Folder Permissions
π Folder Permissions
"Control who sees what."
Flexible, document-based permissions for precise access control.
Inside Brainframe, everything is treated as a documentβpolicies, procedures, risks, non-conformities, and more. This enables a flexible permission model through folder permissions.
π A single folder can have multiple views, each with its own permissions.
Example: A folder named Product X could have views for Security, Documentation, and GDPR, each visible to different audiences, as explained in Folder management.
1οΈβ£ Opening the Permissions Screen
You can configure permissions for all folders except INBOX.
- Click on Modify folder.
- Select the Permissions button.
This opens the full Permissions screen:
2οΈβ£ Assigning Permissions
- Start typing the name of an existing user, or enter the email of a new contact to invite them.
π Permissions can be assigned to individual users or groups.
- READ permissions allow:
- Opening all documents in the folder.
- Approving documents with an unassigned approval, or those assigned directly.
- Performing KPI/Risk readings on documents.
- READ + WRITE permissions allow everything from READ plus:
- Creating and deleting documents in the current folder.
- Modifying all aspects of documents (title, properties, planning, etc.).
- Moving or linking documents to other folders.
- READ + WRITE + MANAGE permissions allow everything above plus:
- Modifying folder and view names.
- Changing folder permissions.
- Creating, moving, or deleting subfolders.
- You can select multiple users or groups at once.
- Current permissions can be applied to all subfolders.
3οΈβ£ Best Practices
- π₯ Use groups instead of individuals when possible to simplify management.
- π Apply permissions to subfolders if consistent access is required.
- π¨ Review MANAGE access carefullyβlimit it to trusted admins.
- π Document your permission model for audit readiness.
- π Audit permissions regularly to ensure compliance with least privilege.
π― Visual Checklist
- [x] Permissions screen opened
- [x] Correct users/groups added
- [ ] Appropriate access level (READ/WRITE/MANAGE) assigned
- [ ] Subfolder permissions applied if required
- [ ] Permission model documented and reviewed
Updated on: 11/09/2025
Thank you!