Glossary
Permission inheritance
Also called: inherited permissions
Permission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually. It is what makes a permission model maintainable at scale, because a new document is correctly restricted the moment it arrives rather than afterwards.
Permission inheritance explained
Why inheritance is the default
Document-level permissioning as a primary model produces an estate nobody can audit: every document is an independent decision, and after two years no report can tell you who can reach what. Inheritance moves the decision to the folder, where there are far fewer of them and where the structure already reflects who should see what.
It also handles new documents correctly without anyone acting, which is the important property — a document that arrives with open permissions and is restricted later has already been visible.
Overrides, and why they need surfacing
Genuine exceptions exist: one document in a folder that is more sensitive than its siblings. The problem is not the exception but its invisibility. Overrides accumulate, nobody remembers them, and the folder's stated permissions stop describing reality.
The fix is a report — a shared-access overview listing every override and active share, so an access review can see them without inspecting documents one at a time.
Effective permissions
What a specific user can actually do with a specific document, after inheritance, overrides, role membership and any network restriction have been applied. If a system cannot answer that question directly, permission problems can only be found by trial.
FAQ
Permission inheritance: common questions
Should a moved document keep its permissions or inherit new ones?
Inherit, in most cases — the folder reflects who should see the content. The exception is a document with a deliberate override, which is why moves involving overridden documents deserve a prompt.
How deep should inheritance go?
As deep as the hierarchy, with breaks only where a genuine boundary exists. Each break is a place the model can drift, so fewer is better.
Related terms
- Access reviewAn access review is a periodic check that the people who have access to something still need it.
- API keyAn API key authenticates a program rather than a person.
- Break-glass accessBreak-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
- Data residencyData residency is the commitment that data is stored and processed within a specified country or region.
- Encryption at restEncryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Role-based access controlRole-based access control grants permissions to roles rather than to individuals, and assigns people to roles.
Last reviewed: 28 August 2026. Browse the full glossary.