← Salesforce Certified Administrator
Test yourself →

Configuration and Setup

## Configuration and Setup Essentials

The "Configuration and Setup" topic is fundamental for any Salesforce Administrator, covering how to tailor an organization's environment, manage users, and secure data.

Company Information

The Company Information page is the central hub for your organization's details. Here you define crucial settings like Organization Name, Primary Contact, Default Locale, Default Language, Default Time Zone, and Currency Locale. It also displays your Salesforce Org ID, license details, and storage usage. Setting the correct Fiscal Year (Standard or Custom) is vital for reporting.

User Management

Effective User Management is paramount. Administrators create and deactivate Users, assigning them a User License, Profile, and optionally a Role.

  • A Profile determines a user's *object and field permissions*, *app access*, *tab visibility*, and *system permissions* (e.g., "Modify All Data"). Every user must have exactly one profile.
  • Permission Sets grant *additional* permissions and access settings without changing a user's profile. A user can have multiple permission sets.
  • Roles primarily control *record-level access* through the Role Hierarchy, determining what records a user can see based on their position in the hierarchy. Users at higher roles can typically see records owned by users below them.
  • Public Groups and Queues are used for sharing records to groups of users, not individual users. Queues are specifically for managing records that need to be processed by a group (e.g., cases, leads).

Security Controls

Salesforce offers robust Security Controls to protect your data.

  • Org-Wide Defaults (OWD) set the baseline level of access for *all records* of an object. This is the most restrictive setting and should be configured first. Options include Public Read/Write, Public Read Only, Private, and Controlled by Parent.
  • Sharing Rules extend access *beyond* OWDs, granting specific users or groups access to records based on criteria or ownership. They are always permissive.
  • Field-Level Security (FLS) restricts user access to individual fields on an object, controlling visibility and editability. This is configured on profiles and permission sets.
  • Password Policies enforce rules for user passwords, such as length, complexity, and expiration.
  • Login Hours and IP Ranges can restrict when and from where users can log in, enhancing security.

User Interface Customization

Administrators can customize the user experience. The App Manager allows creation and management of Lightning Apps. The Lightning App Builder is used to customize Home Pages, Record Pages, and App Pages by dragging and dropping Lightning components. Navigation Items define what tabs appear in an app.

Monitoring and Audit

The Setup Audit Trail tracks all configuration changes made in your Salesforce org, including who made the change and when, providing a critical tool for monitoring and compliance.

  • Company Information defines default locale, currency, fiscal year, and displays org ID and license usage.
  • Every user must have exactly one Profile, which determines object, field, and app access.
  • Permission Sets grant *additional* permissions beyond a user's profile.
  • Roles primarily control record-level access via the Role Hierarchy, enabling data visibility up the hierarchy.
  • Org-Wide Defaults (OWD) establish the *most restrictive* baseline access for records in an object.
  • Sharing Rules *extend* record access beyond OWDs, based on criteria or ownership.
  • Field-Level Security (FLS) controls visibility and editability of individual fields for users.
  • The Setup Audit Trail logs all configuration changes made in the Salesforce org.
What is the primary purpose of a Salesforce Profile?
A Profile determines a user's object and field permissions, app access, tab visibility, and system permissions. Every user must have one.
tap to reveal
How do Permission Sets differ from Profiles?
Permission Sets grant *additional* permissions and access settings to users, extending what their profile allows, and a user can have multiple. Profiles are mandatory and define the baseline.
tap to reveal
What is the function of the Role Hierarchy in Salesforce?
The Role Hierarchy primarily controls record-level access, allowing users at higher roles to view records owned by users below them in the hierarchy.
tap to reveal
What is the most restrictive data access setting in Salesforce and where is it configured?
Org-Wide Defaults (OWD) are the most restrictive baseline access settings for records, configured per object in Sharing Settings.
tap to reveal
How can an administrator grant specific groups of users access to records beyond the Org-Wide Defaults?
By creating Sharing Rules, which extend access based on record ownership or criteria.
tap to reveal
What tool tracks configuration changes in a Salesforce org, including who made them and when?
The Setup Audit Trail.
tap to reveal
What is Field-Level Security (FLS) used for?
FLS controls the visibility and editability of individual fields on an object for users, configured via profiles and permission sets.
tap to reveal
Where can you define your organization's default locale, currency, and fiscal year settings?
On the Company Information page.
tap to reveal

Object Manager and Lightning App Builder

## Object Manager: Building Blocks of Your Data

Object Manager is where administrators define and customize the data structure within Salesforce. It houses both Standard Objects (e.g., Account, Contact, Opportunity) and Custom Objects (created to store unique business data).

