> For the complete documentation index, see [llms.txt](https://docs.rox.com/development/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.rox.com/development/product/governance/access-provenance.md).

# Access Provenance

Trace why and how users can access records and fields, and identify who else has access.

## Overview

Access Provenance explains the current **"access paths"** created by **Rox Governance**.

It consists of paths coming from either ownership, Pods, hierarchies, sharing, cascades, organization-wide defaults(OWDs), or Permission Sets.

## What is an "Access Path"?

**An access path is the chain of Governance settings that connects a user to a record or field**.

A user may have multiple paths to the same record, and Rox applies the most permissive access available.

### An example: Access through a user-based hierarchy

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FPpOf820ZXQ9S43hOXhLU%2Fimage.png?alt=media&amp;token=9a62f06e-287c-4b25-84eb-f91d54afd2f7" alt=""><figcaption><p>The graph’s blue boxes represent users, green boxes represent Pods, and the green border around the Account represents Full access. You can find this info in legend for any access provenance graph.</p></figcaption></figure>

As you can see in the above picture, Ishan has **FULL** access to the Instituto Account. How?

1. Ishan is a member of the CXO Pod.
2. The CXO Pod sits above the Sales Global Leader Pod.
3. Stephen is a member of the Sales Global Leader Pod.
4. Stephen is the Account’s Primary Owner, giving him Full access.
5. The user-based hierarchy rolls Stephen’s Full access up to members of the CXO Pod, including Ishan.

This access path shows how access travels through connected Rox Governance entities.

## Why use Access Provenance?

Consider a global sales organization with thousands of users, multiple territories, and several management levels. After a territory reorganization, a strategic Account moves from the EMEA team to the North America team. But an EMEA Sales Director can still access its Deals and activity.

That access could come from an outdated Pod membership, the management hierarchy, ownership, direct sharing, an OWD, or a Permission Set such as 'View All'.

Access Provenance shows the **exact paths** and **access level**. The administrator can determine whether the access is intentional and remove only the incorrect grant without disrupting access for other teams.

## What you can investigate

1. **User Access:** Why can this user access a record or field, and how?
2. **Record Access:** Who can access this record, and how?
3. **Field Access:** Who can read or edit this field?

## Before you begin

* [x] Confirm you can manage Governance settings.
* [x] Identify the user, record, or field you want to investigate.
* [x] Have the record ID ready when using Record Access.

## Investigate access using Access provenance

Go to **Settings → Governance**. Select "**Access Provenance**" tab.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2Fd07MTyLe4FQxdKIGZ7su%2Fimage.png?alt=media&amp;token=8f97b89c-4356-48fe-a24e-d0ab483467db" alt=""><figcaption></figcaption></figure>

Choose a view based on what you want to investigate.

### 1. User Access

{% hint style="info" %}
Use User Access to understand what one user can access, and why.
{% endhint %}

{% tabs %}
{% tab title="Record: Trace access to a record" %}
{% stepper %}
{% step %}

### Select the resource type

Click on User access **→** "Record" tab **→** Select the resource type

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2F5lule7oGeqyH7oqlKm6P%2Fimage.png?alt=media&amp;token=c1b77786-77a7-4172-afca-b74158d354a4" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select the right user you want to investigate

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FofTg8f0I0DtP5pqrRJ5b%2Fimage.png?alt=media&amp;token=662493b2-1dbd-40c0-b9eb-8784d3a81f70" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select one of their accessible records

Enter the record ID or name.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FpzruDNoA43CLqPDbsN8F%2Fimage.png?alt=media&amp;token=815d9298-0b7a-4eff-8039-746b3fa050e8" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Review the paths connecting the user to the record.

Scroll down to view the complete legend. For complex graphs, select **Full screen** option at the bottom of the graph. You can then reposition nodes for a clearer view.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2F0TE3aqOs0jF48WWChjCu%2Fimage.png?alt=media&amp;token=f4cc7d07-f13b-4e18-b94b-65bb68f37e17" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Click on a Pod to inspect its members

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FwAt5GghiMPKDplWS5yxh%2Fimage.png?alt=media&amp;token=3219676e-9784-4c48-b567-5da42dbfaed7" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="Field: Review a user’s field access" %}
{% stepper %}
{% step %}

### Select the resource type

Click on User access **→** "Field" tab **→** Select the resource type

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FZV6uED8nfYMKqfXd3pzC%2Fimage.png?alt=media&amp;token=15c774ef-7f1d-4e72-9717-5639f2c69019" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select the right user you want to investigate

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FvKPTDi62jyUaZmE2inTj%2Fimage.png?alt=media&amp;token=2c0607a7-82bd-4b8a-904e-06ef572b6af3" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select a field to inspect (optional)

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2Fnv7rQcGIoKi7OPqovXBv%2Fimage.png?alt=media&amp;token=f30a7eda-f06a-4000-8c30-7b154adffab0" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Review the paths connecting the user to the field.

