Skip to main content
Two separate questions decide who reaches an asset:
  • Inside: who on the team finds it in the library. Grants answer this, and Who sees it on an asset narrows it.
  • Outside: who without an account gets it. Share links, signed URLs, Embed and portals answer this. Nothing goes outside unless someone with share on it sends it there.
The two don’t mix: an asset only some people see can still have an embed URL, and an asset everyone on the team sees is still closed to the rest of the world.

Inside: grants add up and reach down

A person’s access is their grants: a role on the organization, a workspace, a collection or one asset. A grant reaches everything below what it is on, and grants add up: a person gets the highest role any of them gives. Here:

Roles

An editor’s or admin’s grant can switch abilities off: an editor who can’t delete, or can’t share.

Only people added

Who sees it on an asset, or Private on a collection, takes it out of the workspace’s reach. A role on the workspace no longer gets there; only these do:
  • a grant on the asset itself,
  • a grant on one of its collections,
  • admin on the workspace or the organization.
An asset whose collections are all private is hidden the same way, without its own setting. One that is also in a collection that isn’t private is seen by the whole workspace. Whoever hides something keeps reaching it: they get a grant on it at the role they had. A workspace admin adds and removes people under Who sees it in the asset’s panel, or on Settings, People for a collection. Upload privately, in the Upload menu, hides files from the moment they land. A contributor’s private upload waits in Review where only admins see it, since editors aren’t among the people added. Each of these takes share on the asset, and stops once it is archived, expires or is replaced. See sharing and portals.

Keys and agents

An API key works in one workspace with one role. A key a person connects is capped at what that person can do there, and loses it when they do. Agents usually get Contributor: what they add waits for a human (decision 0005, decision 0006).