> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.agilium.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Rights management

## Introduction

|| Access rights management is done only at the folder level 

For each folder, the user can restrict access to this sub-folder based on the user's group or a site to secure access to documentation

For each folder, the user can associate the following rights by role (user group) or by user:

* Browse = browse the tree structure
* Read = read the folder content
* Write = add content, add an annotation, rename, generate a new version, paste
* Delete = move to trash, delete a version, delete an annotation, cut, archive
* Share = generate a sharing link

Rights are progressive, meaning that when checking the "Write" right, the interface automatically checks the "Read" right. Same for deletion which will automatically check "Read" and "Write".

Similarly, if you explicitly uncheck "Read", automatically "Write" and "Delete" are unchecked.

## Specify rights on a folder

By default, the folder inherits rights from the parent folder without duplicating or specifying rights on the latter.

However, when specific rights apply, the administrator can specify rights on the folder from the "Rights" tab of the folder properties panel.

To add a right, the user selects a role or a user in the left column. By default, the "Browse" and "Read" rights are checked.

To delete a right, the user must click on the red cross.

|| It is preferable to favor rights management by group rather than by user. This allows simpler and more effective maintainability over time. 

![](https://storage.crisp.chat/users/helpdesk/website/-/9/c/b/b/9cbb13020d73800/sans-titre35_olg09h.png)

## Default rights on the Quality DMS

During installation, the '****quality****' folder (which contains all Quality DMS files, regardless of document status: In validation, Active, Abandoned, Archive) is visible to all platform users, because there is the system role "All users" which has the 'Read' level:

![](https://storage.crisp.chat/users/helpdesk/website/-/9/c/b/b/9cbb13020d73800/sans-titre36_79ifgm.png)

If you want to close default access to all users (and open it separately in each sub-folder), you must uncheck the 'Read' level.