Pros and cons of using sharing rules vs manual sharing for quote access control in CPQ

We’re implementing Salesforce CPQ and need to decide on our quote access control strategy. The debate is between automated sharing rules versus manual sharing (potentially Apex-managed) for granting quote access to finance, legal, and approval teams.

Our requirements: Sales reps own quotes, but finance needs read access to quotes over $100K, legal needs access to quotes with custom terms, and regional VPs need access to all quotes in their region regardless of owner. We have about 15,000 quotes created annually across four regions.

Sharing rules seem straightforward but I’m concerned about the performance impact of criteria-based sharing rules evaluating on every quote create/update. Manual sharing gives us precise control but requires custom code to maintain, and I worry about auditability when sharing is programmatically managed.

What approaches have worked well for others managing CPQ record access in complex org structures? Particularly interested in maintenance burden and how you handle audit requirements around quote visibility.

Both approaches are viable at your scale, but they carry meaningfully different tradeoffs across the dimensions that matter for CPQ access control.

Criteria Comparison

Criteria Criteria-Based Sharing Rules Apex-Managed (Manual) Sharing
Configuration complexity Admin-level, declarative Requires Apex triggers/batch jobs, code review cycle
Maintenance burden Low — rule changes via Setup High — code deploys for logic changes
Performance at 15K records/yr Generally acceptable; async recalculation can lag Synchronous or batch-controlled; predictable execution timing
Precision of logic Limited to field comparisons and role hierarchy Full Apex logic — compound conditions, external callouts, dynamic criteria
Auditability Sharing rule definitions visible in Setup; individual record shares visible in Sharing Detail button Record-level shares logged in QuoteShare object; requires custom audit trail for why a share was granted
Bulk recalculation behavior Platform handles via Sharing Rule Recalculation async job Batch Apex must be authored and monitored manually
CPQ-specific risk Criteria rules tied to SBQQ__Quote__c fields — works if fields are populated pre-save CPQ multi-step save process can cause field population timing issues; trigger entry point matters

Key Architectural Considerations

For your finance use case (quotes > $100K), a criteria-based sharing rule on SBQQ__Quote__c.SBQQ__NetAmount__c (verify field API name in your version) is the lowest-risk path. The async recalculation lag — typically seconds to minutes — is acceptable for read access to high-value quotes. Test recalculation behavior specifically under Defer Sharing Calculations if your org uses it.

For legal’s custom-terms flag, same approach applies if you have a reliable checkbox or picklist field set before the record shares need to be evaluated. If the flag is set late in a multi-step CPQ flow, sharing rule evaluation may fire before the field is populated — this is where Apex-managed sharing gives you explicit control over when sharing is applied.

For regional VP access, role-hierarchy-based sharing rules are the cleanest fit. A role-based sharing rule granting VP roles read access to all quotes owned by subordinates is trivial to configure and requires zero code.

On auditability: QuoteShare (the implicit share object) records every row with RowCause. Apex-managed shares use RowCause = Manual unless you define a custom share reason (verify availability in your version) — do this if you need to distinguish finance shares from legal shares in compliance reporting. Criteria-based shares surface as RowCause = SharingCriteriaRule, which is already distinguishable.

Hybrid pattern: Use declarative sharing rules for the finance and VP use cases; scope Apex-managed sharing only to the legal custom-terms scenario where timing control justifies the complexity. Keep the Apex share logic in a single service class with an explicit audit log to a custom object if compliance requires it.

Ultimately this depends on context / your requirements — specifically your compliance obligations, CPQ save flow configuration, and whether your team has bandwidth to own Apex-managed sharing long-term.


This draft is based on general Salesforce knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.

We use criteria-based sharing rules exclusively for CPQ quote access and haven’t seen performance issues. The key is to keep your criteria simple and indexed. For your scenario, I’d create three sharing rules: one for finance (Amount >= 100000), one for legal (Custom_Terms__c = true), and one for regional VPs (based on Region field). Sharing rules recalculate asynchronously, so they don’t block quote creation. The maintenance is minimal - we review them quarterly. The big advantage is that the sharing logic is visible in Setup, which auditors appreciate. They can see exactly how access is granted without needing to review code.

