[{"data":1,"prerenderedAt":645},["ShallowReactive",2],{"guide:\u002Finternal\u002Faccess\u002Fhow-access-works":3,"related:\u002Finternal\u002Faccess\u002Fhow-access-works":636},{"id":4,"title":5,"audience":6,"body":7,"canonical_url":612,"collection":613,"description":614,"extension":615,"feature_flags":616,"is_draft_preview":617,"legends":618,"meta":619,"navigation":620,"order":621,"path":622,"reading_minutes":623,"related":624,"seo":628,"slug":629,"status":630,"stem":631,"tour_ids":632,"type":633,"updated_at":634,"__hash__":635},"guides\u002Finternal\u002Faccess\u002Fhow-access-works.md","How access works","internal",{"type":8,"value":9,"toc":601},"minimark",[10,14,19,63,69,168,172,187,228,256,259,419,434,469,473,488,491,503,507,514,544,547,551,554,558,581,585],[11,12,13],"p",{},"Almost every access question comes down to three layers: what kind of account someone has in your organisation, which team they belong to, and which role they hold on the thing they are trying to open. Once the layers are separate in your head, the Access tab reads like a sentence.",[15,16,18],"h2",{"id":17},"the-three-layers","The three layers",[20,21,22],"access-layers",{},[11,23,24,25,29,30,33,34,37,38,41,42,45,46,49,50,53,54,58,59,62],{},"A person's access is decided in three layers. The ",[26,27,28],"strong",{},"organisation role"," says what they may do anywhere in your organisation: ",[26,31,32],{},"Admin"," manages users, billing and settings; ",[26,35,36],{},"Member"," uses the platform and the AI and owns projects; ",[26,39,40],{},"Guest"," cannot use AI features or own anything; ",[26,43,44],{},"External"," is a buyer or adviser who signs in through the Deal Portal only and never enters the main app. A ",[26,47,48],{},"team"," groups people so access is granted once: an internal team holds colleagues and is project-scoped by default, an external group holds a buyer organisation whose members are never granted anything individually. The ",[26,51,52],{},"role on a resource"," (Owner, Editor or Viewer, on a project, the Dataroom, a folder or a file) decides what they see and do there: owners have full control including permissions, editors edit and organise content and can download, viewers read in the browser and receive capabilities such as Can download one by one. Two examples from the Cardiolytix deal: Nora Bauer, a Member in the internal Deal team with Editor on ",[55,56,57],"em",{},"1 Corporate & Governance",", edits and downloads everything in folder 1; Ada Halden, an External user in the Halden Partners group with Viewer on ",[55,60,61],{},"1.2.1 Board Meeting Minutes",", reads those documents in the Deal Portal.",[11,64,65,66,68],{},"The three layers are independent. An organisation admin is Owner of every project in the organisation and sees all of its files. A team member sees a folder because the team was granted a role on it, or because they were granted one personally. An external user sees a folder only because their group holds Viewer on it; they have no organisation role beyond ",[26,67,44],{}," and no team beyond their group.",[70,71,72,97],"table",{},[73,74,75],"thead",{},[76,77,78,82,85,88,91,94],"tr",{},[79,80,81],"th",{},"Organisation role",[79,83,84],{},"Enters the main app",[79,86,87],{},"Uses the AI",[79,89,90],{},"Owns projects and templates",[79,92,93],{},"Manages users, billing, settings",[79,95,96],{},"Signs in to the Deal Portal",[98,99,100,119,135,151],"tbody",{},[76,101,102,107,110,112,114,116],{},[103,104,105],"td",{},[26,106,32],{},[103,108,109],{},"✓",[103,111,109],{},[103,113,109],{},[103,115,109],{},[103,117,118],{},"–",[76,120,121,125,127,129,131,133],{},[103,122,123],{},[26,124,36],{},[103,126,109],{},[103,128,109],{},[103,130,109],{},[103,132,118],{},[103,134,118],{},[76,136,137,141,143,145,147,149],{},[103,138,139],{},[26,140,40],{},[103,142,109],{},[103,144,118],{},[103,146,118],{},[103,148,118],{},[103,150,118],{},[76,152,153,157,159,162,164,166],{},[103,154,155],{},[26,156,44],{},[103,158,118],{},[103,160,161],{},"Only