I have a Business Unit team (owner team) that has a custom security role associated to it. I have an account whose owner is this team. Whenever I log in as one of the team users with this security role (that the team is associated with under 'manage roles') and create an opportunity based on the account mentioned above, everyone in the team has full access to it to modify, delete it.
However the security role in question does not permit this. For the opportunity entity, the security profile only allows for 'user' level write, delete, assign access. And 'BU' level for Create, append to and share.
The moment I change the owner on the Account to an individual instead of the team, it works as expected and no one else on the team can modify, delete opportunity records that they did not create.
Is this expected behavior or am I misunderstanding the scope of the team in some way? Ideally I don't want every member of the team to be able to edit all opportunities that were created based on this account by another team member. Reads are fine, but not update/delete operations.
*This post is locked for comments
I have the same question (0)