This document outlines the permission design and regular administrative tasks that administrators (Owners / Team Admins) must perform when using Dive across multiple companies, factories, or departments.
For guidance on whether to consolidate contracts (teams) or separate them, see Pros and cons of consolidating multiple companies and organizations into one team (contract unit). For initial setup when consolidating into one team, see Initial setup and notes for multi-department operations.
Prerequisite: relationship between teams, groups, and folders
Multi-organization operations are determined by combining three organizational units.
- Team: The unit of your contract. Represents your entire company and only one exists within Dive. If teams differ, procedures, users, permissions, plans, security settings, and usage reports are all completely separate.
- Group: Represents departments, sections, or projects within a team. You can create a hierarchy (for example: Manufacturing Department → Manufacturing Section 2) and a single user can belong to multiple groups. The number of groups and nesting levels you can create depend on your plan (see below).
- Folder: The location where procedures are stored. For each folder, you specify which groups have access permission. Members of the designated group and its subordinate groups can access the folder. You can also specify a separate group that "Groups that can also edit" the folder, allowing you to show a procedure to some while restricting editing to others.
In other words, you use groups to determine "who" and folders to determine "what". When spanning companies or locations, you use these two dimensions to design who can see what.
Plan limitations
Multi-company and multi-factory operations are affected by the number of groups you can create and their nesting levels. Confirm these limits before you start designing.
- Groups: You cannot create groups on Free or Lite plans. Core plan allows up to 5 groups; Pro and Enterprise plans have unlimited groups.
- Subgroups (group hierarchy): Core and Pro plans allow one level (for example: Manufacturing Department → Manufacturing Section 2). Deeper hierarchies are only available on Enterprise plan.
- Guest invitations: Available on Core plan and above. You can invite up to three times the number of your "Account limit" and these invitations count separately from your regular user accounts.
- Approval workflow: Available on Pro plan and above.
- Single sign-on and mandatory two-factor authentication for all users: Enterprise plan only.
- IP address restriction and password policy: Available on all plans.
You can also check your current contract limits from the Profile icon in the top right → Subscription, estimates & orders → Subscription Information tab.
Permission placement
When spanning multiple companies or locations, the first thing you need to decide is "who holds the Owner role".
Owners and Team Admins can access all folders in a team regardless of access restrictions. When consolidating multiple companies into one team, a representative from one company will be able to view all procedures from other companies. If you have procedures you don't want to show to other companies, you must separate teams.
When operating with a single team, managing permissions is easier with the following two-level structure:
- Owner / Team Admin: Consolidate in one department such as quality assurance or production technology. This permission level is required for security settings, audit log access, and contract-related operations.
- Group administrator: Place one at each location or department. They handle adding users to their group, creating folders, and approvals.
Folder access restrictions follow the group hierarchy upward (to parent groups), so simply belonging to an upper group does not grant access to folders that are only exposed to subordinate groups. If you want to have someone review multiple locations, either add them individually to each subordinate group or enable "Folder view scope" in Owner Functions → Business rules (initially disabled). When enabled, users at the selected role (Group administrator and above, Created user and above, or View-only user and above) can also access folders for subordinate groups. For details, see Show procedures from subordinate groups (folder view scope).
Conversely, if you want to prevent people in a subordinate location from seeing procedures in a folder filtered by an upper group (such as headquarters), enable "Do not show procedures in folders filtered by upper groups to people in lower groups" in the same section. Subordinate users can navigate through upper folders to reach their location's folders, but any procedures placed there will not be displayed.
Designate people who create procedures as "Created user" and people who only view as "View-only user", and avoid giving too many people higher-level permissions. For operations available at each permission level, see User permissions and account numbers.
A common practice when spanning locations or companies is to specify "Groups that can also edit" in the folder access restrictions. This lets you further limit which groups among those granted access can actually edit. For example, you can show procedures from other locations as reference material while restricting editing to only that location's staff (Owners and Team Admins can always edit).
Operations when teams are separate
When you have separate teams (contracts) by factory, department, or company, each team is completely independent. Pay attention to the following when operating:
What you can do
- Allow mutual viewing: By inviting the other team as guests, you can continuously view folders from other teams. Available on Core plan and above. For details, see What is guest invitation.
