Some Salesforce users run into unexpected trouble accessing their own files. This can show up as an inability to upload files through the user interface (UI), file access failures when using the REST API, errors in Apex code, or a broken "save/preview" step after uploading a branding image in Survey. In every case, the user is unable to find files they uploaded or expect to have access to.
The root cause is almost always the same: the "Query Non Vetoed Files" permission combined with the "Enable Files to be ingested into Data Cloud" org setting. This article explains why that combination breaks file access and how to fix it.
This issue is related to the "Query Non Vetoed Files" user permission and a related organization-level setting. When both the "Query Non Vetoed Files" permission is enabled for a user and the "Enable Files to be ingested into Data Cloud" organization setting is also enabled, Salesforce applies a filter that restricts file search results to only files marked as public.
These settings are intended for specific system integrations, not for regular user accounts. The "Query Non Vetoed Files" permission is designed for machine-to-machine (M2M) integrations that handle data ingestion into Data Cloud - it is not meant for individual users, including administrators.
The "Query Non Vetoed Files" permission is intended for machine-to-machine (M2M) integrations system-to-system connections that ingest data into Data Cloud without human user interaction. It should never be assigned to a regular user or admin profile.
This section explains how to fix file access problems caused by the "Query Non Vetoed Files" permission, by finding and disabling the permission for any affected user.
The "Enable Files to be ingested into Data Cloud" setting is found under Setup > Salesforce Files > General Settings. This setting, combined with the user permission, triggers the file visibility restriction described above.
For example, when the "Query Non Vetoed Files" permission is assigned to a user and the "Enable Files to be ingested into Data Cloud" setting is enabled, a user who also has "View All Data" and "Query All Files" permissions is still unable to access the file in Lightning Experience. The same record can be opened when switching to Classic. Additionally, queries against the file return no records at all.
Disabling the "Query Non Vetoed Files" permission for regular users restores standard file access behavior.
004517924

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.