Skip to main content

Applying permissions in a data room

Control who can access a data room and define what actions they can perform at data room, folder and file level

Permissions control who can access a data room and what actions they can perform.

They can be applied at multiple levels and are inherited by default, allowing you to share documents broadly or restrict access to specific folders or files where required.


Permission levels

Data rooms use four permission levels:

View: Access the data room and preview its contents.

Upload: Add documents and create folders.

Download: Download documents and export content.

Edit: Manage the data room structure and content, including renaming, deleting and reorganising items.

Note: Users with View permission can preview files in the browser. Previewing downloads the file to the browser cache but does not grant Download permission


How permission levels relate to each other

Permissions are independent, but View access is always required to interact with a data room.

  • Upload, Download and Edit include View access.

  • Edit does not automatically include Upload or Download.

  • Upload and Download do not automatically include Edit.

This means you can, for example:

  • Allow a user to upload documents without allowing them to reorganise folders.

  • Allow a user to download documents without allowing them to upload new versions.

  • Grant Edit access while separately controlling whether uploads or downloads are permitted.

Permissions must be combined intentionally to reflect each user’s role.


Where permissions can be applied

Permissions can be applied at three levels:

Data room level: Controls access to the entire data room.

Folder level: Controls access to a specific folder and everything within it.

File level: Controls access to an individual document.

By default, permissions are inherited from the parent level. This means folders and files inherit permissions from the data room unless they are explicitly overridden.

Setting up permissions in advance

You don't need to wait until a participant has access to the data room before configuring their folder or file level permissions.

You can save access for a participant on a folder or document ahead of time, even if they don't yet have matching access further up the hierarchy. These settings are stored but only take effect once the participant is granted the matching permission at the parent level, at which point they activate automatically.

This means you can configure a new participant's access in a single pass through the data room, rather than granting top level access first and then revisiting every relevant folder afterwards.

Note: A folder or file can never give more access than the level above it. If you set access that the level above doesn't allow yet, it isn't granted straight away. It's saved and activates automatically once the level above allows it. Until then, you'll see a message telling you some permissions are waiting on the parent.


Overriding inherited permissions

By default, each folder and document takes its permissions from the level above, so you don't need to add any different permissions for these to work. You only need to set your own permissions where a folder or file should be different from the level above it.

When you open permissions for a folder or file that hasn't been given its own permissions yet, you have two options:

  • Leave as parent: closes the panel without changing anything. The item continues to inherit whatever is set at the data room or parent folder level.

  • Save as custom: saves the current settings against that folder or file. From that point on, it stops following changes made at the parent level for the participants and permission types you've saved.

Once you've changed a folder or file to be different from the level above, it has custom permissions. You can return it to matching the level above at any time using the Reset to parent option. Because this removes any custom access you've set, you'll be asked to confirm the action before it takes effect.

Lower-level permissions can be used to restrict access relative to the parent level.

For example:

  • A user has Edit permission at the data room level.

  • A specific folder is set to View only.

In this case:

  • The folder-level restriction applies.

  • The user can view the folder but cannot upload, edit or move content within it.

  • The folder is treated as restricted for edit actions.

If a user attempts to move files or folders into a restricted location, the action is blocked and an error message is displayed.

Note: Data room-level Edit permission does not override folder or file-level restrictions

This ensures sensitive content can be protected even when broader permissions exist elsewhere in the data room.


Applying permissions during setup

Many admins choose to:

  1. Build the folder structure first.

  2. Upload documents.

  3. Apply permissions once the structure is finalised.

This approach reduces the risk of accidentally sharing incomplete or incorrectly structured content.


Viewing permissions across a data room

Matter Admins can export a report to review the full permissions in bulk. This shows exactly who has access to what across a data room, at the point it's generated.

To generate a report:

  1. Open the data room's permissions page

  2. Click Export in the top right

  3. Choose CSV and My computer as the destination

  4. Click Export

The report is generated in the background. You'll see a notification when it's ready, with a link to download it. For very large data rooms, this may take a little longer to prepare.

What's included: each row in the report covers one folder or document and one participant with access to it, showing:

  • The data room, folder and item name

  • The participant's name and details

  • Their current permissions, shown as a four letter code: V (View), D (Download), U (Upload), E (Edit). A missing letter shows as a hyphen, so VD-- means the participant can view and download but not upload or edit.

  • When their access last changed, and who made that change

Matter admin access

Matter Admins always retain full access to all data rooms within the matter.

This ensures that:

  • Misconfigured permissions can be corrected.

  • Accidental lockouts can be resolved.

  • Administrative oversight is maintained.

No additional override rules are required. Matter Admins can always regain access if needed.

Did this answer your question?