_about_sharing_rules.htm&type=5)
- [Sharing Rule Categories](https://help.salesforce.com/s/articleView?id=platform.security_sharing_data_set_categories.htm&type=5)
- [Public and Personal Groups](https://help.salesforce.com/s/articleView?id=platform.user_groups.htm&type=5)
- [Manual Sharing](https://help.salesforce.com/s/articleView?id=platform.granting_access_to_records.htm&type=5)
- [Considerations for Using Account Teams](https://help.salesforce.com/s/articleView?id=sales.accountteam_def.htm&type=5)
- [Access Levels for Report and Dashboard Folders](https://help.salesforce.com/s/articleView?id=analytics.analytics_folder_access.htm&language=en_US&type=5)
- [Troubleshoot Reports](https://help.salesforce.com/s/articleView?id=analytics.rd_reports_troubleshoot.htm&type=5)
- [Opportunity Teams and Opportunity Splits](https://help.salesforce.com/s/articleView?id=sales.teamselling.htm&type=5)

## About the full unit

The "Core concepts", "Exam traps" and "Worked scenario" sections of this unit, its 8 linked practice questions, and unlimited timed mock exams are included with the Platform Administrator pack (USD $19): https://certifyforce.com/practice-exams
