Filed at 10,000 m, lands at 3,000 m.Architecture

Your org chart is now a security boundary

Why every restructure quietly becomes an access review.

In this descent, 2 stops

Every restructure is an access decision

Every restructure gets a slide deck, a new reporting line and a farewell morning tea. What it rarely gets is an access review, even though the org chart is now wired straight into who can see what. In most large Salesforce orgs the role hierarchy, the sharing rules and half the approval processes are copies of the org chart from about three restructures ago. Nobody updated them because nobody was asked to.

That is a risk question, not an IT question. When a team moves from one division to another, its access either follows it, stays behind, or quietly doubles. The third option is the most common and the least visible. The cost of finding it later is an audit finding, a remediation project and an awkward conversation with the regulator, usually in that order.

Model access on things that change slowly

The fix is to stop treating the role hierarchy as a mirror of the org chart. Model access around the things that change slowly, such as business units, regions and data ownership, and let reporting lines move without dragging visibility with them. Public groups keyed to a business capability survive a restructure far better than roles named after a general manager who left in March.

If a restructure needs a deployment, the access model is built on the wrong thing.

Then make restructures trigger something. A change to a business unit should raise a ticket for the platform team with the affected groups, sharing rules and queues already listed. It is not glamorous. It does mean the access review happens in the same week as the announcement, not eighteen months later when an auditor finds it for you.

Nathan Avatar

More about Nathan

Where next