Menu
Articles in this section
- Permissions & Users: FAQ
- SSO/SAML: FAQ
- Simple vs Advanced Permissions
- Advanced Permissions Guide
- Advanced Permissions: Organization-Wide Sharing
- Advanced Permissions: Profiles
- Advanced Permissions: Roles
- Advanced Permissions: Sharing Rules
- How to create a team
- Granting or removing export permissions
Advanced Permissions: Organization-Wide Sharing
Organization-wide sharing is the Advanced Permissions setting that decides, per record type, whether everyone can reach every record or whether access is governed by roles and sharing rules.
Each record type is either Private or Public.
⚠️ Everything starts Private. When Advanced Permissions is first enabled, every record type is set to Private. Private is also required before roles and sharing rules can be set up for that record type.
On this page:
Private
Access is limited by role. A user sees a record only if both are true:
- They own or are assigned to the record, or they are assigned to a role that lets them view that person’s items, whether through the role hierarchy or through sharing rules.
- They are assigned to a profile giving them Read permission for that record type.
Access can then be widened with roles, sharing rules, or the Read All permission in a profile.
Public
Every user reaches every record of that type, regardless of owner, provided one thing is true: they are assigned to a profile giving them Read permission for that record type.
⚠️ Public switches off roles and sharing rules for that record type. Any access model you have built with roles or sharing rules stops applying the moment a record type is set to Public.
Profiles remain the lever. Assigning a user to a profile without Read permission for a record type hides all of those records from them, and hides the tab from the navigation menu as well.
Deciding which to use
One question per record type: should every user reach every record of this type, no matter who owns it?
Yes, set it to Public. No, set it to Private and build roles and sharing rules.
The source’s own example: project records that anyone with project Read permission should see are Public, while opportunities that only certain people should reach are Private with roles and sharing rules on top.
In both cases the user still needs the appropriate Read permission in their profile.
Changing the setting
- Go to System Settings > Sharing Settings.
- Click Edit Sharing Settings.
- Choose Public View or Private Only from the dropdown for each record type.
- Click Save Sharing Settings.
Related to