Hello,
I have created a group team called "Demo Group Team 2" with team privileges only as follows:
Team is assigned with the security role which has BU scope for write and delete permission.
As per my understanding, in this scenario - User 1 will still consider the "Org BU" even if it's added in the Team having "Demo Business Unit 2" - Is that true? Or User will still consider his/her BU as "Org BU" ?
Meaning, every time user is added into the team - his/her BU must be changed manually even if Team is associated with respective BU.
Can you please clarify my understanding if I am wrong anywhere here?
Thanks,
Here’s also a nice video about security by @jlindstrom that explains it well:
It’s always the BU of the owner of the record. The privileges a user has is the cumulative all of privileges from the roles directly assigned and from roles assigned to the user’s teams (with some exceptions).
If the user is member of a team in another BU but the team doesn’t have any roles assigned then no additional privileges are granted to the user. And so, the user will not gain access to the records of the team’s BU.
Hmmm..and what if the records of the entity is scoped with BU in security role? then which BU will be considered for the record? User's Team's BU OR User's BU?
Thanks,
Hi @dave8,
Yes, user1 will still be under Org BU and doesn't need to change BUs. Users don't need to be associated to the same BU as the team's. It is a common practice to assign members from another BU to a team; it is a way to grant them access to records that normally they wouldn't have access in their BU.
That said, to answer your 2nd statement "his/her BU must be changed manually even if Team is associated with respective BU" is false.
Hope this clarifies...
WarrenBelz
637
Most Valuable Professional
stampcoin
570
Super User 2025 Season 2
Power Apps 1919
473