Loading
Salesforce Enforces New Security Requirements in Summer 2026Read More
Manage Users and Data Access
Review Guest User Object, Record, and Field Access for Sites

Review Guest User Object, Record, and Field Access for Sites

When you allow public access to your Experience Cloud sites, make sure that unauthenticated guest users are able to access only the data that you want them to access. Use the Guest User Sharing Rule Access Report page in Setup to quickly see what objects, records, and fields are accessible to your guest users using guest user sharing rules. Experience Cloud sites are used in many ways. While the Guest User Sharing Rule Access Report page evaluates your configuration and flags potentially misconfigured sharing rules, only you know your site’s business needs. Carefully decide which records and fields are accessible to your guest users.

Required Editions

Available in: Lightning Experience
Available in: Enterprise, Performance, Unlimited, and Developer Editions
Applies to: LWR and Aura sites
User Permissions Needed
To access Guest User Sharing Rule Access Report:

Manage Users

AND

Customize Application

To access Experience Builder:

Create and Set Up Experiences

AND

Is a member of the Experience Cloud site

To edit object and field permissions in profiles:

Manage Profiles and Permission Sets

AND

Customize Application

Review all rows in the report, and then validate the intent of sharing the object with the guest user. We strongly recommend that you test any access changes in a sandbox environment before implementing them in production.

Keep these considerations in mind when using the Guest User Sharing Rule Access Report.

  • If an object returns more than 10,000 results, the results are an approximation and can skew lower. Converted leads may also be counted incorrectly as leads, rather than an account, an opportunity, and contacts.
  • The number of fields identified as having personal information are based on individual fields, not aggregate fields. For example, a name field is counted twice, for both first and last name.
  • The report is missing the following object counts: Solution, EmailMessage, Contact, CaseComment, Task, Note, Pricebook2, Partner, CollaborationGroup, AccountContactRelation. Use the Guest User Sharing rules you’ve created for these objects to check whether any of their records are viewable by guest users.
  • The Guest User Sharing Rule Access Report is available for LWR and Aura sites.
  • The Network object always shows in the report, as it houses the site.
  • Please be patient. Depending on the number of objects being reviewed, the page can take a few minutes to load.
  1. From Setup, in the Quick Find box, enter Guest User Sharing Rule Access Report, and then select Guest User Sharing Rule Access Report.
  2. Select a site from the dropdown, and review the report to see if any of your data is at risk of being accessible through the guest user record. Repeat this step for each site in your org.
  3. If you want to change object-level access, you can do so in the guest user record, profile, permission set, or permission set group. You can access the guest user profile through Digital Experiences | [Your Site’s Name] Builder | Settings | General | [Your Site’s Name] Profile.
  4. If access to records is granted through guest user sharing rules, review the rules’ criteria, and make any changes you need to.
  5. After changing access levels, refresh the page and check to ensure the tool reflects the access levels you have set.
  6. Test your access changes in a sandbox before changing them in production.
 
Loading
Salesforce Help | Article