Library Roles and Permissions
Access to the Library is controlled at two levels: your Library permission determines which Library features you can use overall, and your folder permission determines what you can do within each specific folder.
Who Can Access the Library
- Users in the Administrator role have full access to all Library features.
- Users in the Member role can access the Library if they have been granted one of the following permissions: Library.Creator, Library.Viewer, or Library.FileUploader.
- Users in the Guest role cannot access the Library.
Library permissions are assigned from the Users tab in the Team Management screen. See User Permissions for instructions on how to assign permissions.
Library Permissions
Five permissions are relevant to the Library. They are defined in full on User Permissions, which is the canonical list; what follows is only what is specific to the Library.
| Permission | In the Library |
|---|---|
| Library.Creator | Full access, subject to folder permissions. Cannot archive or restore templates. |
| Library.Viewer | Read-only. Can view and download in any accessible folder. |
| Library.FileUploader | Uploading files only. Grants no other Library access unless paired with Library.Creator or Library.Viewer. |
| Template.Creator | Enables the New Template button. Grants no Library access on its own. |
| KnowledgeBase.Creator | Enables the New Article button. Grants no Library access on its own. |
The distinction that catches people out is the last two: they enable a button for someone who is already in the Library, and do nothing at all for someone who is not.
Folder Permissions
In addition to a Library permission, each folder has its own permission settings. These are set per-folder and can be granted to individual team members or to groups.
| Permission | Description |
|---|---|
| Edit | Can view all items in the folder and make changes — add, edit, move, and delete items |
| View | Can view and download items in the folder; cannot make any changes |
| Deny | Cannot see the folder or any of its contents |
Folder permissions are managed by opening the folder editor (hover over the folder in the sidebar and click the pencil icon) and navigating to the Permissions tab.
See Folders for step-by-step instructions on setting folder permissions.
Permissions Matrix
The table below shows what each combination of Library permission and folder permission allows. Your effective access is the more restrictive of your Library permission and your folder permission.
| Action | Administrator | Library.Creator + Edit folder | Library.Creator + View folder | Library.Viewer |
|---|---|---|---|---|
| Access the Library | ✓ | ✓ | ✓ | ✓ |
| View items in a folder | ✓ | ✓ | ✓ | ✓ |
| Download files | ✓ | ✓ | ✓ | ✓ |
| View template analytics | ✓ | ✓ | ✓ | ✓ |
| View checklist runs | ✓ | ✓ | ✓ | ✓ |
| View version history | ✓ | ✓ | ✓ | ✓ |
| Create a folder | ✓ | ✓ | — | — |
| Edit / rename a folder | ✓ | ✓ | — | — |
| Delete a folder | ✓ | ✓ | — | — |
| Manage folder permissions | ✓ | ✓ | — | — |
| Add a template to the Library | ✓ | ✓ | — | — |
| Edit a template | ✓ | ✓ | — | — |
| Duplicate a template | ✓ | ✓ | — | — |
| Generate a Create & Run link | ✓ | ✓ | — | — |
| Move an item to another folder | ✓ | ✓ * | — | — |
| Create an article | ✓ | ✓ | — | — |
| Edit an article | ✓ | ✓ | — | — |
| Delete an article | ✓ | ✓ | — | — |
| Upload a file | ✓ | ✓ | — | — |
| Edit file tags | ✓ | ✓ | Own files only | — |
| Delete a file | ✓ | Own files only | — | — |
| Open a Data Set and browse its records | ✓ | ✓ | ✓ | ✓ |
| Export a Data Set to CSV | ✓ | ✓ | ✓ | ✓ |
| Create a Data Set | ✓ | ✓ | — | — |
| Edit a Data Set's fields, records and Views | ✓ | ✓ | — | — |
| Replace a Data Set's records from CSV | ✓ | ✓ | — | — |
| Delete a Data Set | ✓ | — | — | — |
| Archive a template | ✓ | — | — | — |
| Restore an archived template | ✓ | — | — | — |
| View the Archived folder | ✓ | — | — | — |
* Moving an item requires Edit permission on both the source and destination folder.
Deleting a Data Set is restricted to Administrators because a Data Set can be feeding controls across many templates. See Data Set Limits and Permissions.
How Library Permission and Folder Permission Interact
To access a folder, a user must satisfy both conditions:
- They must have a Library permission (Library.Creator, Library.Viewer, or Library.FileUploader) or be an Administrator.
- They must have a folder permission of Edit or View for that specific folder (Administrators are exempt from this requirement).
If either condition is not met, the folder will not be visible to the user.
Example: A user with Library.Creator but a Deny folder permission cannot see that folder at all. A user with no Library permission cannot access the Library regardless of folder permissions.
Related Pages
- User Permissions — the canonical list of what each permission grants.
- Library Folders — folder permissions combine with them.
- Roles & Permissions — the three roles underneath.