Files extension

Why did you grant that access? Written down, every time.

Every time someone assigns, changes or revokes an access level, Files asks for a reason and does not proceed without it. The register keeps who made the change, to whom, on which folder or file, from which level to which, and why. Administrators and auditors get an email.

A register, not a confirmation dialog

The reason is not there to slow you down: it is there for later, when someone asks “why could the Bianchi firm see the staff folder?”. The register is per resource — folder or file — and per recipient — person or group — and every row is evidence: without a recipient or a resource nothing gets written. The obligation applies per folder, through the permission “Must give a reason when assigning, changing or revoking an access”, which goes with “Manage permissions”: you can require it on sensitive folders and not on “Marketing material”.

How it works

  1. Decide where it is mandatory

    In the access level of those who manage permissions, switch on “Must give a reason”. On the folders where that level applies, every access change will go through the reason field.

  2. Write the why

    You assign, change or revoke: the field opens — “Enter the reason for granting access…” — and without text saving does not go through. It applies to groups too.

  3. The register and the emails

    The row enters the access change register — readable and filterable — and an email goes out to administrators and auditors with the same data. Whoever checks knows before having to ask.

An access without a reason is an access nobody will be able to explain.

What you can do

  • People and groups

    The recipient can be a person or a group: the row says which, with name and email or group name.

  • Folders and files

    The register is resource-agnostic: an access granted on a single file is justified and logged like one granted on a folder.

  • From which level to which

    Every row carries the previous and the new level — Viewer → Editor — and the type of change: assignment, update, revocation.

  • Obligation per actor, not for everyone

    The reason is required from those who have that permission on the folder. Other changes stay in the register anyway, with the field empty.

  • For the auditor

    The email at every change is how the auditor watches access move in real time, with the why already written.

Frequently asked questions

Does it slow down those who manage many accesses?

One line of text per change, only on the folders where you required it. For bulk work — batch assignments, groups — the reason is written once per operation.

Who sees the register?

Administrators and auditors, who also receive the emails. The user who made the change sees their own rows in the activity.

Can I make it mandatory everywhere?

Yes: just switch on the permission in the access levels that manage permissions, on all root folders. The advice is to do it where it really matters, because a hastily written reason helps nobody.

Move your company files to the cloud

Request a demo: we’ll show you how Files makes storage and sharing simple and secure.

Request a demo