After analyzing all perspectives and mapping them to our specific requirements, here’s my comprehensive assessment of the sharing rules vs manual sharing decision for CPQ quote access:
Sharing Rules vs Manual Sharing Trade-offs:
Sharing Rules Advantages:
-
Declarative and Transparent: The logic is visible in Setup > Sharing Settings, making it easy for admins and auditors to understand without technical knowledge. This transparency is valuable for compliance reviews.
-
Platform-Managed Performance: Salesforce optimizes sharing rule recalculation automatically. The async processing means quote creation isn’t blocked while sharing is calculated. For our 15K annual quotes, this is important.
-
Lower Maintenance Burden: No code to maintain, test, or debug. Changes to sharing criteria are configuration changes that don’t require deployment or test coverage.
-
Built-in Audit Trail: Setup Audit Trail tracks all sharing rule changes, providing a compliance record of who modified access rules and when.
Sharing Rules Limitations:
-
Limited Conditional Logic: Can’t express complex conditions like ‘share with finance only during approval process’ or ‘share with legal team in the same region as quote owner.’
-
Static Criteria: Based on field values at evaluation time. Can’t incorporate temporal logic or external system data.
-
No Granular Control: Can’t easily grant access for a specific duration or revoke access based on workflow completion.
Manual Sharing (Apex-Managed) Advantages:
-
Complex Logic Support: Can implement sophisticated rules like regional matching, approval stage-based access, or integration with external authorization systems.
-
Dynamic Access Control: Can grant and revoke access based on workflow states, time periods, or business events.
-
Detailed Logging: Custom audit logging can capture business context (why access was granted) beyond what platform audit trail provides.
Manual Sharing Challenges:
-
Development and Maintenance Overhead: Requires Apex expertise, test coverage (minimum 75%), and ongoing maintenance as requirements evolve.
-
Governor Limit Management: Must carefully handle bulk operations and DML limits, especially with large-scale sharing operations.
-
Auditability Complexity: Requires custom logging implementation and documentation for auditors to understand the access control logic.
-
Security Responsibility: You own the security implementation. Bugs in sharing code can create security vulnerabilities or unintended access.
CPQ Record Access Recommendations:
For your specific requirements, I recommend a hybrid approach:
Use Sharing Rules For:
-
Regional VP Access: Create a sharing rule based on Quote Region field matching VP’s assigned region. This is static, predictable, and high-volume - perfect for sharing rules.
- Rule: Share quotes where Region = ‘North’ with ‘North Region VPs’ public group (Read access)
- Repeat for each region
-
Finance High-Value Access: Criteria-based rule for quotes over $100K.
- Rule: Share quotes where Amount >= 100000 with ‘Finance Review Team’ public group (Read access)
- Indexed field ensures good performance
Use Flow-Managed Manual Sharing For:
-
Legal Custom Terms Access: When Custom_Terms__c changes to true, use a Record-Triggered Flow to manually share with the legal team. When terms are finalized, remove the manual share.
- Advantages: Access is granted only during active legal review, not permanently
- Flow is visible to admins and easier to maintain than Apex
- Provides audit trail through Flow execution logs
-
Approval Process Access: During quote approval, Flow shares with approval team members. Post-approval, Flow removes those shares.
- This prevents permanent access accumulation
- Access is tied to business process state
Auditability and Maintenance Strategy:
-
Documentation: Maintain an Access Control Matrix documenting:
- Each sharing rule and its business purpose
- Each Flow that manages manual sharing and when it triggers
- Public groups used in sharing rules and their membership criteria
-
Quarterly Reviews: Review sharing rules and Flow-managed sharing quarterly to ensure they still align with business requirements and haven’t created unintended access.
-
Monitoring: Create a dashboard showing:
- Number of quotes shared with each team (Finance, Legal, Regional VPs)
- Manual share records created/removed by Flows
- Any quotes with orphaned manual shares (shares that should have been removed but weren’t)
-
Audit Trail: For manual shares managed by Flow:
- Flow execution logs provide timestamp and reason
- Add a custom field on Quote: Last_Shared_With__c and Last_Share_Date__c to track manual sharing history
- Create a custom object QuoteAccessLog__c to record all manual share grants/revokes with business context
Implementation Approach:
Phase 1: Implement sharing rules for Regional VPs and Finance (static, high-volume scenarios). These are low-risk and provide immediate value.
Phase 2: Build and test Flow-managed manual sharing for Legal team access. Start with a simple trigger condition and validate the audit trail.
Phase 3: Implement approval process sharing via Flow, ensuring proper cleanup of manual shares post-approval.
Phase 4: Monitor for 90 days and adjust based on performance metrics and user feedback.
When to Consider Apex:
Only move to Apex-managed sharing if:
- Flow governor limits are exceeded (unlikely with 15K annual quotes)
- You need complex logic that Flow can’t express (e.g., integration with external authorization system)
- Performance testing shows Flow-managed sharing is too slow (rare)
The hybrid model gives you the best of both worlds: sharing rules handle predictable, high-volume scenarios with minimal maintenance, while Flow-managed manual sharing provides flexibility for workflow-driven access without the complexity of Apex. This approach is auditable, maintainable, and scales to your volume.