Friends don't let friends Set View-All

By , Salesforce CTA·1 min read·First shared on LinkedIn,

You’ve set your Account OWD to Private. You’ve tightened your Sharing Rules. You feel secure. Then, someone says: "We just need 'View All' on this one child Object." You think: "It’s fine, the parent Accounts are still locked down."

Wrong! You just handed over the keys to your entire customer list.

The "Leakiest Link" Problem

Implicit Sharing is the silent architect of data leaks. Even if a user shouldn't see an Account, if they have access to a record that looks up to it, Salesforce often resolves that relationship by showing the Name.

A tech-savvy user can use this "leak" to scrape your entire Customer List via reports or list views. This isn't just a security risk, it’s the kind of architectural oversight that fails a CTA Board.

Quick Recommendations

Option 1: Avoid "View All" - My recommendation

Option 2: The "Global Switch"

You could enable "Require permission to view record names in lookup fields" but beware the UX side effects. Sometimes you want that behavior for context; turning it off can leave users flying blind.

And always: Audit Lookup Fields: Be mindful of what parent data is exposed on child records.

The Lesson: Security isn't just about who can see the record; it’s about what the record reveals about its neighbors. Don't let implicit sharing be the leak that sinks your ship.

Note on the screenshot: The screenshot is taken from a demo org with exactly this setup (Private Account, View All Invoices, Require permission to view record names in lookup fields = False).

Agentforce vibes delivered

The entire demo was built using, I didn't have to open Setup even once to configure the scenario.

Is your Org carrying this kind of dirt?
Book a free 60-minute Salesforce Technical Debt Audit: a score for Usability and Build Quality, and your top cleanup priorities.