if AI chat is switched on for their group",[103,163,118],{},[103,165,118],{},[103,167,109],{},[15,169,171],{"id":170},"roles-and-capabilities","Roles and capabilities",[11,173,174,175,178,179,182,183,186],{},"Roles rank strictly: ",[26,176,177],{},"Owner"," includes everything ",[26,180,181],{},"Editor"," can do, and Editor includes everything ",[26,184,185],{},"Viewer"," can do. In short:",[70,188,189,199],{},[73,190,191],{},[76,192,193,196],{},[79,194,195],{},"Role",[79,197,198],{},"What it allows",[98,200,201,210,219],{},[76,202,203,207],{},[103,204,205],{},[26,206,177],{},[103,208,209],{},"Full control: edit content, share, and manage permissions.",[76,211,212,216],{},[103,213,214],{},[26,215,181],{},[103,217,218],{},"Edit and organise content, upload and place files, download. Cannot manage permissions.",[76,220,221,225],{},[103,222,223],{},[26,224,185],{},[103,226,227],{},"Read-only in the browser. Cannot download.",[11,229,230,231,234,235,238,239,238,242,238,245,238,248,251,252,255],{},"On top of a role sit six ",[26,232,233],{},"capabilities",", each an on\u002Foff switch per folder or file: ",[26,236,237],{},"Can download",", ",[26,240,241],{},"View versions",[26,243,244],{},"No watermark",[26,246,247],{},"No password",[26,249,250],{},"Manage redaction"," and ",[26,253,254],{},"View unredacted",". They extend a role without changing it; a Viewer with Can download reads and downloads but still cannot edit. No password only takes effect when Can download is also on.",[11,257,258],{},"At a glance, per role on a folder or file:",[70,260,261,277],{},[73,262,263],{},[76,264,265,268,270,273,275],{},[79,266,267],{},"Can they…",[79,269,185],{},[79,271,272],{},"Viewer + Can download",[79,274,181],{},[79,276,177],{},[98,278,279,292,305,318,331,349,364,383,402],{},[76,280,281,284,286,288,290],{},[103,282,283],{},"Open documents in the viewer",[103,285,109],{},[103,287,109],{},[103,289,109],{},[103,291,109],{},[76,293,294,297,299,301,303],{},[103,295,296],{},"Download",[103,298,118],{},[103,300,109],{},[103,302,109],{},[103,304,109],{},[76,306,307,310,312,314,316],{},[103,308,309],{},"Upload, rename, move and place files",[103,311,118],{},[103,313,118],{},[103,315,109],{},[103,317,109],{},[76,319,320,323,325,327,329],{},[103,321,322],{},"Share and manage permissions",[103,324,118],{},[103,326,118],{},[103,328,118],{},[103,330,109],{},[76,332,333,336,341,345,347],{},[103,334,335],{},"Open earlier versions",[103,337,338,339],{},"with ",[26,340,241],{},[103,342,338,343],{},[26,344,241],{},[103,346,109],{},[103,348,109],{},[76,350,351,354,356,358,362],{},[103,352,353],{},"Redact documents",[103,355,118],{},[103,357,118],{},[103,359,338,360],{},[26,361,250],{},[103,363,109],{},[76,365,366,369,373,377,381],{},[103,367,368],{},"See the original of a redacted document",[103,370,338,371],{},[26,372,254],{},[103,374,338,375],{},[26,376,254],{},[103,378,338,379],{},[26,380,254],{},[103,382,109],{},[76,384,385,388,392,396,400],{},[103,386,387],{},"See PDFs without the watermark",[103,389,338,390],{},[26,391,244],{},[103,393,338,394],{},[26,395,244],{},[103,397,338,398],{},[26,399,244],{},[103,401,109],{},[76,403,404,407,409,413,417],{},[103,405,406],{},"Download PDFs without the password",[103,408,118],{},[103,410,338,411],{},[26,412,247],{},[103,414,338,415],{},[26,416,247],{},[103,418,109],{},[11,420,421,422,424,425,238,427,238,429,251,431,433],{},"External groups can hold ",[26,423,185],{}," only, plus ",[26,426,237],{},[26,428,244],{},[26,430,247],{},[26,432,254],{},". Guests can hold Viewer or Editor, never Owner.",[435,436,437],"access-explorer",{},[11,438,439,440,442,443,445,446,448,449,451,452,454,455,457,458,460,461,464,465,468],{},"What someone can do on