Fields

Fields are the columns in your database tables. They define what kind of data can be stored. Key field types include:

  • Standard Fields: Pre-defined by Salesforce (e.g., Account Name, Contact Email).
  • Custom Fields: Created by admins to meet specific business needs. Each custom field has a data type (e.g., Text, Number, Date, Checkbox, Picklist, Currency).
  • Relationship Fields: Link objects together.
  • Lookup Relationship: A loose connection, parent record deletion doesn't necessarily delete child, no impact on security.
  • Master-Detail Relationship: A strong, parent-child relationship. Child records inherit security from the parent and are deleted when the parent is deleted. Required on the child object.
  • Formula Fields: Read-only fields that derive their value from a formula you define, often referencing other fields.
  • Roll-Up Summary Fields: Only available on the master side of a Master-Detail relationship. They aggregate data (SUM, COUNT, MIN, MAX) from related detail records.

Page Layouts and Record Types

  • Page Layouts: Control the organization of fields, sections, related lists, and custom buttons on a record detail page. They also determine which fields are visible, read-only, or required. Page layouts are assigned to Profiles and Record Types.
  • Record Types: Allow you to offer different business processes, picklist values, and page layouts to different users based on their profile. They are crucial for tailoring user experience and data entry.

Validation Rules

Validation Rules ensure data quality by preventing users from saving records that don't meet specified criteria. They use a formula to evaluate data and display an error message if the formula returns TRUE.

Compact Layouts

Compact Layouts define the fields that appear in the highlights panel at the top of a record page on desktop and in the record header of the Salesforce mobile app.

## Lightning App Builder: Crafting User Interfaces

The Lightning App Builder is a drag-and-drop tool used to create custom pages for Salesforce Lightning Experience and the mobile app. It allows admins to build flexible and dynamic user interfaces.

Lightning Pages

There are three main types of Lightning Pages:

  • Record Pages: Customize the layout of a specific object's record detail page. You can use Dynamic Forms to break up page layouts into individual fields and sections, allowing for conditional visibility.
  • Home Pages: Customize the content users see when they log in or navigate to the Home tab.
  • App Pages: Create standalone pages with custom content and components that can be added to any Lightning App.

Components

Lightning Pages are built using Lightning Components. These can be standard (provided by Salesforce), custom (developed by developers), or from the AppExchange. Admins drag and drop these components onto the canvas and configure their properties.

Activation

Once a Lightning Page is built, it must be activated to be visible to users. Activation options include setting it as the Org Default, App Default, or assigning it to specific Apps, Record Types, and Profiles. This granular control ensures users see the most relevant interface.

  • Master-Detail relationships enforce security and record deletion on child records from the parent.
  • Roll-Up Summary fields are only available on the master side of a Master-Detail relationship.
  • Page Layouts control field visibility, read-only status, and requiredness, assigned by Profile and Record Type.
  • Record Types allow different picklist values and page layouts based on user profiles and business processes.
  • Validation Rules prevent data from being saved if it doesn't meet defined criteria, using a formula that returns TRUE for an error.
  • Compact Layouts define the fields displayed in the highlights panel and the mobile record header.
  • Lightning App Builder creates Record, Home, and App pages using a drag-and-drop interface with components.
  • Dynamic Forms allow individual fields and sections from a page layout to be placed and conditionally displayed on a Lightning Record Page.
What is the primary difference between a Lookup and a Master-Detail relationship?
Master-Detail relationships are tightly coupled, where child records inherit security and are deleted with the parent. Lookup relationships are loosely coupled, with no security or deletion impact.
tap to reveal
When would you use a Roll-Up Summary field?
To display an aggregate value (SUM, COUNT, MIN, MAX) from related child records on the master record in a Master-Detail relationship.
tap to reveal
What do Page Layouts control?
The organization of fields, sections, related lists, and custom buttons on a record detail page, including field visibility, read-only status, and requiredness.
tap to reveal
How do Record Types benefit an organization?
They allow different business processes, picklist values, and page layouts to be assigned to different users based on their profile, tailoring the user experience.
tap to reveal
What is the purpose of a Validation Rule?
To improve data quality by preventing users from saving records that do not meet specific criteria defined by a formula.
tap to reveal
Name the three types of Lightning Pages you can build with the Lightning App Builder.
Record Pages, Home Pages, and App Pages.
tap to reveal
What are Dynamic Forms?
A feature on Lightning Record Pages that allows administrators to migrate fields and sections from a page layout onto the page directly, enabling individual field visibility rules and a more flexible layout.
tap to reveal

