sf-access-explainer

SF Access Explainer

A Chrome extension (Manifest V3) that, on any Salesforce Lightning record page, shows whether a chosen user has Read/Edit/Delete access to that record and explains why: enumerating every sharing source that grants it.

No OAuth, no external services, no dependencies. It reuses your existing browser session against Salesforce (the sid cookie) to call the REST API directly.

Load the extension (unpacked)

  1. Open chrome://extensions in Chrome.
  2. Enable Developer mode (top-right toggle).
  3. Click Load unpacked.
  4. Select this folder (the one containing manifest.json).
  5. Pin the extension if you’d like quick access from the toolbar.

Using it

  1. Log in to your Salesforce org as usual and navigate to any Lightning record page, e.g.: https://yourorg.lightning.force.com/lightning/r/Account/001XXXXXXXXXXXXXXX/view
  2. Click the extension icon.
  3. The popup shows:
    • Access Verdict: Read/Edit/Delete badges plus max access level, transfer, and full-access flags, computed from UserRecordAccess.
    • Why: every sharing source that grants access: object-level ViewAllRecords/ModifyAllRecords overrides, record ownership, manual shares, sharing rules, teams, implicit sharing, territories, and Apex managed sharing, each attributed to the specific share row and access level.
    • What was checked: every query run, including shares that exist on the record but don’t apply to the target user, so a “no access” verdict is fully explainable.
  4. Click Switch user to search for and inspect a different user (Id, Name FROM User WHERE Name LIKE ...). The default target is always yourself.

How it works

Known edge cases handled explicitly

Permissions

Out of scope (v1)