CCS - Go-Live: Users Access
In this article, the different areas of access configuration to Objects, Records and Fields will be outlined.
Object Level Permissions
Object Level Read, Create, Edit and Delete access is determined at the Profile level. If a Profile doesn’t have Read access at a minimum, Users won’t have access to any Records from that object.
Field Level Security
Field Level Security determines access to fields within a record and is again selected at Profile Level. It starts with visibility; if a Field is not visible to a Profile, they won’t see it on a record. If it is visible by default and the Profile has Edit access to the object, they can edit that field's value. If Users need to see the Field but not edit it, select Read-Only in the FLS settings.
Record Level Access
Organisation-wide Defaults
To define the default access level for an object’s records, use Organisation-wide Defaults. These settings can be configured for custom objects and many standard objects. You can determine different levels of record access for internal, external and guest users.
For most objects, organization-wide sharing settings can be set to Private, Public Read Only, or Public Read/Write. In environments where the organization-wide sharing setting for an object is Private or Public Read Only, an admin can grant users additional access to records by setting up a role hierarchy or defining sharing rules. However, sharing rules can only be used to grant additional access—they can’t be used to restrict access to records beyond what was originally specified with the organization-wide sharing defaults.
https://help.salesforce.com/s/articleView?id=sf.security_sharing_owd_about.htm&type=5
Page Layouts
Custom page layouts can be created and configured display specific content for different Apps and profiles. If a page layout is the Organisation Default, all User’s will be able to see the content of that page providing they have access to the Record, Objects and Fields.
Designing page layouts based on Profiles is a good way to de-clutter dense record pages and give users easy access to the information based on their roles and responsibilities within the organisation avoiding displaying information that's not relevant to them.
Lightning Apps
Dedicated Lightning Apps designed around the functional areas of the Organisation are a great way to direct users to targeted areas of information specific to their roles such as object tabs, dashboards and reports. Lightning App access can be determined at the Profile level.