Category
Salesforce security
Field-level security: the layer people forget
You can lock down records perfectly and still expose the one field that mattered. Field-level security is the quiet last layer of Salesforce access.
Sharing rules: their power, and their risk
Sharing rules are how you open Salesforce access sideways. They are also the layer most likely to accumulate quietly until no one can explain it.
Safe with full access, by design
Read-only was never the real reason Who Sees What is safe to connect. The real reason is how it is engineered, and that is what lets the safety story hold even for tools that need to act.
The role hierarchy is not an org chart
Salesforce role hierarchies look like reporting lines, so people build them that way. That is where a lot of accidental access comes from.
Org-wide defaults: the floor of your sharing model
Org-wide defaults are the most consequential access setting in Salesforce, and the easiest to set once and forget. Here is how to think about them.
The Salesforce access layers, explained
Who can see a record in Salesforce is decided by seven layers stacked on top of each other. Here is what each one does, in plain language.

The quiet ways Salesforce access creeps wider
Access in Salesforce almost never shrinks on its own. Here are the everyday mechanisms that widen it, usually without anyone deciding to.