When using Dive across multiple companies, factories, or departments, this article covers the permission design that administrators (Owner / Team Admin) perform and the regular tasks needed to maintain operations.
To decide whether to consolidate or separate contracts (teams), see Benefits and drawbacks of consolidating multiple companies or organizations into one team (contract unit). For initial setup when consolidated into one team, see Initial setup and notes for multi-department operations.
Prerequisites: Relationship between Team, Group, and Folder
Multi-organization operations are determined by combining three levels of units:
- Team: The contract unit. It represents the entire company and exists only once within Dive. If the team differs, SOPs, users, permissions, plans, security settings, and usage reports are all independent.
- Group: A unit within a team representing departments, sections, or projects. You can create hierarchies (for example: Manufacturing Department → Production Section 2), and a single user can belong to multiple groups. The number of groups and subgroup levels you can create depend on your plan (see next section).
- Folder: Where SOPs are stored. You specify which groups have access to each folder. Members of the specified groups and their sub-groups can access it. You can also specify which groups can edit separately, allowing you to set up access where some groups can only view but not edit SOPs. (Owner and Team Admin can always edit.)
In other words, you use groups to define "who" and folders to define "what". Even across companies or locations, you design the scope of visibility using these two axes.
Limitations by Plan
Multi-company or multi-factory operations are affected by the number of groups you can create and their depth. Confirm these limits before starting your design.
- Groups: Free and Lite plans cannot create groups. Core plan allows up to 5 groups; Pro and Enterprise plans allow unlimited groups.
- Subgroups (Group hierarchy): Core and Pro plans allow up to 1 level (for example: Manufacturing Department → Production Section 2). Deeper hierarchies are available only in the Enterprise plan.
- Guest invitations: Available in Core plan and above. You can invite up to 3 times the number of accounts, counted separately from Owner through View-only user account counts.
- Approval workflow: Available in Pro plan and above.
- Single Sign-On and mandatory two-factor authentication for all: Enterprise plan only.
- IP address restriction and password policy: Available in all plans.
Your current limits can also be confirmed in Owner Functions under Contract information.
How to Assign Permissions
When operating across companies or locations, the first decision you need to make is "who will be the Owner?"
Owner and Team Admin can access all folders within the team regardless of access restriction settings. When consolidating multiple companies into one team, a person from one company can view all SOPs from other companies. If there are SOPs you don't want to show to other companies, you need to separate teams.
When operating with a single team, it is easier to manage with the following two-tier structure:
- Owner / Team Admin: Consolidate in one department such as quality assurance or manufacturing engineering. Operations related to security settings, audit logs, and contracts require this permission level.
- Group Administrator: Place at each location or department. They are responsible for adding users in their group, creating folders, and approvals.
Keep those who create SOPs as Created user and those who only view as View-only user, and try not to increase the number of people with higher-level permissions. For operations available by permission level, see User permissions and account count.
When operating across locations or companies, what is frequently used is the "Groups that can also edit" setting in folder access restrictions. Among the groups you've granted access, you can further narrow down which groups can actually edit. You can set up operations where you show SOPs from other locations as reference material but only allow the staff at that location to edit them. (Owner and Team Admin can always edit.)
Operations When Separating Teams
When you separate teams (contracts) by factory, department, or company, each team is completely independent. Please note the following points in operations:
What you can do
- Have mutual access: By inviting the other team as a guest, you can continuously access SOPs on a folder basis. Available in Core plan and above. For details, see What are guest invitations?
- Share only one SOP: When you Issue URL for external sharing, you can view a single SOP without logging in. See Sharing SOPs externally: Usage guidelines for the differences.
- Multi-role users can use both: Using the same account, you can belong to multiple teams and switch between them. This also applies when a headquarters administrator views each company's teams. For instructions, see Switch teams (when belonging to multiple teams).
What you cannot do
- You cannot collaboratively edit SOPs from different teams. Those invited as guests can only view.