Sales and Marketing Applications

## Sales & Marketing Applications Overview

Salesforce's Sales Cloud is designed to help organizations manage their sales processes from lead generation to deal closure. Key objects include Leads, Accounts, Contacts, Opportunities, Products, and Price Books. Marketing efforts are primarily tracked using Campaigns.

## Lead Management

Leads represent potential customers who have shown interest in your products or services. They are typically unqualified prospects. Admins can configure Lead Assignment Rules to automatically assign new leads to the correct user or queue based on criteria. When a lead is qualified, it undergoes Lead Conversion. This process creates an Account, a Contact, and optionally an Opportunity. The original Lead record is then marked as converted and becomes read-only.

## Account, Contact, and Opportunity Management

Accounts represent companies or organizations you do business with. Contacts are individuals associated with an Account. An Account can have multiple Contacts. Opportunities track potential sales deals and their progress through various Stages. Each stage typically has an associated Probability of closing. Admins define Sales Processes to control the available stages for opportunities. Opportunities can be associated with Products from a Price Book, allowing for detailed revenue tracking and quoting. Quotes can be generated from opportunities to present proposed products and prices to customers.

## Product and Price Book Management

Products are the items or services your company sells. Price Books store a list of products and their associated standard or custom prices. Organizations can have multiple price books (e.g., Standard Price Book, Wholesale Price Book, Retail Price Book). Products must be added to a Price Book before they can be added to an Opportunity.

## Campaign Management

Campaigns are used to track marketing initiatives and their effectiveness. They can represent events, advertisements, email blasts, or other promotional activities. Campaign Members are Leads or Contacts associated with a campaign, indicating their participation or response. Admins can set up Campaign Hierarchies to group related campaigns and analyze their collective performance. The Campaign Influence feature helps attribute revenue to specific campaigns.

## Sales Productivity Features

Admins can enhance sales user productivity with features like Sales Path (Lightning Experience), which guides users through the stages of an opportunity or lead with key fields and guidance for success. The Kanban View provides a visual summary of records (e.g., opportunities) grouped by a picklist field, allowing for easy drag-and-drop updates. Duplicate Rules and Matching Rules are crucial for maintaining data quality across all sales records.

  • Lead conversion creates an Account, Contact, and optionally an Opportunity.
  • Opportunities track potential revenue and progress through defined stages.
  • Price Books store products and their associated prices.
  • Campaigns are used to track marketing efforts and their ROI.
  • Sales Path guides users through the stages of a sales process in Lightning.
  • An Account can have multiple Contacts, and a Contact must be linked to an Account.
  • Duplicate Rules prevent the creation of redundant records like Leads or Accounts.
  • Campaign Members are Leads or Contacts associated with a marketing campaign.
What happens when a Lead is converted in Salesforce?
An Account, a Contact, and optionally an Opportunity are created. The original Lead becomes read-only.
tap to reveal
What is the primary purpose of an Opportunity record?
To track potential sales deals, their progress through stages, and associated revenue.
tap to reveal
How are Products associated with Opportunities?
Products are added to an Opportunity from a Price Book.
tap to reveal
What is a Price Book in Salesforce?
A list of products and their associated prices, which can be standard or custom.
tap to reveal
How do Salesforce Admins enable users to track marketing efforts and their impact?
By setting up and utilizing Campaigns, Campaign Members, and Campaign Hierarchies.
tap to reveal
What is the function of Sales Path in Lightning Experience?
To guide users through the stages of a Lead or Opportunity, highlighting key fields and providing guidance.
tap to reveal
What is the relationship between Accounts and Contacts?
Accounts represent companies, and Contacts are individuals who work at those companies. A Contact must be associated with an Account.
tap to reveal
Which Salesforce feature helps prevent the creation of duplicate records for Leads, Accounts, and Contacts?
Duplicate Rules and Matching Rules.
tap to reveal

