Groups and assignments
Assign to the group once; whoever joins later is already in
A group has a manager, a colour, subgroups and folders. Whoever belongs to it inherits the folders and levels; whoever leaves loses them. The consultant has an access with an end date, and the auditor a role that sees everything and changes nothing.
Inheritance does the boring work
Management contains Administration; Sites contains North Site. Folders assigned to the parent group reach the subgroups; those assigned to a folder reach the subfolders, with exclusions where needed. Assignments have a level, optional custom permissions and an expiry: the day after, the access is gone. The “Who has access” panel shows direct and inherited access, and where it comes from. And if an access change must be justified, the folder demands it.
How it works
-
Create the group, set the manager
Name, colour, description, manager, parent group if it is a subgroup. Then the people: whoever is in inherits everything the group has.
-
Assign folders to the group, with expiry if needed
From the folder or from the group: a level, optional custom permissions, an end date. An expired assignment disappears by itself, and stays in the log.
-
Designate the auditors
Whoever manages members can appoint auditors: they read shares, accesses and the audit log of the whole product, without being able to edit, download or share.
Whoever leaves the group leaves the folders. In the same instant.
What you can do
-
Two-level groups
Parent group and subgroups, manager and colour. Inheritance goes from parent to children, never the other way.
-
Expiring assignments
Person or group, level, optional custom permissions, end date. The due-diligence consultant leaves by themselves on 30 June.
-
Inheritance with exclusions
What holds on “Clients” holds on every client, except where you set an exclusion or an exception for a single member.
-
Who has access, direct and inherited
The panel lists people and groups with level and origin: from this folder, from one above, from a group, from a workspace.
-
Mandatory reason
On folders that require it, every access change must be justified: the reason goes into the access-change log.
-
Auditor
A designation, not a user type: the auditor or DPO sees everything read-only, and their activity stays in the log like everyone else’s.
| Origin | Who receives it | Inherited by subfolders | Expiry | Shown in “Who has access” |
|---|---|---|---|---|
| Direct assignment | persona | yes | yes | yes |
| Group assignment | gruppo e sottogruppi | yes | yes | yes |
| Workspace member | persona o gruppo | yes | no | yes |
| Share to a person | persona | yes | yes | yes |
| Access to all folders (user type) | Amministratore, Gestore | yes | no | yes |
| Auditor | designato | yes | no | no |
Frequently asked questions
How many group levels can I have?
Two: group and subgroup. Enough for “Management › Administration” or “Sites › North Site”, and few enough to always understand where an access comes from.
What exactly does the auditor see?
Shares, assignments, the access log and the audit log of the whole product, read-only. They do not open files, download or share. It is the role for the auditor, the DPO or the compliance consultant.
If I move a folder into a workspace, do the old accesses stay?
They stay, and the workspace flags it: “have access to this workspace’s folders without being members”. From there you decide whether to keep or detach them, one by one.
The other Files features
Move your company files to the cloud
Request a demo: we’ll show you how Files makes storage and sharing simple and secure.