如何配置字段安全:创建记录时可编辑Lead Source字段,创建后仅管理员可编辑
Awesome question—this is a super common requirement for maintaining data integrity, and it’s totally achievable with a mix of field security and automation. Let’s walk through the steps clearly, using Salesforce as an example (the core logic applies to other CRMs too, just adjust the UI/tooling names):
This is the foundation—we’ll define which users can edit the field when creating vs. updating a record:
- Head to Object Manager, find the object your Lead Source field lives on (e.g., Lead, Contact, or a custom object)
- Open the
Lead Sourcefield’s settings page, then click Field-Level Security - For regular user profiles:
- Check the Create permission (lets them fill the field when making a new record)
- Uncheck the Edit permission (blocks them from changing it after the record is saved)
- For admin profiles: Leave both Create and Edit permissions checked so they can modify the field anytime
FLS works for most cases, but it can be bypassed via bulk imports, API calls, or some custom code. Adding an automation rule ensures no one (except admins) can alter the field after creation:
Option A: No-Code with Process Builder/Flow
- Create a new Record-Triggered Flow that triggers when the record is edited
- Add a Decision element: Check if
Lead Sourcehas changed, and if the current user’s profile is NOT an admin profile - If that condition is true, add an Error Message action that says: "Lead Source cannot be modified after record creation—only admins have edit access."
Option B: Code-Based with Apex Trigger
If you need more flexibility (like handling edge cases), write a simple trigger:
trigger LockLeadSource on Lead (before update) { // Replace with your admin profile ID(s) Set<Id> adminProfileIds = new Set<Id>{'00eXXXXXXXXXXXX'}; for (Lead newLead : Trigger.new) { Lead oldLead = Trigger.oldMap.get(newLead.Id); // Block changes if field is modified and user isn't an admin if (newLead.LeadSource != oldLead.LeadSource && !adminProfileIds.contains(UserInfo.getProfileId())) { newLead.addError('Lead Source cannot be edited after record creation. Only admins have permission to modify this field.'); } } }
Pro tip: To get your admin profile ID, go to Setup > Profiles, open the admin profile, and copy the ID from the URL.
- Log in as a regular user: Create a new record, confirm you can fill Lead Source. Try editing the field afterward—you should see a block (either from FLS or the automation error).
- Log in as an admin: Edit the Lead Source field on an existing record to confirm it works.
内容的提问来源于stack exchange,提问作者Seth Partridge

