Groups and assignments

Assign to the group once; whoever joins later is already in

A group has a manager, a colour, subgroups and folders. Whoever belongs to it inherits the folders and levels; whoever leaves loses them. The consultant has an access with an end date, and the auditor a role that sees everything and changes nothing.

Inheritance does the boring work

Management contains Administration; Sites contains North Site. Folders assigned to the parent group reach the subgroups; those assigned to a folder reach the subfolders, with exclusions where needed. Assignments have a level, optional custom permissions and an expiry: the day after, the access is gone. The “Who has access” panel shows direct and inherited access, and where it comes from. And if an access change must be justified, the folder demands it.

How it works

  1. Create the group, set the manager

    Name, colour, description, manager, parent group if it is a subgroup. Then the people: whoever is in inherits everything the group has.

  2. Assign folders to the group, with expiry if needed

    From the folder or from the group: a level, optional custom permissions, an end date. An expired assignment disappears by itself, and stays in the log.

  3. Designate the auditors

    Whoever manages members can appoint auditors: they read shares, accesses and the audit log of the whole product, without being able to edit, download or share.

Whoever leaves the group leaves the folders. In the same instant.

What you can do

  • Two-level groups

    Parent group and subgroups, manager and colour. Inheritance goes from parent to children, never the other way.

  • Expiring assignments

    Person or group, level, optional custom permissions, end date. The due-diligence consultant leaves by themselves on 30 June.

  • Inheritance with exclusions

    What holds on “Clients” holds on every client, except where you set an exclusion or an exception for a single member.

  • Who has access, direct and inherited

    The panel lists people and groups with level and origin: from this folder, from one above, from a group, from a workspace.

  • Mandatory reason

    On folders that require it, every access change must be justified: the reason goes into the access-change log.

  • Auditor

    A designation, not a user type: the auditor or DPO sees everything read-only, and their activity stays in the log like everyone else’s.

Where access to a folder can come from
OriginWho receives itInherited by subfoldersExpiryShown in “Who has access”
Direct assignment persona yes yes yes
Group assignment gruppo e sottogruppi yes yes yes
Workspace member persona o gruppo yes no yes
Share to a person persona yes yes yes
Access to all folders (user type) Amministratore, Gestore yes no yes
Auditor designato yes no no

Frequently asked questions

How many group levels can I have?

Two: group and subgroup. Enough for “Management › Administration” or “Sites › North Site”, and few enough to always understand where an access comes from.

What exactly does the auditor see?

Shares, assignments, the access log and the audit log of the whole product, read-only. They do not open files, download or share. It is the role for the auditor, the DPO or the compliance consultant.

If I move a folder into a workspace, do the old accesses stay?

They stay, and the workspace flags it: “have access to this workspace’s folders without being members”. From there you decide whether to keep or detach them, one by one.

Move your company files to the cloud

Request a demo: we’ll show you how Files makes storage and sharing simple and secure.

Request a demo