**This is an old revision of the document!**

Shared Team Folder Access Controls

Last updated: March 7, 2019

The org. admin can manage access to any Shared Team Folder. This means that he can control who has access to a Shared Team Folder, and he can grant access to himself.

Any org.member who has been assigned a role that has the “manage Team Folders” permission can manage access to any Shared Team Folder, and can grant access to himself.

An org. member to whom the “Manage Permissions” privilege has been assigned for a Shared Team Folder, either directly or because the org. member has been assigned a role that has this privilege, can manage access to that folder.

Access to each Shared Team Folder can be granted to individual org. members. Access to each Shared Team Folder can also be granted to roles, in which case the access privilege applies to every org. member to whom the role has been assigned, subject to these two rules:

  1. Access privileges granted to the individual org. member supersede privileges granted to a role that has been assigned to the org. member.
  2. When an org. member has been assigned two or more roles and the roles have different access privileges for a folder, the most permissive access level prevails.

Each folder also has a default access level. This is the access level that is applied to org. members to whom no other access level has been assigned either directly or through a role.

Inherited Permissions and Managed Folders

When a Shared Team Folder is created, either as a new folder or by converting an existing folder, any folders beneath that folder in the directory tree inherit whatever permissions are applied to that folder (but not necessarily the permission modifiers, which are discussed later in these notes). If permissions are changed on the Shared Tea Folder then the folders beneath it inherit the changes.

Permissions can be changed by a user with the appropriate authority on folders that are beneath a Shared Team Folder in the directory tree. When this happens, the folder on which permissions were changed becomes a Managed Folder. At the moment that a folder becomes a Managed Folder it stops inheriting access permissions from the folder above it in the directory tree, and changes to the permissions on its parent folder’s permissions no longer apply to the newly created Managed Folder.

These permission modifiers are inherited by unmanaged subfolders:

  • List Only
  • Web View Only
  • Can Share Files

These permission modifiers are not inherited by unmanaged subfolders:

  • Subfolder create disabled
  • Upload disabled
  • File rename disabled
  • File move disabled

A new Managed Folder allows no access to any users or roles except those granted by the user who created the Managed Folder by changing a permission. The new Managed Folder’s default access level is copied from its parent folder at the time the Managed Folder is created and can be changed independently of the parent folder’s default access level.