---
id: KB-AD-020
url: https://app.codecontract.io/help/administration/who-should-be-able-to-delete
idioma: en
categoria: administracion
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-014, KB-DI-010, KB-AD-009]
citadoPor: [KB-AD-003]
---

# Who should be able to delete

_The permission handed out most thoughtlessly, and the only one whose mistake shows up when you need what is gone._

**Responde a:** who can delete documents · someone deleted something by mistake · delete permissions for the team · can deleted items be recovered

When permissions are set up, deleting usually rides along with editing: if someone can work on a file, they can remove things from it. That seems reasonable until someone tidies away what they think is surplus and it turns out to be the only copy of something needed three months later.

## What is worth separating

| Action | Who should be able to | Why |
| --- | --- | --- |
| Upload and correct | Most of the team | It is the daily work |
| Archive or take out of view | Whoever works with it | Tidies without destroying |
| Actually delete | Very few people | It is the only irreversible one |
| Delete at a third party's request | Whoever holds that responsibility | It has consequences outside the company |

> [!IMPORTANT]
> The distinction between the two middle rows prevents nearly every scare: **getting something out of the way and destroying it are not the same need**. When someone says «this is surplus», they almost always mean it clutters their list, not that it should be destroyed. If those two actions are one, a tidying gesture takes out a piece of evidence — and whoever did it was right that it cluttered and had no intention of breaking anything.

## What remains when something is deleted

**En corto**

- The log says who deleted it and when, even with the document gone.
- That lets you reconstruct what was missing and from when, which is not nothing.
- But it does not return the content: a trace is not a substitute.
- And if it was sealed, what is lost is the copy, not the record that it existed.

> [!WARNING]
> The case worth settling before it happens: **deleting at a person's request about their own data is not the same as deleting because something clutters**, and it often arrives from outside with a deadline. If that ability is spread across the whole team, anyone can handle such a request badly — deleting too much, or deleting something you were required to keep for another reason. Exactly the kind of decision settled once with your adviser and left with one or two people.

## How to set it up

1. **Give almost everyone archive, and almost nobody delete** — It covers 95% of the times someone wants «this gone».
2. **Name who a real deletion is requested from** — Having to ask makes people think twice.
3. **Review who holds it once a year** — This permission is inherited on role changes and never withdrawn.
4. **And look at the deletion log now and then** — Ten minutes that teach a lot about how things are being used.

> [!NOTE]
> What you must keep and for how long, and how that squares with a personal-data deletion request, depends on your activity and the framework that applies. **Your adviser settles that**; here it is about that deletion not being executable by anyone by accident.

**Can something deleted be recovered?**

It depends how and when: ask soon, not in a month.

**What if something is deleted before we review it?**

The log says who and when; the content, absent a copy, does not come back.

**Should deletions raise an alert?**

Yes, to administrators: one of the few alerts worth having.

## Ejemplos

**Someone tidies a file and deletes the only copy of a certificate that cluttered the list.**

- Gives the whole team archive and reserves deletion for two people

→ Tidying can no longer destroy anything, and the clutter still gets cleared.

**Anyone can delete a document.**

- Limits deletion to the right people

→ Deletion stops being accidental.

**Something is deleted and nobody knows who did it.**

- Checks the action's log

→ The deletion has an author and a date.

**Something that had to be kept is deleted.**

- Checks the policy before deleting

→ Deleting stops being a gamble.

**Deletion rights are requested to clean up duplicates.**

- Grants the permission to whoever reviews

→ The clean-up happens on a basis.

**An external party has deletion rights for no reason.**

- Reviews what they actually need

→ The permission matches the work.
