You are here:
Best Practices and Considerations When Working with the Site Guest User Record
Keep these best practices and considerations in mind when configuring the site guest user record.
Required Editions
| Available in: Essentials, Enterprise, Performance, Unlimited, and Developer Editions |
General Best Practices and Considerations
- Enforce authentication where possible, and lock down access to the site guest user.
Email Field
- The best practice is for an organization to have a verified Organization-Wide Email Address, and use that email address in the guest user record. Salesforce blocks any email sent from an unverified email address. The email address on the guest user record might be used in features like custom flows, which can send notifications and reminders to users.
Record Ownership
- The site guest user must never own records.
- When a guest user creates a record, such as a case via web-to-case or a record created via a flow, the site guest user is the record owner. If the record owner isn’t changed, anyone who has guest access to your Experience Cloud site can see the record. Enable the Reassign new records created by guest users to the default owner setting so that guest users are no longer automatically the owner of records they create.
- In some use cases, you might need to give Read access to guest users to newly created records (such as ideas created by guest users in a site). We recommend that you create a guest user sharing rule to grant record access.
Sharing Settings
The Secure guest user record access setting limits visibility and access that guest users have to your org’s data.
Note This setting is enabled by default and can't be disabled. The timelines
for the rollout and enforcement of this setting are published in Guest User Security
Policies and Timelines.
When this setting is enabled, guest users:
- Use private org-wide defaults for all objects. This access level can’t be changed.
- Can’t be added to queues or public groups.
- Can’t be given access to records through manual sharing or Apex managed sharing.
- Can be granted Read Only access to records only through guest user sharing rules. Guest user
sharing rules are a special type of criteria-based sharing rule and count towards the limit of
50 criteria-based sharing rules per object.
Warning The guest user sharing rule type grants access to guest users without login credentials. By creating a guest user sharing rule, you're allowing immediate and unlimited access to all records matching the sharing rule's criteria to anyone. To secure your Salesforce data and give your guest users access to what they need, consider all the use cases and implications of creating this type of sharing rule. Implement security controls that you think are appropriate for the sensitivity of your data. Salesforce is not responsible for any exposure of your data to unauthenticated users based on this change from default settings.
Did this article solve your issue?
Let us know so we can improve!
