Role-based access control with real granularity
Permissions are assigned by role and applied per module, and the levels are deliberately finer than read/write. A user can be granted preview only, upload only, preview and download, editor, or a custom combination. The distinction between preview and download is the one that matters most in practice: it is the difference between letting someone read a confidential document and letting them keep a copy.
Roles are composed rather than fixed, so an auditor role can be built as read-everywhere-download-nothing without inventing a new user type. Folder permissions are inherited by the documents inside them, with per-document overrides where a genuine exception exists — and because overrides are the thing that quietly undoes a permission model, they are visible in the shared-access overview rather than buried per document.
- Preview only, upload only, preview and download, editor, or custom per module
- Folder-level inheritance with visible per-document overrides
- User, role, branch and department management in one place
- Shared-access overview showing everything currently shared and with whom
