SF Access Explainer
3 ratings
)Overview
Shows whether a chosen user has Read/Edit access to a Salesforce record and explains every sharing source that grants it.
"Why can't this user see this record?" is one of the most time-consuming questions to answer in Salesforce. Sharing access can come from a dozen different places at once: role hierarchy, ownership, manual shares, sharing rules, account/case teams, territories, Apex managed sharing, or a profile-level "View/Modify All" override that bypasses sharing entirely. Normally, answering it means jumping between Setup pages, Sharing Detail buttons, and guesswork. SF Access Explainer answers it in one click. On any Salesforce Lightning record page, it shows whether a chosen user has Read, Edit, or Delete access to that record, and explains exactly why, by enumerating every sharing source that grants it, or ruling each one out. No OAuth, no external servers, no data collection. It reuses your existing browser session against Salesforce (your sid cookie) to call the Salesforce REST API directly from your browser to your own org. Nothing is sent anywhere else, ever. Features: • Access Verdict: Read/Edit/Delete badges, max access level, transfer, and full-access flags, computed from UserRecordAccess. • Why: every sharing source that grants access, object-level ViewAllRecords/ModifyAllRecords overrides, record ownership, manual shares, sharing rules, teams, implicit sharing, territories, and Apex managed sharing, each attributed to the specific share row and access level. • What was checked: every query run, including shares that exist on the record but don't apply to the target user, so a "no access" verdict is fully explainable rather than a dead end. • Switch user: search for and inspect access for any user in your org (requires View All Data for non-self lookups). The default target is always yourself, so it works out of the box with no setup. • Works with standard and custom objects: it automatically handles the differences between standard share tables (e.g. AccountShare) and custom object share tables (e.g. Invoice__Share), and explains when an object has no share table at all (Public Read/Write org-wide defaults, or Controlled by Parent). Built for Salesforce admins, developers, and consultants who need to debug access issues, audit sharing configuration, or explain "who can see what and why" during a security review, without digging through Setup by hand. This is a read-only diagnostic tool. It does not modify any records, sharing rules, or settings in your org.
5 out of 53 ratings
Details
- Version1.0.0
- UpdatedSeptember 23, 2026
- Size30.39KiB
- LanguagesEnglish (United States)
- Developer
Email
cersosimobrian@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
SF Access Explainer has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
SF Access Explainer handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes