Skip to main content

Permission levels

Every workspace, project, folder and document has its own list of people, each with one level — View, Edit or Edit & Share — and exactly one owner. This page covers how levels combine down the tree, what the Members page shows, what removing someone does, and closes with the table of who can do what. Also called: roles, access rights.

How levels combine down the tree

Access flows downward: workspace → project → folder → document.

  • Your level on an item is the highest of the level you were given on the item itself and the levels you hold on everything above it.
  • A grant can only widen access. Someone with Edit on the workspace who is given View on one document still has Edit on that document. There is no way to lower access for a single item below what its folder, project or workspace gives.
  • The person who creates an item owns it. Owning an item counts as Edit & Share on it and on everything inside it, and that can't be lowered. A duplicated document belongs to the person who duplicated it.
  • The workspace owner has Edit & Share on everything in the workspace, with one exception: Invite only projects.

When someone can still edit after you set them to View, their access comes from higher up. An item's Share dialog lists only the people added to that item directly, so check each level in turn: the folders above the item, the project, then Settings → Workspace → Members. Change the level where it was given. Also check whether the person owns the item or a folder above it.

Invite only projects

Where: the Visible to setting in the Add Project dialog and in the project's Share dialog.

  • All workspace members is the default: workspace levels apply inside the project.
  • Invite only cuts the link between the workspace and the project. Only the project's owner and the people added to the project directly get in. Everyone else doesn't see the project at all — including the workspace owner and workspace members with Edit & Share.
  • Only that one link is cut. Inside the project, folders and documents inherit from the project as usual.
  • Changing Visible to needs Edit & Share on the project; renaming the project needs only Edit.
  • Switching a project to Invite only while your own access comes from the workspace locks you out of it. Add yourself to the project first, unless you own it.
  • A workspace member who is invited to a single folder or document inside an Invite only project finds it under Shared with me; the project does not appear in their sidebar.
  • People added to an Invite only project who are not workspace members are listed under Guests on the Members page, where anyone with Edit & Share on the workspace can remove them.

Members, guests and invitations

Where: Settings → Workspace → Members. The app shows the workspace settings to the workspace owner and to members with Edit & Share on the workspace.

  • Members — people added to the workspace itself. Their level applies to everything in the workspace except Invite only projects.
  • Guests — people who are not members but were added directly to a project, folder or document in the workspace, or who own something in it. A guest has no single level: their levels sit on the individual items.
  • Invited — invitations to the workspace that nobody has accepted, shown as Invite sent. Invitations to a single project, folder or document are not listed here; they appear in that item's Share dialog.

The workspace owner's row shows Owner and has no level menu: the workspace owner can't be changed, lowered or removed.

LAST ACTIVE is tracked per workspace, not per account. It moves when the person uses this workspace in the dashboard, or opens one of its documents and moves the pointer, selects, edits or comments there. A document left open and idle does not count. Guests are tracked too; means no activity has been recorded, and invitations always show .

Anyone can remove their own access, at any level. For an item shared with you directly, use Remove from shared under Shared with me. On the Members page, Remove on your own row asks you to confirm with Leave workspace and ends your membership at once; what you own and the levels given to you directly stay, as for any removed member. An owner can't leave their own item.

Removing someone's access

Where: Settings → Workspace → Members → the menu at the end of the person's row → Remove.

Remove on a member's row deletes only the workspace membership. The projects, folders and documents the person created stay theirs, and levels they were given directly on individual items stay in place. What happens next depends on what remains:

What the person still has in the workspaceResult
NothingThe person is gone from the workspace.
Only direct View grantsThey appear under Guests and keep that View access. They do not occupy a seat.
Edit or Edit & Share on any item, or ownership of any project, folder or documentThey appear under Guests, keep that access, and still occupy a seat.

To end the access completely, remove the person a second time, under Guests. Removing a guest needs Edit & Share on the workspace.

warning

Remove on a guest's row can't be undone. It deletes every level the person holds in the workspace, makes the workspace owner the owner of every project, folder and document the person owned there, and moves the person's Trash entries for this workspace to the workspace owner's Trash.

Who can do what

The columns are the level you hold on the item, inherited levels included. Owner is the owner of that item: it equals Edit & Share, plus the right to delete the item or move it away whatever the level on its container. ✓ means allowed, — means refused, and container means your level on the item does not count: the level you hold on the folder, project or workspace that contains it decides.

In the dashboard

The level is the one you hold on the document, folder or project.

CapabilityViewEditEdit & ShareOwner
Open it and see its content
Add to starred a document or folder
Duplicate a document — the copy lands in the same folder, and that folder needs Editcontainercontainercontainer
Rename
Create a document or folder inside it
Move items into it, restore items from Trash into it (Trash)
Delete it or move it somewhere else — needs Edit on the folder, project or workspace that contains it (delete and move)containercontainercontainer
See who it is shared with (Share dialog)
Invite people, change someone's level, remove someone
Revoke or re-send an invitation — the app offers these to
Remove your own access
Change a project's Visible to

On the workspace

The level is the one you hold as a workspace member.

CapabilityViewEditEdit & ShareOwner
See and open projects set to All workspace members
Create a project (Projects)
Rename the workspace
Invite members, change their level, remove them
See Guests and the seat count, remove a guest
Upload, rename or delete custom fonts — uploading also depends on the plan

In the editor

The level is the one you hold on the document. With View the document opens in Read only mode, marked Read only next to the document name. The mode goes beyond the app's disabled controls: no change sent from a View session is saved.

CapabilityViewEditEdit & ShareOwner
Open the document, switch pages, select layers and inspect their settings
Copy, Copy asCopy as PNG / Copy as SVG, Copy link
Appear to collaborators with pointer and selection
Change anything in the document

Comments

The level is the one you hold on the document. The same rules apply in the editor and in preview.

CapabilityViewEditEdit & ShareOwner
Read comments
Start a thread, reply
Resolve and reopen a thread
Edit your own comment — nobody can edit someone else's
Delete your own comment or thread
Delete someone else's comment or thread

In preview

The level is the one you hold on the document. Preview needs a signed-in account with at least View; there are no public links.

CapabilityViewEditEdit & ShareOwner
Open the prototype and interact with it
Read and add comments