- Share a single procedure: By issuing an external sharing URL, anyone can view a single procedure without logging in. External procedure sharing: usage guide explains the differences.
- Multi-team users: The same account can belong to multiple teams and switch between them. This also applies when a headquarters admin needs to view teams from each company. For steps, see Switch teams (when belonging to multiple teams).
What you cannot do
- You cannot collaboratively edit procedures from different teams. People invited as guests have view-only access.
- You cannot move procedures or video materials to a different team. If you need to separate or consolidate teams later, existing procedures cannot be transferred, so decide on the structure before you begin operations.
- You cannot see users and usage from multiple teams in one place. Inventory and usage report reviews must be done for each team separately.
Regular admin tasks
As the number of users grows, confirming "whether settings match current conditions" becomes more important than the settings themselves. We have organized the tasks that actual customers perform, grouped by frequency.
Monthly
- Add new and transferred users and reassign them to their new groups. If you have many users, you can also use bulk import via Excel.
- "Disable user" for people who have retired or transferred. Disabling creates an empty account slot for the next person. Usage history remains and can be restored later.
- Review issued external sharing URLs and disable any that are no longer needed.
Quarterly
- Cross-reference your "User list" with HR data to confirm there are no users still in the system who no longer work there.
- Export audit logs to CSV and keep them as internal operation records. Login, user addition/deletion/permission changes, security setting changes, external sharing URL issuance/disabling and other events are logged. Only Owners can export. For steps, see Export audit logs as CSV.
- Review whether folder access restrictions are keeping pace with organizational changes.
- In the usage report, identify procedures with extremely low view counts. Determine whether the content is outdated or whether the target users have not been properly informed.
Annually
- Review procedures in order of oldest last update and confirm they still match floor operations.
- Check your account usage and estimate the number of users for the next period. You can increase the limit by purchasing additional options.
- Re-confirm your security settings. A list of configuration items is summarized in Security settings overview (Owner Functions).
Decisions to make before deployment
These items are difficult to change after users start using the system. Deciding on them before adding locations or companies will minimize future work.
- Group hierarchy: First define your current organizational hierarchy, then add separate groups for any cross-organizational projects.
- Folder structure: If you think in three levels—"Company-wide", "Location/department shared", and "only this section"—you minimize reassignment work when people transfer. Copying your organizational chart directly creates rework every time your organization changes. Also, if you set access restrictions on both an upper and lower folder, only members belonging to both restricted groups can access the content. Apply restrictions only to the levels where they are needed.
- Naming conventions: Simple rules such as location codes or process names are sufficient. Renaming hundreds of procedures after they are created is a heavy task.
- Pre-publication review: Approval workflow (Pro plan and above) can be set up company-wide or by group. When configured, approvals from designated approvers are required when issuing or revising. Approvers can be specified by criteria such as their hierarchical position relative to the initiator, managers of specific groups such as quality or safety, or holders of specific qualifications. You can also use Draft Sharing if you want to show the procedure to relevant people and collect comments before publication.
- Transfer/resignation trigger: Operations that depend on notifications from the field will have gaps. Establishing a process where HR sends monthly lists to admins ensures reliability.
- Security settings: IP address restriction, password policy, and external sharing prohibition are available on all plans. Single sign-on (Microsoft Entra ID / SAML 2.0) and mandatory two-factor authentication for all users are Enterprise plan only. Since applying these after expanding user numbers is labor-intensive, we recommend deciding on them before deployment.
Frequently asked questions
Can I split the view range for administrators by company within one team?
No. Owners and Team Admins can access all folders in a team. If you want management to be closed off by company, you must maintain separate teams for each company.
Can I later separate or consolidate teams?
You can add additional teams, but you cannot move existing procedures or video materials to a different team. If migration is necessary, you must create them again.
When inviting a group company representative, does it use an account slot?
If they only need to view, use guest invitations. Guest invitations let you invite up to three times your "Account limit" and count separately from your regular user "Number of accounts". If they also need to create or edit procedures, you must add them as a regular user.
People at our locations don't have email addresses.
You can issue an "Email-free account" that uses a Login ID instead.