Access, Teams, and Sharing Overview
For a complete primer on how access works — permission levels, organisation-wide defaults, restricted Groups, and overrides — see Understanding Access, Teams, and Sharing. This page is a shorter operational overview.
Context and Why This Exists
StructureGram keeps organisation data separated by organisation, then uses groups to control who can see and work on specific client or project data.
This matters when your organisation has different working groups, external advisers, or client users who should only see selected groups.
What the Feature Does
Access is controlled in layers:
| Layer | What it controls | Where you manage it |
|---|---|---|
| Organisation role | Whether someone is an organisation admin, internal member, or external guest | Account > Team |
| Member default access | What an internal member can do in open groups by default | Account > Team |
| Group access | Whether a group is open to internal defaults or restricted | A group's Team button |
| Member overrides | Exceptions for individual internal members on one group | A group's Team button |
| Team overrides | Access for all members of a team on one group | A group's Team button |
| Guest sharing | Explicit access for an external guest on one group | A group's Share button |
This avoids setting every permission manually for every user on every group. You can set broad defaults where that is appropriate, then use group settings, teams, and overrides for more specific access.
Permission Levels
| Level | Typical use | Can view | Can create and edit | Can delete entities and relationships | Can delete the group | Can manage group access |
|---|---|---|---|---|---|---|
| Viewer | Read-only access | Yes | No | No | No | No |
| Editor | Working access | Yes | Yes | Yes | No | No |
| Group Admin | Trusted internal group administrator | Yes | Yes | Yes | Yes | Yes |
| Tenancy Admin | Organisation administrator | Yes | Yes | Yes | Yes | Yes |
Editor access includes deleting entities, relationships, documents, and diagrams — from entity pages, lists, or the diagram. Deleting a whole group, managing group access, and deleting from XPM need Group Admin or Tenancy Admin access.
Guests can only be shared as Viewer or Editor. They cannot manage access, join teams, or inherit access from open groups.
Member Baseline Roles
Internal members have a baseline role. Member - Edit and Member - View apply to open groups only; Member - Group Admin applies to every group, including restricted groups:
| Product role | What it means |
|---|---|
| Member - Group Admin | Group Admin access by default, in every group. |
| Member - Edit | Editor access by default, including deleting entities and relationships. |
| Member - View | Viewer access by default. |
| Member - No Baseline Access | No default group access. Access must be granted by team or member override. |
Member - No Baseline Access does not mean the person can never access anything. It means they do not receive automatic access from the organisation baseline.
How Access Is Decided
StructureGram uses the strongest access available to the person for the group.
For an internal member, access may come from:
- Their member default access.
- A direct member override on the group.
- A team override on the group.
For a guest, access only comes from an explicit group share.
Group Access On or Restricted
A group's Team dialog includes Member baseline access.
When Group access: On is enabled, internal members can access the group according to their organisation-level member default access.
When the group is Restricted, internal member defaults do not apply. Only tenancy admins, member overrides, team overrides, and explicit guest shares can access it.
Best Practice
Use broad defaults for people who work across most groups. Use restricted groups and overrides for sensitive groups.
Use teams when the same set of people needs the same access across multiple groups. Use member overrides only for exceptions.
For smaller firms, baseline access is usually easier to manage. For larger firms or department-based access, consider using Member - No Baseline Access with teams.