This is a guide for setting up groups in User management and folders in SOPs at the same hierarchy level to create an organizational chart view like this:
- You can see all folders in your own department and departments below it
- You cannot see SOPs in departments above you or in parallel departments (you can open folders above your department to navigate to your own department's folder)
Settings are configured by the Owner. Groups can be created in Core plan or higher. Sub-groups (group hierarchy) are limited to one level in Core and Pro plans, and there are no limits to the number of levels in the Enterprise plan.
How it works
Folder access restrictions have the following two rules:
- Users who belong to a group are also treated as belonging to the parent group above it. For example, a user in Division 1 can also open folders filtered by Manufacturing Department. However, a user who only belongs to Manufacturing Department cannot open folders filtered by Division 1.
- Filtering on a parent folder also applies to folders within it. If you cannot open the parent folder, you cannot open the folders inside it either.
For this reason, simply specifying the same-named group for each folder results in a situation where "folders in higher departments are visible, but folders in lower departments are not visible" like this:
| Manufacturing Department Folder | Division 1 Folder | Division 2 Folder | |
|---|---|---|---|
| Manufacturing Department users | Visible | Not visible | Not visible |
| Division 1 users | Visible | Visible | Not visible |
In this guide's procedure, Step 3 settings allow higher departments to see folders in lower departments, and Step 4 settings prevent lower departments from seeing SOPs in higher departments.
Steps 3 and 4 correspond to the top two in the diagram below. When both are enabled, the folders appear according to your organizational chart.
Configuration steps
Below, we explain using an organization where Division 1 and Division 2 are under Manufacturing Department.
1. Create groups according to your department hierarchy
- Open "Group management" from "User management" in the side menu and create a group for Manufacturing Department
- Select "Add subgroup" from Manufacturing Department's [...] menu and create groups for Division 1 and Division 2
- Assign each member to their own department's group. Assign Manufacturing Department users to Manufacturing Department, and Division 1 users to Division 1
For how to create groups, see Step 5 Set up groups (for administrators), and for how to change affiliations, see Edit user group affiliation.
2. Create folders at the same hierarchy and filter by same-named groups
- Create a Manufacturing Department folder and create Division 1 and Division 2 folders inside it
- In each folder's "Access Restriction Settings", select "Apply filter" and specify the same-named group. Specify Manufacturing Department group for Manufacturing Department folder, Division 1 group for Division 1 folder, and Division 2 group for Division 2 folder
For how to configure each folder, see Folder access restriction settings.
3. Allow higher departments to see folders in lower departments
- Log in with Owner permissions and open "Owner Functions" from the side menu
- Select the "Business rules" tab at the top and open "Folder view scope"
- Check "Allow viewing folders for groups below the affiliated group" and click "Continue" on the confirmation message
- In "Target roles", select the role for which to display folders below them
- Click "Save"
Select "Target roles" as follows:
- When you want only administrators of higher departments (such as department heads) to see lower folders: Select "Group Administrator or higher" and set their role to Group Administrator
- When you want all users in a higher department to see lower folders: Select "View-only user or higher"
Guests are not applicable. Initially, folders that become visible through this setting are view only. If you want to allow editing and revising, also check "Allow editing and revising, not just viewing". For details, see Allow viewing folders for groups below (Folder view scope).
4. Prevent lower departments from seeing SOPs in higher departments
Division 1 users can open the parent Manufacturing Department folder to access their own folder. Initially, SOPs placed in the Manufacturing Department folder are visible to Division 1 and Division 2 users. The following setting displays Manufacturing Department folder SOPs only to Manufacturing Department users.
- In the same "Folder view scope" as Step 3, check "Do not display SOPs in folders filtered by higher groups to users in lower groups", and click "Continue" on the confirmation message
- Click "Save"
When enabled, when Division 1 users open the Manufacturing Department folder, only the Division 1 folder is displayed. If you create folders without filtering in the Manufacturing Department folder, the SOPs in those folders are also displayed only to Manufacturing Department users. For folders you want to display to Division 1 and Division 2 users, filter by each division's group. For details, see Allow viewing folders for groups below (Folder view scope).
If you don't use this setting, place only folders from each division in the Manufacturing Department folder. SOPs placed directly in the Manufacturing Department folder are visible to Division 1 and Division 2 users.
Additionally, SOPs you want to display only to Manufacturing Department users should be placed in a dedicated folder as follows:
- In "Group management", create a group like "Manufacturing Department Internal" below Manufacturing Department, aligned with Division 1 and Division 2
- Create a folder like "Internal Only" in the Manufacturing Department folder and specify the "Manufacturing Department Internal" group in "Access Restriction Settings"
Manufacturing Department users who match the target role in Step 3 can also see this folder as a folder for lower groups. To display this folder to Manufacturing Department users who don't match the target role, also add them to the "Manufacturing Department Internal" group. Division 1 and Division 2 users cannot see this folder because they are not higher than "Manufacturing Department Internal".
Be careful not to filter this folder by Manufacturing Department group, as Division 1 and Division 2 users would then be able to see it.
How folders appear after setup
This is how folders appear when Step 4 settings are enabled.
| Manufacturing Department Folder SOPs | Division 1 Folder | Division 2 Folder | |
|---|---|---|---|
| Manufacturing Department users (target role) | Visible | Visible | Visible |
| Division 1 users | Not visible (Manufacturing Department folder opens, but only Division 1 folder is displayed inside) | Visible | Not visible |
| Division 2 users | Not visible (Manufacturing Department folder opens, but only Division 2 folder is displayed inside) | Not visible | Visible |
Owners and Team Administrators can see all folders regardless of these settings.
Verify the settings
Changes to "Folder view scope" take effect at each member's next login. To verify, log back in with accounts from Manufacturing Department, Division 1, and Division 2 and confirm that the folder list and search results match the table above.
Frequently asked questions
What should I do when organizational changes affect department parent-child relationships?
Change the parent-child relationships of groups in "Group management" and then move the folders to the same structure. Parent folder filtering also applies to folders within it. For example, if you move Division 1 under a different department but the folder remains under Manufacturing Department, Division 1 users and users in the new higher department will not be able to open Division 1 folder. See Edit folders (including moving and deleting).
What should I do when I want to show lower folders only to certain people?
Don't use "Folder view scope"; instead, add that person to lower groups as well (for example, assign a department head to Manufacturing Department, Division 1, and Division 2). This doesn't change the visibility for other users. However, when new departments are added, you also need to add the affiliation.
Can I apply the same visibility settings to guests?
The setting in Step 3 does not apply to guests (the setting in Step 4 does apply to guests). For folders visible to guests, specify them using "Allow guest user access" for each folder. For details, see Divide which folders each guest can see.
Where should I place SOPs that are common across the entire company?
Create a folder without filtering at the top hierarchy. Folders without filtering are visible to all team members except guests. When Step 4 settings are enabled, SOPs placed in the Manufacturing Department folder are displayed only to Manufacturing Department users. Additionally, SOPs in folders filtered only by groups that have no direct members (such as the entire company) are displayed only to Owners and Team Administrators.