FLS16 — a save that MODIFIES an update-denied field is rejected server-side (3.9) and the
stored value is untouched. Multi can read Phone (Allow) but its Denier role carries
Update=Deny.
The refusal NAMES the missing permission rather than using the ambiguous "does not exist or
you do not have access" wording. That wording protects two facts — that the column exists, and
that it is restricted for this caller — and Multi already holds both: it can read Phone and see
its value. Telling someone a field they are looking at might not exist is misleading, not
discreet. The ambiguous wording stays where it earns its keep: READ denials, where a caller
probing a predicate must not learn which columns a deployment treats as sensitive.
FLS16 — a save that MODIFIES an update-denied field is rejected server-side (3.9) and the stored value is untouched. Multi can read Phone (Allow) but its Denier role carries Update=Deny.
The refusal NAMES the missing permission rather than using the ambiguous "does not exist or you do not have access" wording. That wording protects two facts — that the column exists, and that it is restricted for this caller — and Multi already holds both: it can read Phone and see its value. Telling someone a field they are looking at might not exist is misleading, not discreet. The ambiguous wording stays where it earns its keep: READ denials, where a caller probing a predicate must not learn which columns a deployment treats as sensitive.