This article covers the permission design and ongoing operational tasks that administrators (Owner / Team Administrator) perform when using Dive across multiple companies, factories, or departments.
For guidance on whether to consolidate multiple contracts (teams) or keep them separate, see Consolidating multiple companies or organizations into a single team: benefits and drawbacks. For initial setup in a single team structure, see Initial setup and notes for multi-department operations.
Prerequisites: The relationship between Teams, Groups, and Folders
Multi-organization operations are determined by combining three organizational units:
- Team: Your contract unit. It represents your entire company and exists only once within Dive. When teams differ, SOPs, users, permissions, plans, security settings, and usage reports are all completely independent.
- Group: Departments, sections, or projects within a team. Groups can be organized hierarchically (for example, Manufacturing Department > Manufacturing Section 2), and a single user can belong to multiple groups. The number of groups and levels of subgroups you can create depends on your plan.
- Folder: The location where SOPs are stored. You specify which groups have access to each folder. Members of the assigned group and any subgroups beneath it can access the folder. Additionally, you can separately specify which groups can also edit, allowing you to set permissions where some groups can only view but not edit.
In other words, you determine "who" through groups and "what" through folders. Even when spanning multiple companies or sites, you design visibility using these two dimensions.
Plan-based restrictions
When operating across multiple companies or factories, you are limited by the number of groups you can create and the depth of their hierarchy. Please review these before starting your design.
- Groups: Free and Lite plans cannot create groups. Core plan allows up to 5 groups, and Pro and Enterprise plans allow unlimited groups.
- Subgroups (group hierarchy): Core and Pro plans allow 1 level (for example, Manufacturing Department > Manufacturing Section 2). Deeper hierarchies are available only with the Enterprise plan.
- Guest invitations: Available with Core plan and higher. You can invite up to 3 times the number of accounts, counted separately from your Owner to View-only user permission slots.
- Approval workflow: Available with Pro plan and higher.
- Single sign-on and mandatory two-factor authentication for all users: Enterprise plan only.
- IP address restriction and password policy: Available with all plans.
Your current contract limits are also visible in the Contract information section under Owner Functions.
Setting up permissions
When spanning multiple companies or sites, the first thing you need to decide is "who holds the Owner role."
The Owner and Team Administrator can access all folders in the team regardless of access restrictions. When consolidating multiple companies into a single team, one company's representative can view SOPs from other companies. If you have SOPs you don't want to show to other companies, you need to separate your teams.
When operating with a single team, a two-tier structure is easiest to manage:
- Owner / Team Administrator: Consolidate into one department such as quality assurance or production engineering. This permission level is required for security settings, audit logs, and contract-related operations.
- Group Administrator: Assign one to each location or department. They handle adding users to their group, creating folders, and approvals.
Users who create SOPs should be "Created user" and those who only view should be "View-only user." Avoid giving higher permission levels to too many people. For a breakdown of what each permission level can do, see User permissions and permission slots.
When spanning multiple locations or companies, "Groups that can also edit" in folder access restrictions is frequently used. You can further narrow down which groups can actually edit among those with access. This lets you show SOPs from other locations as reference material while allowing only that location's team to edit them (Owner and Team Administrator can always edit).
Operations when teams are separated
When you separate teams by factory, department, or company, each team operates completely independently. Please note the following for daily operations:
What you can do
- Cross-team viewing: By inviting someone as a guest to another team, you can continuously view folders on a per-folder basis. Available with Core plan and higher. For details, see What is a guest invitation?
- Share a single SOP: When you issue an external sharing URL, one SOP can be viewed without logging in. See Sharing SOPs externally: usage guidelines for the differences.
- Multi-role users accessing both: The same account can belong to multiple teams and switch between them. This also applies when a head office administrator views each company's team. The steps are in Switch teams (when you belong to multiple teams).
What you cannot do
- You cannot collaboratively edit SOPs in different teams. Users invited as guests can only view.
- You cannot move SOPs or video materials to another team. If you later decide to separate or consolidate teams, existing SOPs cannot be transferred. Decide on your organizational unit before starting operations.
- You cannot view users or usage across multiple teams in one place. Inventory checks and usage report reviews must be done separately for each team.
Regular admin tasks
As the number of users grows, checking whether settings match current operations becomes more important than the settings themselves. We have organized common tasks performed by customers running active operations by frequency:
Monthly
- Add users for new hires and transferred employees, and reassign them to the correct group. For large numbers, you can also use bulk import via Excel.
- Disable users who have left or transferred. Disabling frees up permission slots for the next user. Usage history is retained and can be restored later.
- Check issued external sharing URLs and disable any that are no longer needed.
Quarterly
- Cross-check the user list against your HR data to confirm that no former employees remain.
- Export the audit log as CSV for internal record-keeping. Logins, user additions, deletions, permission changes, security setting changes, and external sharing URL issues and disables are all recorded. Only the Owner can export. For steps, see Export audit logs to CSV.
- Review whether folder access restrictions are keeping pace with organizational changes.
- Use the usage report to identify SOPs with unusually low view counts. Determine whether content is outdated or if target users haven't been notified.
Annually
- Review SOPs in order of last update date and confirm they align with current work floor operations.
- Check permission slot usage and estimate the number of users for the next fiscal year. You can increase limits by adding options.
- Re-review security settings. A summary of all settings is available at Security settings overview (Owner Functions).
Decide before rolling out
These items are difficult to change once users increase. Deciding on them before adding locations or companies reduces future work.
- Group hierarchy: First define using your current organizational structure, then add separate groups for any cross-functional projects.
- Folder structure: Organizing into three levels—"company-wide," "location/department common," and "this section only"—minimizes reassignment when people transfer. Mirroring your organizational chart directly means rebuilding every time the organization changes. Note: when you apply access restrictions to both parent and child folders, only members belonging to both groups can access. Apply restrictions only to the levels where needed.
- Naming conventions: Simple rules such as location codes or process names are fine. Renaming SOPs after you have hundreds is a heavy task.
- Pre-publication review: Approval workflow (Pro plan and higher) can be set per group. Once set, designated approvers must approve on publication or revision. If you want to share with stakeholders and collect comments before publishing, you can also use draft sharing.
- Trigger for transfers and departures: Waiting for field reports creates gaps. Have HR send a monthly list to administrators to ensure accuracy.
- Security settings: IP address restriction, password policy, and external sharing restrictions are available with all plans. Single sign-on (Microsoft Entra ID / SAML 2.0) and mandatory two-factor authentication are Enterprise only. Both require extra work to apply after users have increased, so we recommend deciding before rollout.
Frequently asked questions
Can I split admin visibility by company within one team?
No, you cannot. Owner and Team Administrator can access all folders in the team. If you want to close off management by company, you must separate into different teams and contracts.
Can I separate or consolidate teams later?
You can add teams, but you cannot move existing SOPs or video materials to another team. If migration is necessary, you will need to create them again.
Do subsidiary company representatives consume permission slots if invited?
If they only need to view, use guest invitations. Guest invitations allow up to 3 times the number of accounts and are counted separately from your Owner to View-only user permission slots. If they also need to create or edit SOPs, you must add them as regular users.
A field employee has no email address.
You can issue an "Email-free account" using a Login ID method.
Related resources
- Consolidating multiple companies or organizations into a single team: benefits and drawbacks
- Initial setup and notes for multi-department operations
- Setting up groups (Admin guide)
- Folder access restriction settings
- Understanding user limits and permission slots
- Approval workflow
- Export audit logs to CSV