Skip to main content

Access and Administration

Access design starts with the work you want people to perform. Reading a file, publishing a Share Link, maintaining a team's accounts, and administering a Workspace are different responsibilities. Files.com lets you grant those responsibilities at different levels so that a person does not need full site administration to do useful work.

Administrators use this section to choose the boundaries around teams, external organizations, and shared resources. The boundary must match what you are delegating. A folder permission controls access to content; a Group Admin manages accounts and membership; a Workspace Administrator can manage a complete set of resources. Treating all three as variations of "access to this folder" misses the authority each role carries.

Permissions Combine With Ownership

A user's effective folder access can come from direct grants and group membership. Resources such as Share Links and Automations also have ownership and execution rules. The person allowed to edit a resource, the person who starts an operation, and the permissions used by that operation are not always the same.

This is why access reviews need to consider both people and the resources they manage. Removing a person from a group changes the access they receive through that membership. It does not necessarily end a business process they configured or a Share Link they created. Those resources have their own lifecycle because organizations need workflows and external relationships to survive staff changes.

Choosing What to Delegate

Delegating account administration lets team leads and partner organizations handle their own onboarding and maintenance. It also lets them influence who can use the access you have granted. Membership, recovery addresses, credentials, expiration dates, and re-enablement all matter when choosing a delegate's capabilities.

Start with the resources and account population the delegate should control, then select the role and its settings. Review inherited permissions and existing shared resources alongside that choice. Delegated Administration explains the consequences of the Group Admin and Partner Admin capabilities in that context.