Your workspace
What permissions to give each person
Neither everyone an administrator nor everyone read-only: the split that works.
Both extremes fail for the same reason: nobody stops to think who needs what. Everyone an administrator ends in an accidental deletion; everyone read-only ends with one person doing eight people's work.
The split that usually works
| Profile | Can | Cannot |
|---|---|---|
| Administrator | Everything, including settings and permissions | — |
| Manager | Create processes, launch sends, approve | Change organisation settings |
| Contributor | Work on their own items, upload and respond | Delete, or touch other people's processes |
| Read-only | View and download their own material | Change anything |
Two practical rules
- Two administrators, not one and not five. With one, if they lose access nobody can fix it; with five, nobody feels responsible.
- Delete permission does the most damage and is needed least day to day. Grant it sparingly.
Important
An external adviser or accountancy firm does not need to administer your account. Give them read access to their own scope and nothing more: it is your information, not theirs.
Worth knowing
Permissions get reviewed when someone changes role, not only when they join. A promotion leaves old permissions that no longer fit.
Watch out
If you use teams, a broad permission in one team should not reach another team's documents. Check the scope, not just the level.
›Can I give access to only one project?
Yes, scoped by team or by folder.
›Can I see who did what?
Yes, every action carries its author.
›Can a contributor invite others?
No, and it is better that way.
A real case
The situation
A twenty-person company has all twenty as administrators.
What you do
- Keeps two administrators
- Four area managers
- The rest as contributors within their team
What you get
Nobody loses the ability to work and the risk of someone deleting a whole case by accident disappears.
The situation
Broad permissions are granted so nobody is blocked.
What you do
- Grants what each role needs
What you get
The block clears without opening more than necessary.
The situation
An intern can see sensitive documentation.
What you do
- Reviews what belongs to each role
What you get
Sensitive material stays where it should.
The situation
Nobody has reviewed permissions in two years.
What you do
- Schedules a periodic review
What you get
Access reflects today's organisation.
The situation
An external party asks for access to the whole folder.
What you do
- Grants access to the file they need
What you get
They see theirs and nothing more.
The situation
Somebody leaves and their permissions stay active.
What you do
- Revokes access on their last day
What you get
The account reflects who works here.
This article answers
- configure user permissions
- what role should i give a colleague
- limit what someone can do
- team permissions