How access works
The three layers that decide what a person can see and do, how a grant on a folder flows to everything inside it, and why external groups follow different rules.
Almost every access question comes down to three layers: what kind of account someone has in your organisation, which team they belong to, and which role they hold on the thing they are trying to open. Once the layers are separate in your head, the Access tab reads like a sentence.
The three layers
Read this as text
A person's access is decided in three layers. The organisation role says what they may do anywhere in your organisation: Admin manages users, billing and settings; Member uses the platform and the AI and owns projects; Guest cannot use AI features or own anything; External is a buyer or adviser who signs in through the Deal Portal only and never enters the main app. A team groups people so access is granted once: an internal team holds colleagues and is project-scoped by default, an external group holds a buyer organisation whose members are never granted anything individually. The role on a resource (Owner, Editor or Viewer, on a project, the Dataroom, a folder or a file) decides what they see and do there: owners have full control including permissions, editors edit and organise content and can download, viewers read in the browser and receive capabilities such as Can download one by one. Two examples from the Cardiolytix deal: Nora Bauer, a Member in the internal Deal team with Editor on 1 Corporate & Governance, edits and downloads everything in folder 1; Ada Halden, an External user in the Halden Partners group with Viewer on 1.2.1 Board Meeting Minutes, reads those documents in the Deal Portal.
The three layers are independent. An organisation admin is Owner of every project in the organisation and sees all of its files. A team member sees a folder because the team was granted a role on it, or because they were granted one personally. An external user sees a folder only because their group holds Viewer on it; they have no organisation role beyond External and no team beyond their group.
| Organisation role | Enters the main app | Uses the AI | Owns projects and templates | Manages users, billing, settings | Signs in to the Deal Portal |
|---|---|---|---|---|---|
| Admin | ✓ | ✓ | ✓ | ✓ | – |
| Member | ✓ | ✓ | ✓ | – | – |
| Guest | ✓ | – | – | – | – |
| External | – | Only if AI chat is switched on for their group | – | – | ✓ |
Roles and capabilities
Roles rank strictly: Owner includes everything Editor can do, and Editor includes everything Viewer can do. In short:
| Role | What it allows |
|---|---|
| Owner | Full control: edit content, share, and manage permissions. |
| Editor | Edit and organise content, upload and place files, download. Cannot manage permissions. |
| Viewer | Read-only in the browser. Cannot download. |
On top of a role sit six capabilities, each an on/off switch per folder or file: Can download, View versions, No watermark, No password, Manage redaction and View unredacted. They extend a role without changing it; a Viewer with Can download reads and downloads but still cannot edit. No password only takes effect when Can download is also on.
At a glance, per role on a folder or file:
| Can they… | Viewer | Viewer + Can download | Editor | Owner |
|---|---|---|---|---|
| Open documents in the viewer | ✓ | ✓ | ✓ | ✓ |
| Download | – | ✓ | ✓ | ✓ |
| Upload, rename, move and place files | – | – | ✓ | ✓ |
| Share and manage permissions | – | – | – | ✓ |
| Open earlier versions | with View versions | with View versions | ✓ | ✓ |
| Redact documents | – | – | with Manage redaction | ✓ |
| See the original of a redacted document | with View unredacted | with View unredacted | with View unredacted | ✓ |
| See PDFs without the watermark | with No watermark | with No watermark | with No watermark | ✓ |
| Download PDFs without the password | – | with No password | with No password | ✓ |
External groups can hold Viewer only, plus Can download, No watermark, No password and View unredacted. Guests can hold Viewer or Editor, never Owner.
- Yes:Open the folder and read its documents in the viewer.
- No:Download: viewers cannot until Can download is switched on.
- No:PDFs in the viewer and in downloads carry the project watermark, if one is set.
- No:Cannot upload, rename, move or place files here.
- No:Cannot share the folder or change permissions; only an owner can.
- No:Sees the redacted version of documents that carry redactions.
- No:AI chat only if you switched it on for the group in the Deal Portal, within its monthly credit limit.
