← All guides

Access and permissions: who should see what

Security basics · 5 min read

Most access problems come from the same root cause: sharing that was generous when it was set up and never reviewed. An ex-contractor still in the shared folder, a "anyone with the link" document floating around, a whole team with edit access to a folder where they only ever read. None of this needs security software to fix — it needs simple rules and a regular look.

Start default-private

The simplest policy that works: new folders and documents start private, and access is granted deliberately. It's much easier to open things up as needed than to discover later that something sensitive was visible to everyone. When someone asks "why can't I see this folder?", the answer should be "let me add you" — not "I didn't know you could."

Share by role, not by person

Give access based on what someone needs to do, not who they are:

If your tool supports sharing with groups (a mailing list, a team group), use groups instead of naming individuals. When someone joins or leaves, you update the group once instead of hunting through dozens of shared folders.

Sharing links need hygiene

Links are convenient and also the most common way access leaks. A few habits:

Audit access twice a year

Access decays: people change roles, contractors finish, projects end. Twice a year, go through your main shared areas and ask three questions:

  1. Who has access? Look at the actual sharing list, not who you think has access.
  2. Do they still need it? Former employees, finished contractors, and people who moved teams come off the list.
  3. Is the level right? Anyone with edit access who only ever reads goes down to viewer.

This takes less time than it sounds, and it catches the slow accumulation that turns "the finance folder" into "the folder half the company can edit."

Offboarding is part of access control

When someone leaves — employee, contractor, volunteer — removing their access should be a checklist item on their last day, not a "we'll get to it." The list:

Keep the model simple enough to explain

The final test of any permissions setup: can you explain it to a new person in two minutes? "Everyone sees their team's folder, editors are the content owners, the admin group is just the two of us, and we review access every six months" is a complete access policy for most small teams. If your setup needs a diagram, it's too complicated — and complicated permissions are the ones nobody maintains.

Back to all guides →