User and group document security
User and group document security provide an additional layer of protection beyond drawer-level permissions by letting administrators control user or group-level access to documents based on their index values. Using document security, you can deny access or provide full or view-only access to specific documents. You can configure these permissions for individual employees, for groups, or both.
When setting up document security, keep the following in mind.
- User-level permissions override group-level permissions.
- You can set document security to allow or deny access based on specific criteria at the user level or the group level.
- Document security can prevent users from accessing or editing documents based on specific criteria at the user level or the group level even if the user belongs to a group that has editing permissions.A best practice used by many firms is to configure document security at the group level whenever possible. If there are exceptions, the administrator configures document security at the user level.
The option you choose affects the user's or group's access to those documents.
- If you choose theDeny Accessoption for documents with certain index values (for example, business tax file sections), the user or group will have access to all documents within the drawer except those with the specified tax file sections. This table shows how such a configuration would impact access to documents.File sections (Typical)Deny Business TaxAllow Business TaxBusiness Tax 1120DenyAllowBusiness Tax 1120SDenyAllowBusiness Tax 1065DenyAllowBusiness Tax 5500DenyAllowBusiness Tax 990DenyAllowFiduciary TaxAllowDenyIndividual Tax 1040AllowDenyPayroll TaxAllowDenySales TaxAllowDenyGift/Estate TaxAllowDenyAuditAllowDenyGeneral LedgerAllowDenyFinancial StatementsAllowDenyPermanent BusinessAllowDenyPermanent IndividualAllowDenyGeneral CorrespondenceAllowDenyLitigation SupportAllowDenyBusiness ValuationAllowDeny
- If you choose theAllow Accessoption for documents with certain index values (for example, Client Number), the user or group will have access only to documents within the drawer that have the specified values. TheNo Editoption lets users view documents with certain index values, but restricts them from editing. Users withReadpermission can still export documents.noteTo set read-only access to a document for all users and groups, mark the document checkbox in the search results, right-click, and select Archive. The Archive status is a global document setting available to administrators as part of the GoFileRoom document retention features.