You are here:
Considerations for Account Team Member Access
When you view a team member's access, the level shown depends on where you look. The account team member record shows only the directly granted access, while the Team Member Access action shows the user's total access from all sources.
Required Editions
| Available in: Lightning Experience and Salesforce Classic |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions |
Direct Access and Consolidated Access
An account team member's effective access is the combination of access from multiple sources, not just the access granted directly on the account team member record. Salesforce always applies the highest level of access from any source.
This means you can't reduce a user's effective access by lowering the account team member grant if another source, such as a sharing rule or role hierarchy position, provides higher access.
Where to View Access
| Where You Look | What It Shows | Includes Access From |
|---|---|---|
| Account team member record (view or edit) | Only the access granted directly when the team member was added or last edited | Account team member assignment only |
| Team Member Access action on the Account Team related list | The user's total effective access to the account and related records | Org-wide defaults, role hierarchy, sharing rules, account team membership, profile and permission set permissions, and manual shares |
Access Sources
These sources contribute to a user's consolidated access. The Team Member Access action shows the highest level from any source.
| Access Source | How It's Set | Example |
|---|---|---|
| Org-wide default (OWD) | A Salesforce admin sets the baseline in Sharing Settings | Account OWD set to Private means no access unless explicitly granted |
| Role hierarchy | Automatic, based on user's position relative to the account owner | A user above the account owner in the role hierarchy inherits access to the account |
| Sharing rules | A Salesforce admin creates criteria-based or ownership-based rules | All users in Role X get Read access to accounts owned by users in Role Y |
| Account team member (direct grant) | Set when a user is added to the account team or when the record is edited | Read Only or Read/Write selected at team member creation |
| Profile or permission set | A Salesforce admin assigns object-level permissions | Modify All Data permission or object-level View All |
| Manual sharing | The account owner or a Salesforce admin shares an individual record | A one-time share on a specific account |
Common Scenarios
These scenarios show why the access on the account team member record can differ from the access shown in Team Member Access.
| Scenario | Account Team Member Record Shows | Team Member Access Shows | Why They Differ |
|---|---|---|---|
| Team member granted Read Only for opportunities, but a sharing rule gives the user Read/Write | Read Only | Read/Write | The sharing rule provides higher access than the direct grant |
| Team member granted no case access, but the user is above the account owner in the role hierarchy | Private | Read Only | Role hierarchy grants inherited access to the account owner's records |
| Team member granted Read/Write with no other access sources | Read/Write | Read/Write | No difference because only one access source applies |
| Team member granted Read Only, but the user's profile has View All on accounts | Read Only | Read/Write | The profile-level permission overrides the direct grant |
AccountTeamMember Object Sharing
The AccountTeamMember object has a default org-wide sharing setting of Public Read/Write. This setting applies to the team member records themselves and doesn't change based on the Account object's sharing settings. This is expected behavior.
