Hierarchical security: This gives access based on the actual manager-employee relationship. If you’re someone’s manager, you automatically get access to the records owned by that person, and it keeps going down the chain — a manager’s manager can see even further down. There are two types:
- Manager Hierarchy: Access follows the “Manager” field on the user record. So if Priya is Ravi’s manager, Priya automatically sees Ravi’s records.
- Position Hierarchy: Access follows job positions instead of the manager field, which is useful when the actual org chart doesn’t match who’s marked as “manager” in the system.
Business-unit-based security:
This one doesn’t care about who reports to whom. It’s based purely on which Business Unit owns the record. If you’re given Business Unit-level access, you see everyone’s records within that Business Unit, no matter who their manager is. And if it’s set to Parent: Child Business Unit access, you also see records in the smaller units underneath yours.
Simple way to remember it:
Hierarchical security → based on manager-employee relationships (or job positions)
Business unit security → based on which unit owns the record, regardless of reporting lines


