Sharing setup
Domain scoping runs on Salesforce record sharing, so it depends on two org settings that live in Setup rather than in the Studio tab. Check them once, after install.
Set the org-wide default
Setup → Sharing Settings → Entity Domain → Organization-Wide Default: Private.
New installs arrive this way. Confirm it anyway — the org-wide default is yours to change, and ContextWorks cannot set it for you.
Private is what makes a grant mean anything. Left at Public Read/Write, every user holds every domain, every catalog is the full catalog, and nothing errors — the boundary simply isn’t there. The Access page reports which state you are in, because it is otherwise invisible.
Clear Grant Access Using Hierarchies
Setup → Sharing Settings → Entity Domain → clear Grant Access Using Hierarchies.
Left on, anyone above a domain’s owner in the role hierarchy inherits that domain without being granted it — and under the fallback rule, inheriting a domain takes them off the default one.
It only bites when a domain’s owner has a role. Admins commonly have none, in which case the setting does nothing either way. The Access page names any domain owned by someone with a role, so you can tell which case you are in.
What install does for you
| Step | Done by |
|---|---|
| Create the General domain and roster the default entities | Install |
| Share General with all internal users | Install |
| Set Entity Domain to Private | Install, then yours to keep |
| Clear Grant Access Using Hierarchies | You, if it applies |
After that, a reader needs only the ContextWorks User permission set.
What’s next
- Domain access — who gets which catalog.
- Access and cache — the health report.