Service and Support Applications

## Service and Support Applications: Core Concepts

Service and Support applications in Salesforce, primarily Service Cloud, are designed to help companies manage customer inquiries, provide support, and improve customer satisfaction. The central object for tracking customer issues is the Case.

## Case Management Fundamentals

A Case represents a customer's question, feedback, or issue. Admins configure the Case object, including custom fields, page layouts, and record types, to capture relevant information.

Key automation tools for Cases include:

  • Case Assignment Rules: Automatically assign new or updated cases to specific users or queues based on criteria (e.g., product type, priority).
  • Case Escalation Rules: Automatically reassign cases and/or notify users when a case is not resolved within a specified time period. This helps enforce Service Level Agreements (SLAs).
  • Case Auto-Response Rules: Automatically send personalized email responses to customers when they submit a case, confirming receipt and providing initial information.

Cases can be created in several ways:

  • Web-to-Case: Generates an HTML form that can be embedded on a company's website, allowing customers to submit cases directly. Up to 5,000 cases can be created per day.
  • Email-to-Case: Converts emails sent to a specific support email address into cases. This can be On-Demand (using Salesforce email services) or using a local agent.

## Enhancing Agent Productivity

The Service Cloud Console is a specialized user interface designed for support agents, providing a unified view of customer information and tools to efficiently manage cases.

Salesforce Knowledge (often referred to simply as Knowledge) allows organizations to create, publish, and manage articles containing solutions, FAQs, and policies. These articles can be used by agents to quickly resolve cases and by customers through self-service portals.

Macros are tools that allow agents to automate repetitive tasks by performing a series of actions (e.g., updating fields, sending emails) with a single click.

Omni-Channel is a feature that routes work items (like cases, chats, or leads) to the most appropriate and available agents, ensuring efficient distribution of workload and adherence to service levels.

## Service Level Agreements (SLAs)

Entitlements define the level of support a customer is eligible for (e.g., phone support, 24/7 support). They are often linked to Service Contracts.

Milestones are required steps in a support process that must be completed to meet an SLA (e.g., "First Response within 1 hour"). They are configured within Entitlement Processes.

  • Cases track customer questions, feedback, or issues.
  • Web-to-Case and Email-to-Case automate case creation from external sources.
  • Case Assignment Rules automatically route cases to users or queues.
  • Escalation Rules reassign and notify based on unresolved case criteria.
  • Salesforce Knowledge provides articles for agents and customers for self-service.
  • Entitlements define a customer's support level, often tied to service contracts.
  • Milestones are time-dependent steps within an Entitlement Process to meet SLAs.
  • Omni-Channel routes work items to available agents efficiently.
What is the primary purpose of a Case in Salesforce?
To track a customer's question, feedback, or issue.
tap to reveal
Name two ways to automate case creation from external sources.
Web-to-Case and Email-to-Case.
tap to reveal
Which automation tool automatically assigns cases to users or queues based on criteria?
Case Assignment Rules.
tap to reveal
What do Escalation Rules do?
Automatically reassign cases and/or notify users when a case isn't resolved within a specified time.
tap to reveal
What is the purpose of Salesforce Knowledge?
To create, publish, and manage articles that agents and customers can use to find answers and solutions.
tap to reveal
What are Entitlements used for in Service Cloud?
To define the level of support a customer is eligible for, often tied to service contracts.
tap to reveal
How do Macros help agents?
They automate repetitive tasks by performing a series of actions with a single click.
tap to reveal
What is Omni-Channel used for?
To route work items (like cases, chats) to the most appropriate and available agents.
tap to reveal

Productivity and Collaboration

## Productivity and Collaboration in Salesforce

Salesforce provides a robust suite of tools designed to enhance user productivity and foster collaboration across teams. Administrators play a crucial role in configuring and managing these features to optimize business processes and communication.

