Newer Version Available

This content describes an older version of this product. View Latest

Create Sharing Rules

A sharing rule is based on the record owner or other criteria, including record type and certain field values. You can define up to 300 total sharing rules for each object, including up to 50 criteria-based or guest user sharing rules, if available for the object.
Available in: Salesforce Classic (not available in all orgs) and Lightning Experience
Available in: Professional, Enterprise, Performance, Unlimited, and Developer Editions

User Permissions Needed
To create sharing rules: Manage Sharing
  1. If you plan to include public groups in your sharing rule, confirm that the appropriate groups have been created.
  2. From Setup, enter Sharing Settings in the Quick Find box, then select Sharing Settings.
  3. In the Sharing Rules related list for the object, click New.
  4. Enter the label name and rule name. The label name appears on the user interface. The rule name is a unique name used by the API and managed packages.
  5. Optionally, enter a description of the sharing rule, up to 1,000 characters.
  6. Select a rule type, if prompted. Some rules types aren’t available for all objects.
  7. Select which records or users to share. Depending on the rule type you selected, do the following.
    • Based on record ownerFor owned by members of, specify which users’ records are shared. Select a category from the first dropdown list and a set of users from the second dropdown list or lookup field.
    • Based on criteria or Guest user access, based on criteriaSpecify the field, operator, and value criteria that records must match to be included in the sharing rule. The fields available depend on the object selected, and the value is always a literal number or string. To change the AND relationship between filters, click Add Filter Logic.

      To use a field that’s not supported by criteria-based sharing rules, create a workflow rule or Apex trigger to copy the value of the field into a text or numeric field. Then use that field as the criterion.

      Note

    • Based on account territories—For Accounts in Territory, select Territories or Territories and Subordinates from the first dropdown list and a territory from the second dropdown list. This option is available only for sharing rules created via the Account Territory Sharing Rules related list. The Account Territory Sharing Rules related list isn’t available with Enterprise Territory Management.
    • Based on group membership—You can share users who are members of a group with members of another group. For Users who are members of, select a category from the first dropdown list and a set of users from the second dropdown list or lookup field. This option is available only for user sharing rules.
  8. Specify the users who get access to the data. For Share with, select a category from the first dropdown list and a set of users from the second dropdown list or lookup field.

    If the Secure guest user record access setting is enabled, you must create guest user sharing rules to open up record access to guest users. Keep in mind that the guest user sharing rule type grants access to users without login credentials. By creating a guest user sharing rule, you're allowing immediate and unlimited access to all records matching the sharing rule's criteria to anyone. To secure your Salesforce data and give your community guest users access to what they need, consider all the use cases and implications of creating this type of sharing rule. Implement security controls that you think are appropriate for the sensitivity of your data. Salesforce is not responsible for any exposure of your data to unauthenticated users based on this change from default settings.

    Note

  9. Select sharing access settings for users. Some access settings aren’t available for some objects or in some situations.
    Access Setting Description
    Private Users can’t view or update records, unless access is granted outside of this sharing rule.

    Available only for associated contacts, opportunities, and cases.

    Read Only Users can view, but not update, records.

    Guest user sharing rules can only grant Read Only access.

    Read/Write Users can view and update records.
    Full Access Users in the selected group, role, or territory can view, edit, transfer, delete, and share the record, just like the record’s owner.

    With a Full Access sharing rule, users can also view, edit, delete, and close activities associated with the record if the org-wide sharing setting for activities is Controlled by Parent.

    Available for campaigns only.

    Contact Access is not available when the organization-wide default for contacts is set to Controlled by Parent.

    Note

  10. Click Save.