Access

Everyone sees their folders, and no others

An employee, an external collaborator, a guest and an auditor do not need the same things. In Files they have different user types, different access levels on folders, different groups and, where needed, an access that expires on its own.

Three questions, three tools: who you are, what you see, with whom

The user type says who you are for Files — Administrator, Manager, Employee, Collaborator, Guest or one of yours — and what privileges you have in general: which sections you see, whether you have a personal space, whether you can use the desktop or the document chat. The access level says what you can do on a folder: Manager, Editor, Viewer, Guest or one of yours, permission by permission. The group says who you share it with: whoever joins the group inherits its folders, whoever leaves loses them. Assign at the top, it holds below.

How it works

  1. Give the person a user type

    The user type says what they can do in general: whether they manage members and levels, whether they have a personal space, whether they use the desktop or the document chat, which sections they see. An external Collaborator works in workspaces; a Guest sees a simplified home with their direct accesses.

  2. Assign the folders, with a level

    “Grant access” on a folder: pick the person or group, the level, and an expiry if you want one. The panel shows direct accesses next to those inherited from the folders above.

  3. Let the groups do the rest

    Administration inside Management, North Site inside Sites. Whoever joins the group inherits its folders; whoever leaves loses them. No list of people to update by hand.

The extra permission is the one you discover after the leak.

What you can do

  • Five user types, plus yours

    Administrator, Manager, Employee, Collaborator, Guest: privileges grouped by administrative activities, use, visible sections. The “External firm” type takes two minutes.

  • Granular per-folder permissions

    Content, file control, classification, document status, approvals, notes, collaboration, sharing, administration, extensions: every access level is a combination you decide.

  • Access that expires

    The due-diligence consultant has access until 30 June. On 1 July nobody has to remember to remove it.

  • Two-level groups

    Parent group and subgroups, with a manager and a colour. Folders assigned to the group reach everyone, including whoever joins tomorrow.

  • Auditor: sees, doesn’t touch

    A role for the auditor or DPO: reads shares, the access log and the logs, without being able to edit or download.

  • Who has access without being a member

    The workspace flags people who reach its folders through an old assignment or a moved folder. You decide whether to keep or detach them.

In depth

The model

  • Company space, not personal

    In services born for personal use every person has their own space and shares a few folders with colleagues: when they change jobs, the folders leave with them. Files starts from the opposite end. There is one archive, the company’s; top-level folders are decided by administrators; people receive an access, with a level, on a part of the tree. Nobody “owns” a client’s folder.

  • One login for the ecosystem

    Whoever enters Files is the same person who sends a contract for signature with kSign, writes with kMail, opens a data room in kVDR and receives documents with Flow. Not because the passwords are the same: because the account is one. Files takes people from Kamzan Account and adds only what it needs — the user type, the levels, the groups.

Who can do what

  • User types

    The user type decides a person’s general privileges: whether they administer, whether they have a personal space, which sections they see, whether they are internal or external to the company. Five ready-made, yours as many as you need.

  • Access levels and permissions

    An access level is a list of permissions with a name. Manager, Editor, Viewer and Guest are ready-made; you compose your own by ticking what is needed, permission by permission, and assign them to people or groups on each folder.

  • Groups, assignments and auditors

    A group has a manager, a colour, subgroups and folders. Whoever belongs to it inherits the folders and levels; whoever leaves loses them. The consultant has an access with an end date, and the auditor a role that sees everything and changes nothing.

Frequently asked questions

What happens when someone leaves the company?

You deactivate the user in Kamzan Account and they lose all access across all products. Their files stay in the company’s folders, with the creator’s name still readable on every row; the personal space is closed towards the person, in a protected archive.

Can I view Files “as” a user to check what they see?

Yes, administrators can impersonate a user read-only to verify permissions. The operation goes into the audit log.

Do permissions also apply from the desktop app?

Yes. The desktop app and the browser go through the same check: if you cannot delete from the browser, you cannot delete from the computer.

Move your company files to the cloud

Request a demo: we’ll show you how Files makes storage and sharing simple and secure.

Request a demo