Permission system
What a user sees and may do in the DocSecBox comes down to two questions. First: which folders does the user reach? Second: what may the user do in those folders? This page explains both and shows where you set them.
Who sees which folder
A user sees a folder only when assigned to it. There are two ways to do that:
- Through a group. You put users and folders into the same group. Every member then reaches every folder of the group. This is the usual way, because one group serves many people at once.
- Directly. You assign a single account to exactly one folder, without a group. This suits exceptions, such as an external partner who should see one folder only.
Anyone who reaches a folder sees its files.
graph LR
A1[**User**
Sales 1] ---> B;
A2[**User**
Sales 2] ---> B;
B[**Group**
Sales] ---> C;
A3[**User**
Customer] -.->|direct| C;
C[**Folder**
Quotes] ---> D1[**File**
Quote 1];
C ---> D2[**File**
Quote 2];
Where to assign:
| What | Where |
|---|---|
| Create a group with members and folders | Settings › Overview › Groups |
| Assign groups or single accounts to a folder | The folder's Members tab |
| Assign groups to an account | Edit user dialog, Groups card |
Good to know:
- Subfolders inherit nothing. A subfolder has its own assignments. Anyone who sees the parent folder therefore does not automatically see the subfolder.
- New folders. When an administrator creates a folder, that administrator is assigned to it directly. You choose further groups when creating the folder or later on the Members tab. Groups that should reach every new folder are set under Objects.
- Direct assignments stay visible. They appear under Overview › Groups on the Direct assignments tab, so no access stays hidden.
What someone may do in a folder
Once a user is assigned to a folder, nine permissions decide what that user may do there:
| Permission | What it allows |
|---|---|
| View files | Open and read files. Without it, a user sees only a file's name, size and date. |
| Download | Download files, as long as the file allows downloading. |
| Upload | Upload files into the folder. |
| Edit own files | Edit files the user uploaded. |
| Edit all files | Edit any file in the folder, including other people's. |
| Delete own files | Delete files the user uploaded. |
| Delete all files | Delete any file in the folder, including other people's. |
| View logs | Open a file's history. |
| Notify | Notify others about a file. |
These permissions only work in folders the user reaches. Without an assignment, even the widest permission is of no use.
The user dialog lists two more entries that are not folder permissions:
- Create/edit folders for assigned groups: the account may create folders and change their settings, for example name, deletion rules and notifications. It may not change a folder's members.
- Management: the account is an administrator (see The roles).
Global permissions and folder exceptions
The nine permissions belong to the account. You set them in the Edit user dialog, in the Global permissions card. These global permissions apply in every folder the account reaches.
If an account should be allowed more or less in one particular folder, create a folder exception there. It changes only the permissions you pick, and only in that folder. In the exception each permission has three values: Inherited (the global permission applies), Allowed and Withheld.
flowchart TD
A["Is the account assigned to the folder?"] -->|no| B["The folder stays invisible."]
A -->|yes| C["Does the folder have an exception for this permission?"]
C -->|yes| D["The exception applies: Allowed or Withheld."]
C -->|no| E["The account's global permission applies."]
To create a folder exception:
- Open the folder in the explorer and switch to the Members tab.
- Expand the account's row. Its nine permissions in this folder appear below it.
- Click Override permissions....
- Set the permissions that should differ to Allowed or Withheld.
- Click Save.
You reach the same dialog through View permissions › Folders tab › Exception. Exceptions exist only for accounts assigned to the folder. Your tenant can reserve them for superadmins (Only super administrators can grant folder permissions to users under Roles).
Whether an account can actually delete a file also depends on the folder's deletion rules.
What an account may actually do
The View permissions dialog under Overview › Users shows each account's global permissions and the result in each of its folders, exceptions included. Every user sees the same for themselves in the profile under Permissions.
The same nine permissions, two spellings
The DocSecBox labels the nine permissions differently in two places. The left column applies to the Global permissions card in the user dialogs and to Roles. The right column applies to a folder's Members tab, the View permissions dialog and the profile. Each row means the same permission.
| User dialogs and Roles | Members tab, View permissions and profile |
|---|---|
| PDF-Viewer | View files |
| Download | Download |
| Upload | Upload |
| Edit own files | Edit own files |
| Edit other files | Edit all files |
| Delete own files | Delete own files |
| Delete others files | Delete all files |
| File log | View logs |
| Send notifications | Notify |
The roles
Besides its permissions, every account has a role. It is shown in the Role column under Overview › Users.
| Role | What it may do |
|---|---|
| User | Sees the folders the user is assigned to and may do there what the permissions allow. |
| Group admin | Also maintains the members of their own groups in Group management. Does not decide which folders a group reaches. |
| Administrator | Holds the Management permission. Opens the settings, creates users, groups and folders and grants access. |
| Superadmin | Can do everything an administrator can, plus whatever your tenant reserves for superadmins under Roles. |
A few details about the roles:
- A member becomes Group admin in the Edit group dialog: in the Role column, click Member to turn the member into a Group admin. The column only appears when Enable group admins is switched on under Roles. Administrators cannot be group admins.
- An account becomes Superadmin through the Superadmin checkbox in the user dialog. Only a superadmin can set it. In a new installation this is usually the operator of your DocSecBox.
- Under Roles your tenant can reserve three things for superadmins: editing user accounts, granting folder exceptions and the pages under Application.