I’ll offer the counterpoint - we started with sharing rules and moved to Apex-managed sharing because of limitations. Sharing rules can’t handle complex logic like ‘grant access to finance team members in the same region as the quote owner’ or ‘grant access only during the approval process.’ We built an Apex class that manages quote shares based on quote stage and attributes. The code runs on quote creation and status changes. For auditability, we log all sharing operations to a custom object with timestamp, user, and reason. This gives us a complete audit trail that sharing rules don’t provide. The maintenance burden is real though - you need good test coverage and documentation.

From a security architecture perspective, start with sharing rules and only move to programmatic sharing when you hit a limitation. Sharing rules are declarative, easier to understand, and less prone to bugs. They also respect the platform’s security model automatically. With Apex-managed sharing, you’re taking on the responsibility of correctly implementing and maintaining security logic. That said, if your requirements truly need complex conditional logic that sharing rules can’t express, then Apex is necessary. Just make sure you’re not overengineering - I’ve seen orgs write custom code for scenarios that could be handled with two or three sharing rules.

One hybrid approach: use sharing rules for the static, predictable access patterns (like regional VP access based on region) and manual sharing for dynamic scenarios. For example, when a quote enters approval, use a Flow to manually share it with the approval team members. When approval completes, the Flow removes those manual shares. This keeps the complex logic visible in Flow Builder rather than buried in Apex, which helps with maintenance and auditability. You get the performance of sharing rules for bulk scenarios and the flexibility of manual sharing for workflow-driven access.

If you go the Apex route, here’s a code pattern we use successfully:


List<SBQQ__Quote__Share> shares = new List<SBQQ__Quote__Share>();
SBQQ__Quote__Share financeShare = new SBQQ__Quote__Share();
financeShare.ParentId = quote.Id;
financeShare.UserOrGroupId = financeGroupId;
financeShare.AccessLevel = 'Read';
shares.add(financeShare);
insert shares;

This runs in an after-insert trigger on Quote. The key is to bulkify properly and handle governor limits. We process shares in batches of 200 to stay under DML limits.

Auditability perspective: sharing rules are easier to audit because they’re configuration, not code. When we have SOX audits, I can show auditors the sharing rule setup and they can verify the criteria. With Apex-managed sharing, we have to walk through code logic, test classes, and hope the auditor understands Apex. That said, if you do use Apex, implement comprehensive logging as mentioned earlier. Log every share grant/revoke with the business reason. This audit trail is actually more detailed than what sharing rules provide, but it requires discipline to maintain.

After analyzing all perspectives and mapping them to our specific requirements, here’s my comprehensive assessment of the sharing rules vs manual sharing decision for CPQ quote access:

Sharing Rules vs Manual Sharing Trade-offs:

Sharing Rules Advantages:

  1. Declarative and Transparent: The logic is visible in Setup > Sharing Settings, making it easy for admins and auditors to understand without technical knowledge. This transparency is valuable for compliance reviews.

  2. Platform-Managed Performance: Salesforce optimizes sharing rule recalculation automatically. The async processing means quote creation isn’t blocked while sharing is calculated. For our 15K annual quotes, this is important.

  3. Lower Maintenance Burden: No code to maintain, test, or debug. Changes to sharing criteria are configuration changes that don’t require deployment or test coverage.

  4. Built-in Audit Trail: Setup Audit Trail tracks all sharing rule changes, providing a compliance record of who modified access rules and when.

Sharing Rules Limitations:

  1. Limited Conditional Logic: Can’t express complex conditions like ‘share with finance only during approval process’ or ‘share with legal team in the same region as quote owner.’

  2. Static Criteria: Based on field values at evaluation time. Can’t incorporate temporal logic or external system data.

  3. No Granular Control: Can’t easily grant access for a specific duration or revoke access based on workflow completion.

Manual Sharing (Apex-Managed) Advantages:

  1. Complex Logic Support: Can implement sophisticated rules like regional matching, approval stage-based access, or integration with external authorization systems.