## Activity Management

Activities in Salesforce encompass Tasks and Events.

  • Tasks are to-do items with a due date, assigned to a user, and can be related to records like Accounts, Contacts, Leads, Opportunities. They can be recurring.
  • Events are scheduled meetings or appointments with a start and end time, and can include attendees. They appear on calendars.
  • The Activity Timeline in Lightning Experience provides a chronological view of past and upcoming activities related to a record, making it easy to track interactions. Admins can customize activity fields and record types.

## Chatter

Chatter is Salesforce's enterprise social network, enabling real-time collaboration.

  • Users can post updates, ask questions, and comment on records or groups.
  • Chatter Groups allow users to collaborate on specific projects or topics. They can be public, private, or unlisted.
  • Mentions (@username) notify specific users, and Topics (#hashtag) categorize conversations.
  • Admins can enable/disable Chatter, manage feed tracking for objects, and set up email notifications.

## Email and Templates

Salesforce facilitates email communication directly from records.

  • Email Templates standardize outbound communications. They can be Classic (Text, HTML with Letterhead, Custom HTML, Visualforce) or Lightning Email Templates. Lightning templates offer a more intuitive builder and support merge fields.
  • Letterheads are used with Classic HTML email templates to provide consistent branding.
  • Enhanced Email is a Lightning Experience feature that saves emails as records, relating them to contacts, leads, and other records, providing a complete communication history.
  • Admins configure organization-wide email addresses, email deliverability settings, and manage template folders.

## Search

Efficient search is vital for productivity.

  • Global Search (or Salesforce Search) allows users to find records across most standard and custom objects from the top of any page. It uses a relevance ranking algorithm.
  • Einstein Search (if enabled) provides personalized, natural language search capabilities, actionability, and search results tailored to the user.
  • Admins can configure search layouts, object search settings, and result filters.

## Salesforce Mobile App

The Salesforce Mobile App provides on-the-go access to Salesforce data and functionality.

  • Users can view and update records, log activities, collaborate via Chatter, and access custom apps.
  • Admins can customize the navigation bar, compact layouts, and Lightning pages for mobile users to optimize the experience.
  • **Tasks** are to-do items with a due date, while **Events** are scheduled meetings with a start and end time.
  • The **Activity Timeline** in Lightning Experience provides a chronological view of past and upcoming activities on a record.
  • **Chatter Groups** can be Public, Private, or Unlisted, allowing controlled collaboration.
  • **Lightning Email Templates** offer a modern builder and support merge fields for personalized emails.
  • **Enhanced Email** saves emails as records, relating them to other records for a complete communication history.
  • **Global Search** allows users to find records across multiple objects from the top search bar.
  • The **Salesforce Mobile App** provides customizable on-the-go access to records, activities, and Chatter.
  • Admins can customize **compact layouts** to optimize record displays for the Salesforce Mobile App.
What is the primary difference between a Task and an Event in Salesforce?
A **Task** is a to-do item with a due date, while an **Event** is a scheduled meeting or appointment with a start and end time.
tap to reveal
What is the purpose of the Activity Timeline in Lightning Experience?
To provide a chronological view of all past and upcoming activities (Tasks, Events, Emails) related to a specific record.
tap to reveal
Name the three types of Chatter Groups.
Public, Private, and Unlisted.
tap to reveal
Which Salesforce feature allows emails sent from records to be saved as records themselves, providing a complete communication history?
Enhanced Email.
tap to reveal
How do you notify a specific user in a Chatter post?
By using an **@mention** (e.g., @JohnDoe).
tap to reveal
What are two common types of email templates available in Salesforce?
Classic Email Templates and Lightning Email Templates.
tap to reveal
What is the main benefit of customizing compact layouts for the Salesforce Mobile App?
To display the most important fields at the top of a record detail page, optimizing the mobile user experience.
tap to reveal
What is Global Search used for in Salesforce?
To find records across most standard and custom objects from the search bar at the top of any page.
tap to reveal

Data and Analytics Management

Data and Analytics Management is crucial for understanding business performance and making informed decisions in Salesforce. This topic covers how to extract, analyze, and manage data effectively using Salesforce's built-in tools.