a folder follows from who they are, the role they hold there and the capabilities switched on. A ",[26,441,185],{}," opens documents in the viewer but cannot download, upload or share; with ",[26,444,237],{}," they also download. PDFs carry the project's watermark in the viewer and in downloads unless ",[26,447,244],{}," is granted, and downloads ask for the project's password unless ",[26,450,247],{}," is granted. An ",[26,453,181],{}," additionally uploads, renames, moves and places files and can always download. An ",[26,456,177],{}," additionally shares the folder and manages permissions. ",[26,459,254],{}," shows the original of documents that carry redactions; without it the redacted version is shown. ",[26,462,463],{},"Guests"," cannot be made owners and cannot use the AI features. ",[26,466,467],{},"External groups"," hold Viewer at most; their members use AI chat only if it is switched on for the group in the Deal Portal, within a monthly credit limit.",[15,470,472],{"id":471},"how-access-flows-down","How access flows down",[11,474,475,476,479,480,483,484,487],{},"A role granted on the Dataroom applies to every folder and file inside it. A role granted on a folder applies to that folder and everything inside, unless something inside was granted differently. A role granted on a file applies to that file only. The Access tab shows where each row's access comes from: a ",[26,477,478],{},"direct grant"," on the row itself, or an ",[26,481,482],{},"inherited"," role from a parent. A folder listed with ",[26,485,486],{},"No role"," is there only because something inside it is shared.",[11,489,490],{},"Two consequences matter in practice. A file's access is the combination of every path that reaches it, so clearing a folder grant does not remove a grant placed on a file inside that folder. And a stronger role can be added on a child, but an inherited role cannot be taken away on the child; it has to be changed where it was granted.",[492,493,494],"access-inheritance",{},[11,495,496,497,499,500,502],{},"Access flows downwards. Jonas Keller, an Editor on ",[55,498,57],{},", is an Editor on every folder and document inside it, marked as inherited. Nora Bauer, a Viewer on the document GOV-002 only, sees that document; the folders above it are listed for her without a role, only because something inside is shared, and clearing a grant on a folder above would not remove her grant on the file. Halden Partners, an external group with Viewer on ",[55,501,61],{},", sees that folder and its documents; folders 1 and 1.2 appear only because something inside is shared, and folder 6 is absent from their Deal Portal rather than shown as locked. External groups hold Viewer at most.",[15,504,506],{"id":505},"internal-teams-and-external-groups","Internal teams and external groups",[11,508,509,510,513],{},"Both live on the project's ",[26,511,512],{},"Teams"," page and both have Members, Permissions and Settings tabs, but they run on different rails:",[515,516,517,532],"ul",{},[518,519,520,523,524,527,528,531],"li",{},[26,521,522],{},"Internal teams"," hold colleagues. They are ",[26,525,526],{},"project-scoped"," by default, so the team exists only in this project; switch on ",[26,529,530],{},"Organization-wide"," to reuse it across projects and manage it at organisation level. Members of an internal team work in the main app and can also hold individual grants on top of what the team gives them. An internal team can hold any role.",[518,533,534,536,537,539,540,543],{},[26,535,467],{}," hold a buyer organisation and its advisers. Their members sign in through the Deal Portal only, never see the main app, and never receive individual grants: everything comes from the group, which can hold ",[26,538,185],{}," at most, plus the download-related capabilities, and only on the Dataroom, its folders and files, never on