Sharing setup

Domain scoping runs on Salesforce record sharing, so it depends on two org settings that live in Setup rather than in the Studio tab. Check them once, after install.

Set the org-wide default

Setup → Sharing Settings → Entity Domain → Organization-Wide Default: Private.

New installs arrive this way. Confirm it anyway — the org-wide default is yours to change, and ContextWorks cannot set it for you.

Private is what makes a grant mean anything. Left at Public Read/Write, every user holds every domain, every catalog is the full catalog, and nothing errors — the boundary simply isn’t there. The Access page reports which state you are in, because it is otherwise invisible.

Clear Grant Access Using Hierarchies

Setup → Sharing Settings → Entity Domain → clear Grant Access Using Hierarchies.

Left on, anyone above a domain’s owner in the role hierarchy inherits that domain without being granted it — and under the fallback rule, inheriting a domain takes them off the default one.

It only bites when a domain’s owner has a role. Admins commonly have none, in which case the setting does nothing either way. The Access page names any domain owned by someone with a role, so you can tell which case you are in.

What install does for you

StepDone by
Create the General domain and roster the default entitiesInstall
Share General with all internal usersInstall
Set Entity Domain to PrivateInstall, then yours to keep
Clear Grant Access Using HierarchiesYou, if it applies

After that, a reader needs only the ContextWorks User permission set.

What’s next