Access and permissions

Which permission each Documents screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (11)

Permissions by screen

ScreenMenuPermission needed
LibraryDocuments > Documents > Librarydms.view (list); Upload needs dms.manage; New folder needs dms.configure
Library - My documents tabDocuments > Documents > My documentsdms.view
Library - Expiring tabDocuments > Documents > Expiringdms.view
Library - Quarantine tabDocuments > Documents > Quarantinedms.view
Document recordDocuments > Library > open a row > Open documentdms.view; Edit, New version, Archive need dms.manage; hold and disposal need dms.dispose
Upload documents wizardLibrary > Uploaddms.manage
Disposal reviewDocuments > Operations > Disposal reviewdms.dispose; menu hidden when Retention and disposal is switched off
Expiring documentsDocuments > Reporting > Expiring documentsdms.view
Retention registerDocuments > Reporting > Retention registerdms.view; menu hidden when Retention and disposal is off
Storage usageDocuments > Reporting > Storage usagedms.view
Workspaces and foldersDocuments > Configuration > Workspaces and foldersdms.view (list); dms.configure (New / Edit)
Document typesDocuments > Configuration > Document typesdms.view (list); dms.configure (New / Edit)
Retention policiesDocuments > Configuration > Retention policiesdms.view (list); dms.configure (New / Edit); menu hidden when Retention and disposal is off
Indexed storesDocuments > Configuration > Indexed storesdms.view; menu hidden when Indexed external stores is off
Documents smart buttonAny record with a smart-button row (sales / purchase document, invoice, customer, product, employee, vehicle, manufacturing order, project, transfer, journal entry)dms.view plus the right to read that record; no button when refused
Documents app configurationApplications > Documents > Features / FieldsCompany administrator (app configuration rights)

All Documents screens

RuleWhat the system does
dms.view neededNo menu; API calls refused 'You do not have permission for this action.'

Library / Upload

RuleWhat the system does
Upload needs dms.manageButtons hidden; API refused (403)

Document record

RuleWhat the system does
Hold and disposal need dms.disposeNo hold / disposal items; API refused. dms.dispose is not given to operational roles by default
Guessed id learns nothing (DOC-A2)All answer 'Record not found.' (404), same as an id that does not exist
Edit conflicts on hold and versionsTab 2 refused 'This record changed. Reload it before saving.'

Configuration

RuleWhat the system does
Configuration needs dms.configureLists readable, no New / pencil; API refused

Disposal review

RuleWhat the system does
Maker-checkerRefused: 'Somebody other than the person who proposed it must review a disposal.'

Library

RuleWhat the system does
Employee papers need hr.private.viewEmployee documents store and files not shown; opening one by id -> 'Record not found.'
Payroll bank files and recruitment filesPayroll bank files and Recruitment files not shown, not counted in tabs, storage or export

All

RuleWhat the system does
Company isolation'Record not found.'; the bytes store is per company so a key cannot reach another company's file

Upload

RuleWhat the system does
Linking needs the right to read the recordRefused 'Record not found.' (404); the wizard does not offer that record type

Preview / Download

RuleWhat the system does
Content cannot runX-Content-Type-Options: nosniff; Cache-Control: private, no-store; Content-Security-Policy with sandbox (PDF inline: default-src 'none'; frame-ancestors 'self'); non-viewable files sent as attachment

Export manifest

RuleWhat the system does
Export is audited and filteredNo employee papers in the CSV; audit 'dms.manifest.exported' with row count and hash; formula cells start with an apostrophe