- You cannot move SOPs or video materials to a different team. If you later separate or consolidate teams, already-created SOPs cannot be transferred, so decide on the unit before starting operations.
- You cannot review users and usage status from multiple teams in one place. Inventory and usage report checks must be done for each team.
Regular Tasks for Administrators
The more users you have, the more important it becomes to verify that "your settings match current conditions" rather than the settings themselves. We have organized tasks that customers actually perform, sorted by frequency.
Monthly
- Add users for new hires or transferred employees and change their group assignments. If there are many, you can also use bulk import from Excel.
- Disable users for those who have retired or transferred. When disabled, account slots become available for the next person. Usage history remains and can be restored later.
- Review issued external sharing URLs and disable any that are no longer needed.
Quarterly
- Cross-reference the user list with HR data to ensure no one still appears who is no longer employed.
- Export audit logs to CSV and keep them as internal operation records. Logins, user additions, deletions, permission changes, security setting changes, and external sharing URL issuance and disabling are all recorded. Only Owner can export. For instructions, see Export audit logs to CSV.
- Review whether folder access restrictions are keeping pace with organizational changes.
- In the Usage Report, check SOPs with extremely low view counts. Determine whether content is outdated or if the target audience has not been informed.
Annually
- Review SOPs in order from oldest last update and verify they match current on-site work.
- Check account usage and estimate the number of users needed for the next period. You can increase limits by adding Options.
- Review security settings again. A list of settings is available at Overview of security settings (Owner Functions).
Decisions to Make Before Rollout
These items are difficult to change once you have many users. Deciding these before adding locations or companies will reduce work later.
- Group hierarchy: First define based on your current organizational structure, then add separate groups for any cross-organizational projects.
- Folder structure: Thinking in three layers — "Company-wide", "Location or department shared", and "This section only" — keeps reassignment work to a minimum during transfers. Copying an organizational chart directly means you'll have to recreate it with every organizational change. Note: If you apply access restrictions to both parent and child folders, only members of both groups can access. Set restrictions only at the levels where necessary.
- Naming convention: A simple rule such as location code or process name is sufficient. Renaming hundreds of SOPs later becomes a large undertaking.
- Pre-release verification: Approval workflows (Pro plan and above) can be set up company-wide or by group. Once configured, approvals from designated approvers are required when issuing or revising SOPs. Approvers can be specified by conditions such as higher-level managers as seen from the initiator, managers of specific groups such as quality assurance or safety, or holders of specific qualifications. For pre-release review comments from stakeholders, you can also use Draft Sharing.
- Source of changes and terminations: Operations that wait for field reports result in missed updates. Having HR send a monthly list to administrators ensures accuracy.
- Security settings: IP address restriction, password policy, and external sharing prohibition settings are available in all plans. Single Sign-On (Microsoft Entra ID / SAML 2.0) and mandatory two-factor authentication for all are Enterprise plan only. Both require significant effort to implement after user growth, so we recommend deciding before rollout.
Frequently Asked Questions
Within one team, can I separate what administrators see by company?
No. Owner and Team Admin can access all folders within the team. If you want to close management by company, you need to have separate teams with separate contracts.
Can I separate (or consolidate) teams later?
You can add teams themselves, but you cannot move already-created SOPs or video materials to another team. If migration is necessary, you will need to recreate them.
If I invite staff from a group company, will it use my account count?
If you only need viewing, use guest invitations. Guest invitations allow you to invite up to 3 times your account count, counted separately from Owner through View-only user account counts. If you need the staff to create and edit SOPs, you must add them as regular users.
Our field staff do not have email addresses.
You can issue "Email-free account" using Login ID method.
Related Information
- Benefits and drawbacks of consolidating multiple companies or organizations into one team (contract unit)
- Initial setup and notes for multi-department operations
- Set up groups (for administrators)
- Folder access restriction settings
- Account limit and counting methods
- Approval workflow
- Export audit logs to CSV