基于记录字段撤销编辑权限的方案咨询
Great question—this is a perfect use case for leaning into Salesforce’s native sharing and permission tools without relying on triggers or extra custom fields. Here’s the step-by-step approach tailored to your Job object setup:
1. Adjust Base Object Permissions
First, we’ll flip your current Public Read/Write default to Public Read Only for the Job object. This sets a secure base where all users can view Jobs, but can’t edit them unless explicitly granted access via a sharing rule.
- Navigate to
Setup > Object Manager > Job > Sharing Settings - Under "Default Internal Access", switch from "Public Read/Write" to "Public Read Only"
- Save your changes
2. Create a Criteria-Based Sharing Rule for In-Progress Jobs
Next, we’ll build a sharing rule that grants edit access only to Jobs where your "completion flag" field is empty (indicating the job is still in progress). Replace Completion_Date__c below with your actual completion field name (the one that gets populated when the job finishes):
- In the Job object’s Sharing Settings, click
Newunder "Sharing Rules"- Rule Name: "Allow Edit for In-Progress Jobs" (use a clear, descriptive label)
- Description: "Grants read/write access to users for Jobs that haven’t been completed (completion field is empty)"
- Rule Type: Select "Criteria-Based Sharing Rule"
- Criteria: Set the condition to
[Job].Completion_Date__cequals null (match your field’s empty state) - Share With: Choose "All Internal Users" if all teams should edit in-progress jobs, or select a specific Public Group if only certain users need this access
- Permission Level: Pick "Read/Write"
- Activate the rule
3. Validate Profile & Permission Set Overrides
- For users who need to edit all Jobs regardless of status (like admins or job managers), ensure their Profile has
Modify All Datapermission, or assign a Permission Set withModify Allaccess on the Job object. This bypasses the sharing rule restrictions for these users. - Double-check that all other users’ Profiles have only Read Only base access to the Job object—this ensures the sharing rule is the sole source of edit access for in-progress jobs.
Why This Works
- No triggers or extra fields: Everything uses out-of-the-box Salesforce tools, so you avoid maintenance overhead and custom code bloat.
- Dynamic access: As soon as the completion field is filled (marking the job as done), the sharing rule stops applying, and the user’s access reverts to Read Only automatically.
- Scalable: You can easily tweak the criteria or shared groups later if your business needs change.
内容的提问来源于stack exchange,提问作者Jason Papp

