| Audience: DocuShare administrators |
Manage DocuShare Object Permissions and Generate Permission Reports
Overview
DocuShare permissions determine which actions users can perform on objects. The permission model may use three permissions (Reader, Writer, Manager) or six permissions, depending on the site configuration. User level, group membership, object permissions, and inherited access all affect the result.
Review Permissions Before Changing Them
1. Open the object's properties or permissions page.
2. Review the user and group entries and the permission assigned to each.
3. Consider inherited access and the user's group memberships before changing an entry.
4. Make the smallest change that provides the required access, then test with an account representing the affected user.
The meaning of an action depends on the configured permission model. For example, in the three-permission model, changing permissions, ownership, or location generally requires Manager permission, while changing object properties requires Writer or Manager. Consult the permission matrix in the Administrator Guide for the site's three- or six-permission model and task.
Generate a User Permission Report
1. Open Admin Home > Content Management > Permission Reports > User Reports.
2. Select List Group Membership to review the groups containing a specified user. The report can be exported as CSV or Excel.
3. Select List Objects With Matching Permissions to find objects a user can access.
4. Enter the username or email address, then select an object type and permission filter as needed.
5. Select Generate Report and review the results.
Generate a Group Permission Report
Use Permission Reports > Group Reports to list group members, group memberships, or objects associated with a group. Filter results where the report provides filter options.
Use Reports Carefully
Permission reports show access at the time they are generated. If access changes afterward, generate the report again. Treat exported reports as sensitive because they can reveal users, groups, object names, and access patterns. Store and share them according to your organization's security policies.
Troubleshooting
- If a user has more or less access than expected, review direct permissions, group membership, inherited permissions, and user level.
- If a report is empty, confirm the username/email, selected object filter, and permission filter.
- For large sites, allow the report time to complete and avoid repeatedly launching identical reports.