  2. Dynamic Access Control: Can grant and revoke access based on workflow states, time periods, or business events.

  3. Detailed Logging: Custom audit logging can capture business context (why access was granted) beyond what platform audit trail provides.

Manual Sharing Challenges:

  1. Development and Maintenance Overhead: Requires Apex expertise, test coverage (minimum 75%), and ongoing maintenance as requirements evolve.

  2. Governor Limit Management: Must carefully handle bulk operations and DML limits, especially with large-scale sharing operations.

  3. Auditability Complexity: Requires custom logging implementation and documentation for auditors to understand the access control logic.

  4. Security Responsibility: You own the security implementation. Bugs in sharing code can create security vulnerabilities or unintended access.

CPQ Record Access Recommendations:

For your specific requirements, I recommend a hybrid approach:

Use Sharing Rules For:

  1. Regional VP Access: Create a sharing rule based on Quote Region field matching VP’s assigned region. This is static, predictable, and high-volume - perfect for sharing rules.

    • Rule: Share quotes where Region = ‘North’ with ‘North Region VPs’ public group (Read access)
    • Repeat for each region
  2. Finance High-Value Access: Criteria-based rule for quotes over $100K.

    • Rule: Share quotes where Amount >= 100000 with ‘Finance Review Team’ public group (Read access)
    • Indexed field ensures good performance

Use Flow-Managed Manual Sharing For:

  1. Legal Custom Terms Access: When Custom_Terms__c changes to true, use a Record-Triggered Flow to manually share with the legal team. When terms are finalized, remove the manual share.

    • Advantages: Access is granted only during active legal review, not permanently
    • Flow is visible to admins and easier to maintain than Apex
    • Provides audit trail through Flow execution logs
  2. Approval Process Access: During quote approval, Flow shares with approval team members. Post-approval, Flow removes those shares.

    • This prevents permanent access accumulation
    • Access is tied to business process state

Auditability and Maintenance Strategy:

  1. Documentation: Maintain an Access Control Matrix documenting:

    • Each sharing rule and its business purpose
    • Each Flow that manages manual sharing and when it triggers
    • Public groups used in sharing rules and their membership criteria
  2. Quarterly Reviews: Review sharing rules and Flow-managed sharing quarterly to ensure they still align with business requirements and haven’t created unintended access.

  3. Monitoring: Create a dashboard showing:

    • Number of quotes shared with each team (Finance, Legal, Regional VPs)
    • Manual share records created/removed by Flows
    • Any quotes with orphaned manual shares (shares that should have been removed but weren’t)
  4. Audit Trail: For manual shares managed by Flow:

    • Flow execution logs provide timestamp and reason
    • Add a custom field on Quote: Last_Shared_With__c and Last_Share_Date__c to track manual sharing history
    • Create a custom object QuoteAccessLog__c to record all manual share grants/revokes with business context

Implementation Approach:

Phase 1: Implement sharing rules for Regional VPs and Finance (static, high-volume scenarios). These are low-risk and provide immediate value.

Phase 2: Build and test Flow-managed manual sharing for Legal team access. Start with a simple trigger condition and validate the audit trail.

Phase 3: Implement approval process sharing via Flow, ensuring proper cleanup of manual shares post-approval.

Phase 4: Monitor for 90 days and adjust based on performance metrics and user feedback.

When to Consider Apex: Only move to Apex-managed sharing if:

  • Flow governor limits are exceeded (unlikely with 15K annual quotes)
  • You need complex logic that Flow can’t express (e.g., integration with external authorization system)
  • Performance testing shows Flow-managed sharing is too slow (rare)

The hybrid model gives you the best of both worlds: sharing rules handle predictable, high-volume scenarios with minimal maintenance, while Flow-managed manual sharing provides flexibility for workflow-driven access without the complexity of Apex. This approach is auditable, maintainable, and scales to your volume.