Sharing & Permissions
Who can see a document, who can change it, and how to share something private with specific people.
Overviewβ
Access to a document is decided by two things working together:
- Your role's permissions β what you may do with documents in general
- The document's visibility β who that particular document is for
Sharing sits on top as an additive overlay: it can grant access to a private document, and it never takes access away.
Visibilityβ
Every document is either visible to the organization or private.
| Visibility | Who can open it |
|---|---|
| Organization | Everyone in the organization who can read documents |
| Private | The creator, administrators, and the people or teams it is shared with |
Change it from the document's detail panel. The hint in the UI says it plainly: "Private documents are visible to you, admins and people you share them with".
Visibility is not inherited β putting a private document inside a public folder does not make it public, and vice versa. Navigating to a document does still depend on being able to see the folders above it.
An organization-wide default for new documents can be set in Settings β Documents.
Sharing a Private Documentβ
Sharing only applies to private documents. If a document is visible to the whole organization there is nothing to grant, and the share dialog says so:
This document is visible to the whole organization, so sharing adds nothing. Switch it to Private to share it with specific people or teams.
To share:
- Open the document and click Share
- Choose Person or Team
- Pick exactly one person or one team
- Choose the access level
- Click Add
| Access level | Grants |
|---|---|
| Can view | Opening, previewing, and downloading the document |
| Can comment | Viewing, plus commenting once document comments arrive |
| Can edit | Viewing plus changing the document |
Two limits are worth knowing:
- "Can edit" is not a permission grant. As the dialog notes, it "only takes effect for people who also have permission to edit documents". Sharing cannot give somebody an ability their role does not have.
- Only the document's creator or an administrator can share it.
Use Remove access to revoke a share at any time.
Comment threads on documents are not available yet β the Can comment level is in place ready for them. For now, treat it as equivalent to Can view.
The DOCS_* Permissionsβ
Seven permissions control the Documents hub. They can be adjusted per role in Settings β Roles & Permissions.
| Permission | Allows |
|---|---|
DOCS_READ | Browse the tree, search, open documents, download files |
DOCS_CREATE | Create folders and pages, upload files, duplicate documents |
DOCS_UPDATE | Edit documents, move, rename, archive, share, link records, correct extracted text |
DOCS_DELETE | Delete archived documents |
DOCS_MANAGE | Open Documents settings, manage the category catalog, run the legacy import |
DOCS_REVIEW | Approve and reject documents in the review queue |
DOCS_AI_IMPORT | Import documents into AI knowledge, exclude them, and re-index |
Default Role Matrixβ
This is what each role gets out of the box.
| Role | READ | CREATE | UPDATE | DELETE | MANAGE | REVIEW | AI IMPORT |
|---|---|---|---|---|---|---|---|
| Super Admin | β | β | β | β | β | β | β |
| Admin | β | β | β | β | β | β | β |
| Manager | β | β | β | β | β | β | β |
| Employee | β | β | β | β | β | β | β |
| Data Entry | β | β | β | β | β | β | β |
| Viewer | β | β | β | β | β | β | β |
| Candidate | β | β | β | β | β | β | β |
| Interviewer | β | β | β | β | β | β | β |
A few consequences of these defaults:
- Employees can write. The hub is not read-only for staff β they can create pages, upload files, and edit what they own.
- Managers can review and delete but cannot administer. A manager cannot change the category catalog or the organization defaults; that stays with administrators.
- Candidates and interviewers see nothing. Documents does not appear in their sidebar at all.
These are defaults, not fixed rules. Roles are editable in Settings β Roles & Permissions, and custom roles can be given any combination of the seven.
Related Pagesβ
- Documents Overview β where each screen lives
- Reviews & Approvals β what
DOCS_REVIEWunlocks - AI Knowledge β what
DOCS_AI_IMPORTunlocks - Settings β what
DOCS_MANAGEunlocks - Custom Roles & Permissions β editing roles