Security Settings
A user can be granted access to an item or an entity type in several ways. Not all possible ways are currently included in the connector. The security is layered and the security overrides depend the individual Salesforce environment settings. Initial access can be given or denied for all entities of a certain type and later access can be granted or restricted for individual items of this entity type. Security permissions are given by Licenses, Organization-Wide Defaults, Profiles, Permission Sets, Public Groups, User and Group Sharing (Direct Sharing), Roles, Sharing Rules (Object Sharing), Inherited Access (for managers), Sharing Access by parent object and Field objects and Field Accessibility.
The current user security access is implemented in the connector.
...
- Permission Sets.
- Sharing Rules (Object Sharing).
- Inherited Access. Security settings to directly check if a manager should be able to view all items of users which he/she manages.
Currently only roles will inherit permissions from sub roles - given by the user roles hierarchy. - Sharing Access by parent object. Currently only exists for the well-known entity types with preselected metadata fields.
- Field Accessibility. No field restrictions for any of the index entities.
...
At search time when users log into ViaWorks Locator they are authenticated with Active Directory. User attributes for the authenticated user are used to find a username in Salesforce. This happens automatically in the plug-in and the user does not need provide the Salesforce credentials.
...
Document items are marked with a list of Salesforce groups and user SIDs at fetching time. At search time, users are given SIDs based on the Salesforce account associated with the ViaWorks Locator login.
Example:
- Salesforce_999 005A0000004wzojIAA (User)
- Salesforce_999 00GA0000001LnPuMAK (Group)
- Salesforce_999 Account (View all account - from user settings)
- Salesforce_999 AllData (View all data - from profile settings)
- Salesforce_999 Users (View all users - from profile settings)
...