Remove someone's access
Take a colleague or a buyer out of a project or the organisation, and make sure no other path still lets them in.
Access can come through several paths at once: a direct grant, a team, an inherited folder role, an organisation-wide default. Removing someone properly means closing every path and then checking the result, which takes a minute with the Access tab.
Before you start
- You are an owner of the project; removing someone from the organisation needs an organisation admin.
- Know what you want to achieve: out of one folder, out of the project, or out of the organisation.
Steps
- For one folder or file, open its ⋮ › Permissions panel in Files, find the person or team and clear their role. Remember that a grant placed directly on a file inside the folder stays; check the files if any were shared individually. External groups only appear in the panels of Dataroom folders and files; to take a group out of the room entirely, use the group itself (step 4).
- For a whole project, open Teams › People with access, select the person, use the remove icon (Remove user from project), then confirm with Remove. This clears their own direct grants on the project and everything inside it.
- Then check their teams. Removing from the project does not take them out of an internal team that still holds access. Open each team's Members tab and remove them there, or clear the team's role if the whole team should lose it.
- For a buyer, open the external group's Members tab, select ⋮ › Remove on their row and confirm. Their portal access ends at once and their NDA acceptance is cleared; adding them again later means accepting the NDA again. To pause a whole buyer organisation, switch the group's External access off instead. This also clears every group member's NDA acceptance, so each of them accepts the NDA again when you switch access back on.
Removal takes effect as soon as you confirm. - For someone leaving the company, an organisation admin selects the trash icon on their row under Profile › Teams & People and confirms with Remove User. This ends their access to every project in the organisation.
Check the result
Open People with access. The person is no longer listed, or their row shows no remaining rights under All resources. Their history stays in Analytics and in each document's Access History.
If something goes wrong
Find the remaining path: select them under People with access, switch to All resources and hover the dashed role to see where it is inherited from, then clear it there. Changes take effect within seconds, in rare cases up to a minute; someone who already has a document open keeps it until they reload.
They are the team's last owner, or the team includes all organisation members indirectly. Assign another owner, or switch Include all organization members off, then remove them.
Removal stops new views and downloads. Files already downloaded remain with the person; the watermark and password on downloaded PDFs are the protection that still applies.