Loading

Troubleshoot INSUFFICIENT_ACCESS errors with Opportunities

Fecha de publicación: Jul 27, 2026
Descripción

Users may encounter an INSUFFICIENT_ACCESS error when attempting to view, edit, or update Opportunity records. This error indicates that the user lacks the necessary permissions or record-level sharing access to perform the requested action.

This article covers the most common causes and their resolutions.

Solución

Why This Error Occurs

The INSUFFICIENT_ACCESS error on Opportunities is caused by one or more of the following:

  • The user's profile or permission set lacks object-level Edit permission on Opportunities
  • The Opportunity's record-level sharing settings do not include the user
  • The organization-wide default (OWD) for Opportunities is set to Private or Public Read Only, with no sharing rule granting access
  • The user's role does not have access via the role hierarchy to the record owner's role
  • A validation rule or before-trigger is blocking the save and surfacing the error

Step 1: Check Object-Level Permissions

  1. Go to Setup > Users and click the affected user's name.
  2. Click the user's Profile link and look under Object Settings > Opportunities or Standard Object Permissions > Opportunities.
    1. Optionally, use the View Summary button when viewing the user record, then review the Object Permissions under User Access Summary.
  3. Also check any Permission Sets assigned to the user for conflicting or missing permissions.
  4. Confirm that Read and Edit are both checked.
  5. If missing, update the profile or assign a permission set with the correct permissions.

Step 2: Check Record-Level Access

  1. Navigate to the specific Opportunity record.
  2. Click the gear icon or the Sharing button (if visible).
  3. Confirm the affected user, their role, or a group containing them appears in the sharing list.
  4. In Lightning, click Edit, then View Sharing Hierarchy to view all Users with access.
  5. If not present, create a manual share for the record, or create a sharing rule to grant access automatically.

Step 3: Review Organization-Wide Defaults

  1. Go to Setup > Security > Sharing Settings.
  2. Locate the Opportunities row and note the Default Internal Access setting.
  3. If Organization-Wide Defaults (OWD) is Private: users can only see records they own or are explicitly shared with.
  4. Create a sharing rule or update the OWD if appropriate.
  5. If OWD is Public Read Only: users can see all records but cannot edit unless explicitly granted Edit access via sharing or permissions.

Step 4: Check Role Hierarchy

  1. Go to Setup > Roles.
  2. Confirm the affected user's role in the hierarchy relative to the record owner's role.
  3. Role hierarchy grants access upward (managers see subordinates' records), not sideways. If the record owner is a peer or in an unrelated branch, manual sharing or sharing rules are required.

Step 5: Check for Validation Rules

  1. Go to Setup > Object Manager > Opportunity > Validation Rules.
  2. Review active rules. A rule that references fields not visible to the user, or that evaluates to true on save, can cause an INSUFFICIENT_ACCESS-style error.
  3. To test: temporarily deactivate a suspect rule, retry the update, then reactivate and refine the rule logic.

 

Note: System Administrators with "Modify All Data" or "Modify All" on Opportunities bypass all sharing settings. If the admin can edit the record but the user cannot, the issue is very likely permissions or sharing — not a product bug.

FAQ

Q: Why can a user see an Opportunity but not edit it?
A: Read and Edit are separate permissions. The user's profile grants Read but not Edit. Check object-level permissions on the profile or permission set and add Edit if appropriate.


Q: The error occurs on some Opportunities but not others. Why?
A: This is a record-level access issue. Records created by users whose role hierarchy does not grant access to the affected user will appear inaccessible. Review manual shares and sharing rules for the specific records.


Q: Can this be caused by a field-level security restriction?
A: Yes. If the user's profile does not have Read access to a required field on the Opportunity, some operations will fail. Check Field-Level Security for the Opportunity object on the user's profile.

Número del artículo de conocimiento

005390125

 
Cargando
Salesforce Help | Article