> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Folder Permissions

# 🔐 **Folder Permissions**  
> **"Control who sees what."**  
> *Flexible, document-based permissions for precise access control.*  

Inside Brainframe, **everything is treated as a document**—policies, procedures, risks, non-conformities, and more. This enables a **flexible permission model** through folder permissions.  

📌 *A single folder can have multiple **views**, each with its own permissions.*  

Example: A folder named *Product X* could have views for **Security**, **Documentation**, and **GDPR**, each visible to different audiences, as explained in [Folder management](https://docs.brainframe.com/en/article/folder-management-1d8wdkm/).  

---

## 1️⃣ Opening the Permissions Screen  
You can configure permissions for all folders except **INBOX**.  

1. Click on **Modify folder**.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/screenshot-2026-07-07-at-16141_1e3t98w.png =676xauto)


2. Select the **Permissions** button.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/screenshot-2026-07-07-at-16160_jtdeo4.png =497xauto)


This opens the full **Permissions screen**:  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/1_vcm0ie.png =673xauto)
| 📌 Users can only see folders where they have at least READ permission.  

## 2️⃣ Assigning Permissions  

1. Start typing the name of an existing user, or enter the email of a new contact to invite them.  

📌 *Permissions can be assigned to individual users or groups.*

2. **READ permissions** allow:  
* Opening all documents in the folder.  
* Approving documents with an unassigned approval, or those assigned directly.  
* Performing **KPI/Risk readings** on documents.  

3. **READ + WRITE permissions** allow everything from READ plus:  
* Creating and deleting documents in the current folder.  
* Modifying all aspects of documents (title, properties, planning, etc.).  
* Moving or linking documents to other folders.  

4. **READ + WRITE + MANAGE permissions** allow everything above plus:  
* Modifying folder and view names.  
* Changing folder permissions.  
* Creating, moving, or deleting subfolders.  

5. You can select **multiple users or groups** at once.  

||| Due to our ability to link folders in multiple places, and contrary to how typical folder permissions inherit permissions, in Brainframe folders are always only configured on the current folder (and not on its subfolders). To simulate inheritance you can use step 5 and 6 explained above
---

## 3️⃣ Best Practices  
* 👥 **Use groups** instead of individuals when possible to simplify management.  
* 🔄 **Apply permissions to subfolders** if consistent access is required.  
* 🚨 **Review MANAGE access carefully**—limit it to trusted admins.  
* 📝 **Document your permission model** for audit readiness.  
* 🔍 **Audit permissions regularly** to ensure compliance with least privilege.  

---

## 🎯 Visual Checklist  
* [x] Permissions screen opened  
* [x] Correct users/groups added  
* [ ] Appropriate access level (READ/WRITE/MANAGE) assigned  
* [ ] Subfolder permissions applied if required  
* [ ] Permission model documented and reviewed  