## Reports

Reports are lists of records that meet specific criteria, displayed in rows and columns. They are the foundation of Salesforce analytics.

  • Report Types: Determine which objects and fields are available in a report. Standard Report Types are pre-built by Salesforce. Custom Report Types allow you to define relationships between objects (up to 4 primary objects) to report on specific data combinations, essential when standard types don't meet requirements.
  • Report Formats:
  • Tabular: Simple list, no grouping. Good for lists like mailing labels.
  • Summary: Group rows by fields, show subtotals. Used for charts and most analysis.
  • Matrix: Group rows and columns, show subtotals. Good for comparing related totals.
  • Joined: Combine up to 5 blocks of different report types in a single report, each with its own fields, filters, and sort order.
  • Filtering & Grouping: Use filters to narrow down results (e.g., date ranges, field values). Cross Filters allow you to filter a report based on the existence or non-existence of related records. Grouping fields in Summary or Matrix reports allows for aggregation (sum, average, min, max).
  • Folders & Sharing: Reports are stored in folders, which control visibility and access for users, roles, or public groups.

## Dashboards

Dashboards visually display data from source reports, providing a high-level overview of key metrics and trends.

  • Components: Dashboards consist of various components like charts, gauges, metrics, and tables, each based on a single source report.
  • Running User: This is critical. A Static Dashboard runs as a specific user, and all viewers see data based on that user's security settings. A Dynamic Dashboard runs as the logged-in user, meaning each viewer sees data according to their own access permissions. You can have up to 5 dynamic dashboards for Enterprise Edition (more for Unlimited).
  • Folders & Sharing: Similar to reports, dashboards are stored in folders to manage access.

## Data Management for Analytics

Effective analytics relies on clean, accurate data.

  • Data Quality: Implement Duplicate Rules and Matching Rules to identify and prevent duplicate records, ensuring data integrity.
  • Data Export: Salesforce offers a Weekly Export Service (or monthly for some editions) to back up data, which can also be used for external analysis. The Data Loader can also be used for manual data exports.
  • Custom Report Types are necessary when standard report types don't provide the required object relationships for reporting.
  • Dynamic Dashboards display data based on the viewing user's security settings, while Static Dashboards show data based on a specified running user.
  • Joined Reports combine up to five blocks of different report types into a single report for comprehensive analysis.
  • Summary reports are essential for grouping data, calculating totals, and displaying charts in dashboards.
  • Cross Filters allow reports to filter primary records based on the existence or absence of related records.
  • Duplicate Rules help maintain data quality by preventing or alerting users to the creation of duplicate records.
  • Report and Dashboard folders control access and visibility for users, roles, or public groups.
What are the four main report formats in Salesforce?
Tabular, Summary, Matrix, and Joined.
tap to reveal
When would you create a Custom Report Type?
When standard report types don't include the necessary objects or fields, or don't define the correct relationships between objects.
tap to reveal
Explain the difference between a Static and Dynamic Dashboard.
A Static Dashboard runs as a specified user, showing the same data to everyone. A Dynamic Dashboard runs as the logged-in user, showing data based on each viewer's security settings.
tap to reveal
What is the purpose of a Cross Filter in a Salesforce report?
To filter primary records in a report based on the existence or absence of related records (e.g., Accounts with or without Cases).
tap to reveal
Which report format is required to display charts in a dashboard?
Summary or Matrix reports, as they allow for grouping and aggregation of data.
tap to reveal
How do Duplicate Rules contribute to data quality?
They identify and prevent users from creating duplicate records, or alert users when duplicates are detected, ensuring data accuracy and integrity.
tap to reveal
What is the primary use case for a Joined Report?
To view different types of related information side-by-side in a single report, combining up to five blocks of different report types.
tap to reveal

Workflow and Process Automation

Salesforce provides several powerful declarative tools to automate business processes, enhance efficiency, and maintain data integrity. Understanding these tools and their appropriate use cases is crucial for a Salesforce Administrator.