For complex graphs, select **Full screen** option at the bottom of the graph

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FgsLxa62PrEoHrWfGaVy9%2Fimage.png?alt=media&amp;token=3172bfde-f430-404c-b6c0-3423363df693" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="Record and Field" %}
{% stepper %}
{% step %}

### Select the resource type

Click on User access **→** "Record + Field" tab **→** Select the resource type

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FdyplfUaojvbV3b0HyZQn%2Fimage.png?alt=media&amp;token=1978fe72-0546-4dce-92a9-8dee6faa2f2c" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select the right user you want to investigate

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FutFykkgtrMfEsb8MSoTc%2Fimage.png?alt=media&amp;token=8aebcd58-2e6a-4bd1-aea5-55f14a7eb980" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select an accessible record

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2Fd6FOgwL75aLPnX0My3oo%2Fimage.png?alt=media&amp;token=da267b18-018e-4223-9d3d-b6aa0aa508c1" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select the field (optional)

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FrM42xsCRWU4Pjl4eOQzH%2Fimage.png?alt=media&amp;token=b339f61f-99e0-4ec8-ad84-fd7f76700366" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Review how resource, record, and field access combine

For complex graphs, select **Full screen** option at the bottom of the graph

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FWU6U626uPFr5o5hwRxZE%2Fimage.png?alt=media&amp;token=27363145-a78d-4095-9e0b-a013d3c4d94e" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}
{% endtab %}
{% endtabs %}

### 2. Record Access

{% hint style="info" %}
Use Record Access to identify everyone who can access a record, and why.
{% endhint %}

{% stepper %}
{% step %}

#### Select Record Access and choose resource type

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FNkXoXwbtAWSe81Lfxar2%2Fimage.png?alt=media&amp;token=2fa3c93a-63df-4ed8-abbe-b2c83a4fa8b0" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Paste the record ID

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FzpMG7E4oZC34TzFwoHqA%2Fimage.png?alt=media&amp;token=bc3ae987-33b4-45ae-9395-e92e861c330e" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Review its access paths

Scroll down to view the complete legend. For complex graphs, select **Full screen** option at the bottom of the graph. You can then reposition nodes for a clearer view.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2F9JkxUPM7CDHDafaX31GN%2Fimage.png?alt=media&amp;token=a80bc723-5f03-4a8b-8d72-71da255f2df7" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Select a Pod to inspect the users receiving access through it

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FEEgeJKTm5I8qNJyY6hyi%2Fimage.png?alt=media&amp;token=236d2a5c-eecb-46e4-b143-dd0241357084" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

### 3. Field access

{% hint style="info" %}
Use Field Access to identify who can read or edit a field.
{% endhint %}

{% stepper %}
{% step %}

#### Select Field Access and choose resource type

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FxY57gVy4tUGM0cvGsGdN%2Fimage.png?alt=media&amp;token=4ba4e762-cab1-491e-b0ea-63581659d23b" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Select the field

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FuY3yVA0XfuwMYRJphUVM%2Fimage.png?alt=media&amp;token=4c076a25-4cd4-44bc-998b-8d63ed9d5f1d" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Choose the minimum access: Read or Edit.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FAD3QwoAGcZK1ul5kkPga%2Fimage.png?alt=media&amp;token=1312186a-7945-4f25-a9ae-dfa77f8a5d48" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

#### Review the users and settings granting that access

For complex graphs, select **Full screen** option at the bottom of the graph. You can then reposition nodes for a clearer view.

Select a Pod or Permission Set to inspect the users receiving access through it.

<figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FjG7N0oUr6pEMp6sGigdI%2Fimage.png?alt=media&amp;token=4514e00f-5ded-4592-ae8e-75966a482f4f" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

## Best practices

1. **Check broad grants first.** OWDs, 'View All', and 'Modify All' sets can affect large groups of users.
2. **Protect sensitive fields intentionally.** Set the baseline(OWDs) to **Hidden** when values must be hidden or redacted, then use Permission Sets to grant masked access (such as Hash or Last 4 characters) or full visibility only to users who need it.\
   If everyone with record access may read a field but only selected users should edit it, use a Read-only OWD and grant Editable access through Permission Sets.\
   **Use Field Access to verify the result**.
3. **Preview and verify changes**. Use **Simulate removal** before changing a field Permission Set, then rerun Access Provenance.<br>

   <figure><img src="https://2986926806-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBzWA2LkfjbdaffIaGlN%2Fuploads%2FVPc7AKoeoC4iTU5ea75H%2Fimage.png?alt=media&amp;token=91a1c1d8-cbf4-4227-85f9-24dcd2e6f8c3" alt=""><figcaption></figcaption></figure>
4. **Fix the source of access**. Update the Pod, hierarchy, sharing, ownership, baseline(OWD), or Permission Set identified by the graph. **Review every path before changing access**.

## Related

* [OWDs](https://docs.rox.com/development/product/governance/organization-wide-defaults-owds)
* [Rox Governance (Engineering)](https://docs.rox.com/development/engineering/governance)