External users sign in through the Deal Portal only and inherit everything from their group; nothing can be granted to one of them individually.
Read this as text
What someone can do on a folder follows from who they are, the role they hold there and the capabilities switched on. A Viewer opens documents in the viewer but cannot download, upload or share; with Can download they also download. PDFs carry the project's watermark in the viewer and in downloads unless No watermark is granted, and downloads ask for the project's password unless No password is granted. An Editor additionally uploads, renames, moves and places files and can always download. An Owner additionally shares the folder and manages permissions. View unredacted shows the original of documents that carry redactions; without it the redacted version is shown. Guests cannot be made owners and cannot use the AI features. External groups hold Viewer at most; their members use AI chat only if it is switched on for the group in the Deal Portal, within a monthly credit limit.
How access flows down
A role granted on the Dataroom applies to every folder and file inside it. A role granted on a folder applies to that folder and everything inside, unless something inside was granted differently. A role granted on a file applies to that file only. The Access tab shows where each row's access comes from: a direct grant on the row itself, or an inherited role from a parent. A folder listed with No role is there only because something inside it is shared.
Two consequences matter in practice. A file's access is the combination of every path that reaches it, so clearing a folder grant does not remove a grant placed on a file inside that folder. And a stronger role can be added on a child, but an inherited role cannot be taken away on the child; it has to be changed where it was granted.
External group · Viewer on 1.2.1. Select a folder or document to grant or clear a direct role.
Halden Partners can open 2 of 2 documents and 1 of 4 folders. 1 and 1.2 appear only because something inside is shared: the Access tab lists them with No role. External groups hold Viewer at most; the download, watermark and password capabilities are switched on separately.
Read this as text
Access flows downwards. Jonas Keller, an Editor on 1 Corporate & Governance, is an Editor on every folder and document inside it, marked as inherited. Nora Bauer, a Viewer on the document GOV-002 only, sees that document; the folders above it are listed for her without a role, only because something inside is shared, and clearing a grant on a folder above would not remove her grant on the file. Halden Partners, an external group with Viewer on 1.2.1 Board Meeting Minutes, sees that folder and its documents; folders 1 and 1.2 appear only because something inside is shared, and folder 6 is absent from their Deal Portal rather than shown as locked. External groups hold Viewer at most.
Internal teams and external groups
Both live on the project's Teams page and both have Members, Permissions and Settings tabs, but they run on different rails:
- Internal teams hold colleagues. They are project-scoped by default, so the team exists only in this project; switch on Organization-wide to reuse it across projects and manage it at organisation level. Members of an internal team work in the main app and can also hold individual grants on top of what the team gives them. An internal team can hold any role.
- External groups hold a buyer organisation and its advisers. Their members sign in through the Deal Portal only, never see the main app, and never receive individual grants: everything comes from the group, which can hold Viewer at most, plus the download-related capabilities, and only on the Dataroom, its folders and files, never on the project itself. Access takes effect only once the group's External access is switched on and the data room is published. If the portal requires an NDA, each buyer must accept it before the room opens for them.
A person cannot be on both rails: an external user cannot be added to an internal team, and a colleague cannot be added to an external group.
Who can see whose name
Members and admins see every colleague. Guests see only the people in teams they belong to. Members of an external group see only their own group, so two buyer organisations in the same data room never learn of each other: not in the portal, not in Q&A, not in any list. Keep one group per buyer organisation for exactly that reason; putting two bidders in one group would show them each other's names.
Availability and limitations
- Permission changes take effect within seconds; in rare cases up to a minute.
- Workspace and Dataroom are two containers for the same files. A colleague granted a document in the Dataroom also sees it in the Workspace tab, because visibility is checked on the file. Buyers never see the Workspace.
- Removing someone from a project clears their own grants but not access they hold through a team or through an organisation-wide default; see Remove someone's access.
Next actions
- Check what someone can see reads the Access tab for a team or a person.
- Manage your team and roles creates teams and sets roles.