## Workflow Rules

Workflow Rules are the oldest automation tool, primarily used for simple, single-object automation. While still functional, Salesforce recommends using Flow for new automation. They consist of evaluation criteria (e.g., created, created & every time it's edited) and rule criteria.

  • Actions: Task (assigns a task), Email Alert (sends an email), Field Update (changes a field on the triggered record or its master in a master-detail relationship), Outbound Message (sends data to an external system).

## Process Builder

Process Builder is a more powerful, node-based automation tool that extends the capabilities of Workflow Rules. Salesforce is also deprecating Process Builder in favor of Flow.

  • It can automate processes across multiple objects and perform more complex actions than Workflow Rules.
  • Key capabilities: Creating records, updating any related record (parent, child, or unrelated via lookup), invoking a Flow, calling Apex code, posting to Chatter.

## Flow Builder

Flow Builder is Salesforce's most powerful and recommended declarative automation tool. It can handle almost any business process automation requirement, offering high flexibility and control.

  • Flow types:
  • Screen Flow: Guides users through a business process with screens for input.
  • Record-Triggered Flow: Launches when a record is created, updated, or deleted (can be before-save or after-save).
  • Schedule-Triggered Flow: Runs at specified times and frequencies.
  • AutoLaunched Flow (No Trigger): Can be invoked by Apex, Process Builder, or REST API.
  • Elements include: Get Records, Create Records, Update Records, Delete Records, Decisions, Assignments, and Actions.

## Approval Processes

Approval Processes are used to automate the process of approving records that require multiple steps or multiple approvers.

  • They define the entry criteria, approval steps (with assigned approvers), and actions to be taken at each stage (initial submission, final approval, final rejection, recall).
  • Actions are similar to Workflow Rules (Field Update, Email Alert, Task, Outbound Message).

## Choosing the Right Tool

  • For new automation, Flow Builder is almost always the preferred choice due to its versatility and power.
  • Use Approval Processes specifically for multi-step record approval workflows.
  • Understand Workflow Rules and Process Builder for maintaining existing automation in an org, but avoid them for new implementations where Flow is capable.
  • Flow Builder is Salesforce's most powerful and recommended declarative automation tool.
  • Workflow Rules can trigger Tasks, Email Alerts, Field Updates, and Outbound Messages.
  • Process Builder can create records and update related records, unlike Workflow Rules.
  • Approval Processes manage multi-step record approval workflows.
  • Record-Triggered Flows run when a record is created, updated, or deleted.
  • Screen Flows require user interaction and input through screens.
  • Workflow Rules and Process Builder are being deprecated in favor of Flow for new automation.
  • Before-save Record-Triggered Flows are generally faster than after-save flows for field updates on the triggering record.
What are the four types of actions available with Workflow Rules?
Task, Email Alert, Field Update, Outbound Message.
tap to reveal
Which automation tool is Salesforce's recommended solution for new declarative automation?
Flow Builder.
tap to reveal
When would you use an Approval Process?
To automate multi-step approval requirements for records.
tap to reveal
What is a key capability of Process Builder that Workflow Rules lack?
Creating records or updating related records (e.g., child records or unrelated records via lookup).
tap to reveal
Name two types of Flows.
Screen Flow, Record-Triggered Flow, Schedule-Triggered Flow, AutoLaunched Flow (any two).
tap to reveal
What is the primary difference between a 'before-save' and 'after-save' Record-Triggered Flow?
Before-save flows run before the record is committed to the database and are faster for updating the triggering record's fields, as they don't require an extra DML operation.
tap to reveal
Can Workflow Rules update fields on a related record (e.g., a child record or a lookup-related record)?
No, Workflow Rules can only update fields on the record that triggered the rule or its master record in a master-detail relationship.
tap to reveal

Security and Access

## Salesforce Security and Access

Salesforce employs a robust, layered security model to control access to data at various levels. Understanding this hierarchy is crucial for administrators.

