- Inside: who on the team finds it in the library. Grants answer this, and Who sees it on an asset narrows it.
- Outside: who without an account gets it. Share links, signed URLs, Embed and portals answer this. Nothing goes outside unless someone with share on it sends it there.
Inside: grants add up and reach down
A person’s access is their grants: a role on the organization, a workspace, a collection or one asset. A grant reaches everything below what it is on, and grants add up: a person gets the highest role any of them gives. Here:Roles
An editor’s or admin’s grant can switch abilities off: an editor who can’t
delete, or can’t share.
Only people added
Who sees it on an asset, or Private on a collection, takes it out of the workspace’s reach. A role on the workspace no longer gets there; only these do:- a grant on the asset itself,
- a grant on one of its collections,
- admin on the workspace or the organization.
Outside: links
Each of these takes share on the asset, and stops once it is archived, expires or is replaced.
See sharing and portals.