the project itself. Access takes effect only once the group's ",[26,541,542],{},"External access"," is switched on and the data room is published. If the portal requires an NDA, each buyer must accept it before the room opens for them.",[11,545,546],{},"A person cannot be on both rails: an external user cannot be added to an internal team, and a colleague cannot be added to an external group.",[15,548,550],{"id":549},"who-can-see-whose-name","Who can see whose name",[11,552,553],{},"Members and admins see every colleague. Guests see only the people in teams they belong to. Members of an external group see only their own group, so two buyer organisations in the same data room never learn of each other: not in the portal, not in Q&A, not in any list. Keep one group per buyer organisation for exactly that reason; putting two bidders in one group would show them each other's names.",[15,555,557],{"id":556},"availability-and-limitations","Availability and limitations",[515,559,560,563,572],{},[518,561,562],{},"Permission changes take effect within seconds; in rare cases up to a minute.",[518,564,565,251,568,571],{},[26,566,567],{},"Workspace",[26,569,570],{},"Dataroom"," are two containers for the same files. A colleague granted a document in the Dataroom also sees it in the Workspace tab, because visibility is checked on the file. Buyers never see the Workspace.",[518,573,574,575,580],{},"Removing someone from a project clears their own grants but not access they hold through a team or through an organisation-wide default; see ",[576,577,579],"a",{"href":578},"\u002Finternal\u002Faccess\u002Fremove-someones-access","Remove someone's access",".",[15,582,584],{"id":583},"next-actions","Next actions",[515,586,587,594],{},[518,588,589,593],{},[576,590,592],{"href":591},"\u002Finternal\u002Faccess\u002Fcheck-what-someone-can-see","Check what someone can see"," reads the Access tab for a team or a person.",[518,595,596,600],{},[576,597,599],{"href":598},"\u002Finternal\u002Faccess\u002Fmanage-your-team-and-roles","Manage your team and roles"," creates teams and sets roles.",{"title":602,"searchDepth":603,"depth":603,"links":604},"",2,[605,606,607,608,609,610,611],{"id":17,"depth":603,"text":18},{"id":170,"depth":603,"text":171},{"id":471,"depth":603,"text":472},{"id":505,"depth":603,"text":506},{"id":549,"depth":603,"text":550},{"id":556,"depth":603,"text":557},{"id":583,"depth":603,"text":584},"https:\u002F\u002Fdocs.vdr.valutico.dev\u002Finternal\u002Faccess\u002Fhow-access-works","access","The three layers that decide what a person can see and do, how a grant on a folder flows to everything inside it, and why external groups follow different rules.","md",[],false,{},{},true,0,"\u002Finternal\u002Faccess\u002Fhow-access-works",7,[625,626,627],"check-what-someone-can-see","manage-your-team-and-roles","invite-buyers-to-a-data-room",{"title":5,"description":614},"how-access-works","published","internal\u002Faccess\u002Fhow-access-works",[],"feature","2026-09-29T13:21:45+02:00","dE3_2JXjgu5isGGXaALGkE_shhSzGHxQHhadu9bMPjw",[637,639,641],{"title":592,"description":638,"path":591,"audience":6,"slug":625},"Read the Access tab of a team or a person to see exactly which folders and files they can open, where each right comes from, and look at the room through their eyes.",{"title":599,"description":640,"path":598,"audience":6,"slug":626},"Invite colleagues, choose their organisation role, put them in a team, give the team a role on the data room, and keep a project-scoped team from leaking into other projects.",{"title":642,"description":643,"path":644,"audience":6,"slug":627},"Invite buyers to a data room","Create an external group, add the buyers, choose which folders they can see, and send the invitations by publishing the data room.","\u002Finternal\u002Fdata-room\u002Finvite-buyers-to-a-data-room",1790706827235]