Environment Access Control

If you have multiple team members with varying access roles using Prodly, you should be using Environment Access Control. With **this feature, you can customize your users’ access to managed environments. This information will review the object and record access levels you can modify to control access to **Managed Environments.

Prodly Admin vs. Prodly User Permissions

By default, Prodly sets the sharing model for Managed Environments to private, therefore, users will need to be granted permission to access them.

To determine which permissions your users need, refer to the following chart:

Permission Sets Object Assignments Access
Prodly Admin Managed Environments Read, Create, Edit, Delete, View All and Modify All View, Create, Edit and Delete all environments
Prodly User Managed Environments Read, Create, Edit and Delete View, Create, Edit and Delete their own environments

<aside> <img src="/icons/info-alternate_blue.svg" alt="/icons/info-alternate_blue.svg" width="40px" />

If the permissions granted by the Prodly Admin or the Prodly User permission sets are not ideal, you can create a custom permission set for your users based on their needs.

</aside>

Organization-Wide Default Settings

Before assigning users individual permissions, it is important to make sure that your Sharing Settings are set appropriately for your Managed Environments. By default, settings will be set to private for Managed Environments.

To change your Sharing Settings, follow these steps:

  1. Visit ‘Setup’ in your Salesforce org and search for ‘Sharing Settings
  2. Here, you will be able to select ‘Managed Environment’ in the dropdown menu
  3. This will show you your Organization-Wide Default for your managed environments.

Select the appropriate settings for your Organization-Wide Defaults:

Assignment Access
Public Read Only All users can view and report on records but not edit them.
Public Read/Write All users can view, edit, and report on all records.
Private Only the record owner can view, edit, and report on those records.

Sharing Rule Override

If you wish to make exceptions to the Organization-Wide Defaults for certain environments and for certain users, you can create a Sharing Rule under ‘Managed Environment Sharing Rules’.

<aside> <img src="/icons/info-alternate_blue.svg" alt="/icons/info-alternate_blue.svg" width="40px" />

Sharing Rules can only expand access; they cannot restrict access beyond your baseline defaults.

</aside>

To use Sharing Rules for extending access beyond Organization-Wide Defaults, complete the following steps:

  1. Create Separate Profiles for Users

    Users of Release often have the System Administrator profile to have write access for all of the objects within a Managed Environment. If your organization wants to limit access to environment objects, a separate profile will need to be created with the removal of ‘Modify All’ and ‘View All’ for the Managed Environments object (and any other Prodly-specific objects you want to secure).