Skip to content

Document storage and access control ​

What it is for ​

Two questions come up the moment real documents arrive: where are the bytes kept, and who may do what with them. This page answers both.

Where files are kept ​

  • Disk on the server is the default, and it streams large files without loading them into memory.
  • Your own bucket: a workspace can store its files in Amazon S3, MinIO, Azure Blob or Google Cloud Storage. Open Settings > Storage, enter the connection, and use Test connection. The test does a real round trip before anything is saved.
  • Credentials are encrypted with a key kept per workspace. They are never shown again after saving.
  • Object stores work for normal files. For very large files (several gigabytes), keep disk storage for now, because object stores hold a whole file in memory while moving it.
  • Video and audio get extra streaming copies stored beside the original. See Store large files and play video and audio.

Who may do what ​

Rights are checked on every action, and they follow the usual inheritance: file, then folder, then cabinet.

RightWhat it allows
ViewSee the file in lists, open its details and play video or audio in the player
DownloadSave a copy. Someone with only View sees no download button and no save-as menu
Create, update, deleteUpload, change and remove

Three layers can narrow access further:

  • Access control lists (ACLs) on a specific cabinet, folder, file or document. A named ACL can be reused across many items.
  • Field-level security: hide or make read-only particular fields of a document for some roles.
  • Record-level security: restrict which documents a role sees at all.

Set the rules in the Permission Designer. If no rule exists for document management, every signed-in person is allowed, as for the other platform features, so set rules before real use.

  • A video or audio player never uses a permanent address. It asks the server for a signed address that expires after four hours and names the person's rights at that moment.
  • Portal members reach library files only through folders the portal shows to their role.

What to know ​

  • Rights are checked on the server. Hiding a button is never the only protection.
  • Retention and legal hold protect documents from deletion by policy.
  • Everything done to a document is in its audit trail; sign-ins and permission changes are in the platform audit log.

Where next ​