Skip to main content

Permissions for Documents

Learn which roles see which document areas and how read and write permissions per folder are assigned.

Written by Gideon Weller

Permissions in Document Management have two layers: a role-based base visibility determines which document areas a person can access at all. Within these areas, read and write permissions per folder are assigned granularly.

Role-based base visibility

Which document areas a person can see depends on their ZEP role:

Administrators

Administrators have access to all document areas: general documents, employee documents, project documents, and customer documents. They can create folders, upload documents, and assign permissions.

Controllers

Controllers have access to Employee documents and General documents by default. Project and customer documents are not included.

Users with additional authorizations

Users with the Additional authorizations permission see Customer documents, Project documents (if assigned as project team member or project manager), and General documents.

Users without additional authorizations

Users without additional authorizations see Project documents only for projects in which they are entered as project team member or project manager, as well as General documents. Employee and customer documents are not visible.

Employees and their own documents

Every person sees their own employee documents under Documents > Employee documents – even without further permission. Standard users only see their own folder there. Administrators, controllers, and Department Manager see the folders of all authorized persons.

Granular permissions per folder

Within each area, read and write rights are assigned separately per folder. You assign permissions via the two links Set Read Access and Set Write Access above the table or by right-clicking the folder. Each link opens its own dialog with the Explicitly authorized employees selection field and the following options:

  • Read permission – who may open the folder and its documents

  • Write permission – who may upload, edit, move, or delete documents

For each selection field, the following options are available:

  • all – every authorized person may access. This option is only available for general documents and employee documents, not for project or customer folders.

  • As defined for the parent folder – the right of the parent folder is adopted. In the selection, the inherited value appears in square brackets.

  • All project team members – only employees assigned to the project (only for project folders)

  • All project managers – only persons with project manager role in this project (only for project folders)

  • All users with additional authorizations – persons with this role

  • Special team member list – individual selection of single persons from a list

Above the selection, the dialog shows the Implicitly authorized employees as a read-only group. These always include all administrators, for project, customer, and employee folders additionally the responsible department managers, and for customer folders the key account manager. These persons always have access regardless of the selection.

The links Set Read Access and Set Write Access are only available to employees who already have write access to the relevant folder, in particular administrators and implicitly authorized persons such as department heads or the customer representative. For employee folders, this does not apply to the top-level folder: these links are not available there.

Right-clicking a folder icon opens a context menu with further actions for the selected folder:

  • "New document" – creates a new document in the folder

  • "New reference" – links to a document stored externally

  • "New subfolder" – adds another level within the folder structure

  • "Rename" – renames the folder

  • "Delete" – permanently removes the folder along with all subfolders and documents it contains, which is why you must confirm a safety prompt

These actions are only available if you have write permission for the respective folder.

Inheritance of permissions

If a sub-folder is configured with the option As defined for the parent folder, it automatically adopts the permissions of the parent folder. If the parent folder permissions change later, they apply to the inherited sub-folders without further adjustment.

Note: For newly created sub-folders, the option As defined for the parent folder is set by default. You can change this default to a specific selection at any time via Set Read Access or Set Write Access.

Right to change permissions

Permissions can be changed by persons who themselves have write permission on the relevant folder. Administrators generally have write permission on all document areas.

Did this answer your question?