Salesforce File Security

File-Level Visibility in Salesforce

Standard Salesforce has no way to hide a single file on a record from specific users — if you can open the record, you can see every file attached to it. Smarter Files fixes that with true file-level visibility.

The problem

Why native Salesforce has no true file-level visibility

Salesforce controls who can see a record — but not which files on that record each user can see. This surprises a lot of admins:

  • Files in the Related Files list are visible to everyone with access to the record. There is no per-file restriction.
  • Sharing rules and org-wide defaults govern record access, not individual file access.
  • Field-Level Security (FLS) hides fields — it does nothing for files attached to a record.
  • Once a user opens a record, they can preview and download every file in it.

The solution

How Smarter Files adds file-level visibility

Role-based categories

Assign each file a category and lock that category to specific roles. Users whose role isn't on the list never see the file — it doesn't appear in their list at all.

Private documents

Any user can mark a file as private. It becomes visible only to the owner and to users holding the “View Private Documents” permission set.

Server-side filtering

In Isolated storage mode, files a user can't access are never sent to the browser. Files sit behind a junction object, fully managed by the component.

Common use cases

Frequently asked questions

Can I hide a specific file from certain users in Salesforce?

Not with native Salesforce — record access is all-or-nothing for files. With Smarter Files you can, using role-based categories or by marking a file private.

Is this the same as Field-Level Security?

No. Field-Level Security hides fields on a record. File-level visibility controls which files (attachments) each user can see. They solve different problems.

Do I need Sales or Service Cloud?

No. Smarter Files works with Salesforce Platform Starter and Plus licenses — no Sales or Service Cloud dependency.

Are files hidden on the client or the server?

Server-side. Files a user isn't allowed to see are never sent to the browser, so they can't be recovered from the page source.

Add file-level visibility to your Salesforce org

Install Smarter Files from the AppExchange and control who sees which files on any record.

Install from AppExchange