## Organization-Wide Defaults (OWD)

Organization-Wide Defaults (OWD) are the baseline security settings for records in your Salesforce org. They define the default access level for records an owner *does not* own. OWDs are the most restrictive settings possible and should be set first. Options include:

  • Private: Only the record owner and users above them in the role hierarchy can view, edit, and report on records. No one else can access them.
  • Public Read Only: All users can view and report on records, but only the owner and users above them in the role hierarchy can edit them.
  • Public Read/Write: All users can view, edit, and report on records.
  • Controlled by Parent: Access is determined by the related parent record's OWD setting (for detail records in a master-detail relationship).

## Role Hierarchy

The Role Hierarchy opens up access vertically. Users at any given role level can automatically view, edit, and report on all records owned by users below them in the hierarchy, regardless of the OWD settings. This is a powerful way to grant managers access to their team's data.

## Sharing Rules

Sharing Rules open up access horizontally. They extend access to records beyond OWDs and the role hierarchy based on specific criteria or record ownership. Sharing rules can be:

  • Criteria-based: Grants access to records that meet certain field criteria (e.g., all 'High Priority' cases).
  • Owner-based: Grants access to records owned by users in a specific role or group (e.g., all cases owned by the 'Support Team' role).

## Manual Sharing

Manual Sharing allows individual record owners or users with 'Full Access' to a record to grant read or read/write access to specific users, public groups, or roles. This is used for ad-hoc, one-off sharing situations.

## Profiles and Permission Sets

Profiles define a user's baseline permissions, including object access (Create, Read, Update, Delete - CRUD), Field-Level Security (FLS), app access, tab visibility, page layout assignments, and system permissions (e.g., 'Modify All Data'). Every user must have exactly one profile.

Permission Sets extend a user's functional access without changing their profile. They grant additional permissions and settings (e.g., more object permissions, specific field access, custom app access). Users can have multiple permission sets, and they are additive to the profile.

Field-Level Security (FLS) controls whether a user can see, edit, or delete the value for a particular field on an object. This is set at the profile or permission set level.

## Organization Security Controls

Administrators can configure various org-wide security settings:

  • Password Policies: Define password requirements, expiration, and lockout settings.
  • Login IP Ranges: Restrict user logins to specific IP addresses.
  • Login Hours: Restrict when users can log in.
  • Multi-Factor Authentication (MFA): Requires users to verify their identity with a second factor (e.g., authenticator app) in addition to their username and password.
  • Health Check: A tool to assess and improve the security posture of your Salesforce org against a security baseline.
  • Session Settings: Control session timeout, security levels, and IP address enforcement for sessions.
  • Organization-Wide Defaults (OWD) are the most restrictive baseline for record access.
  • The Role Hierarchy grants vertical record access, allowing managers to see records owned by their subordinates.
  • Sharing Rules grant horizontal record access based on criteria or ownership, extending beyond OWDs and roles.
  • Profiles define a user's base object, field, app, and system permissions.
  • Permission Sets grant additional permissions to users, supplementing their profile.
  • Field-Level Security (FLS) controls the visibility and editability of individual fields.
  • Multi-Factor Authentication (MFA) significantly enhances login security by requiring a second verification method.
  • Salesforce Health Check assesses your org's security settings against a security baseline.
What is the most restrictive level of data access in Salesforce?
Organization-Wide Defaults (OWD)
tap to reveal
How does the Role Hierarchy impact record access?
It grants vertical access, allowing users to see records owned by those below them in the hierarchy.
tap to reveal
What is the primary purpose of Sharing Rules?
To grant horizontal record access based on criteria or ownership, extending beyond OWDs and the role hierarchy.
tap to reveal
What defines a user's base object, field, and app permissions?
Their Profile
tap to reveal
How can you grant *additional* permissions to a user without changing their profile?
By assigning a Permission Set
tap to reveal
What controls whether a user can see or edit a specific field on a record?
Field-Level Security (FLS)
tap to reveal
What security feature helps prevent unauthorized logins by requiring a second verification method?
Multi-Factor Authentication (MFA)
tap to reveal
Which tool helps administrators assess and improve their org's security settings?
Health Check
tap to reveal