Appearance
Document storage and access control
What it is for
Two questions come up the moment real documents arrive: where are the bytes kept, and who may do what with them. This page answers both.
Where files are kept
- Disk on the server is the default, and it streams large files without loading them into memory.
- Your own bucket: a workspace can store its files in Amazon S3, MinIO, Azure Blob or Google Cloud Storage. Open Settings > Storage, enter the connection, and use Test connection. The test does a real round trip before anything is saved.
- Credentials are encrypted with a key kept per workspace. They are never shown again after saving.
- Object stores work for normal files. For very large files (several gigabytes), keep disk storage for now, because object stores hold a whole file in memory while moving it.
- Video and audio get extra streaming copies stored beside the original. See Store large files and play video and audio.
Who may do what
Rights are checked on every action, and they follow the usual inheritance: file, then folder, then cabinet.
| Right | What it allows |
|---|---|
| View | See the file in lists, open its details and play video or audio in the player |
| Download | Save a copy. Someone with only View sees no download button and no save-as menu |
| Create, update, delete | Upload, change and remove |
Three layers can narrow access further:
- Access control lists (ACLs) on a specific cabinet, folder, file or document. A named ACL can be reused across many items.
- Field-level security: hide or make read-only particular fields of a document for some roles.
- Record-level security: restrict which documents a role sees at all.
Set the rules in the Permission Designer. If no rule exists for document management, every signed-in person is allowed, as for the other platform features, so set rules before real use.
Playback and share links
- A video or audio player never uses a permanent address. It asks the server for a signed address that expires after four hours and names the person's rights at that moment.
- Portal members reach library files only through folders the portal shows to their role.
What to know
- Rights are checked on the server. Hiding a button is never the only protection.
- Retention and legal hold protect documents from deletion by policy.
- Everything done to a document is in its audit trail; sign-ins and permission changes are in the platform audit log.
