Loading

Who Can Read a Document

A document has no permission list of its own. Who can read it is worked out from the records it is attached to — and then checked against its classification.

Where to find it

Architect Panel → Security:

  • Document Access — what was read, and what was refused

On a document, the Sharing panel shows every route by which somebody reaches it.

The union rule

If you can read any record a document is attached to, you can read the document. Not all of them — any of them.

That is the right model for casework and it is the one thing to understand before attaching anything. A survey on a planning application and an enforcement case is readable by both teams, and that is a feature rather than a leak: it is why the file exists once instead of twice.

Classification is checked first, and separately

A document can carry a classification level, and a level can demand a clearance. That check runs before any route is considered, so no attachment and no grant reaches past it.

The ordering is the security property. Were it the other way round, attaching a classified document to an open case would be a way to launder it — and it would look like a feature.

Reading and downloading are different

A classification can permit reading and forbid export: the content may be looked at and must not leave. That distinction is enforced at the download, which is the one place it can be.

An inline preview is a download. The browser has the file either way, so a preview is offered only where a download would be.

A document with no links

Readable by the person who created it, by anybody granted it, and through the library. That is narrower than most people expect, and it is the safe direction — an adopted file store document or an unlinked upload does not quietly become public.

Every refusal says the same thing

“No such document” and “you may not see this document” are the same sentence, deliberately. Two different answers would let somebody find out which document IDs exist, and roughly how sensitive each one is, by trying them.

Worked example

A safeguarding report is attached to one restricted case and classified. A colleague on the general enquiry that led to it cannot read it — no route — and somebody with a route but no clearance cannot read it either. The Sharing panel on the document names both facts, so the manager can see which one to fix.

Recommendations

  • Think of attaching as granting, because it is.
  • Classify the document, not the record, when it is the content that is sensitive.
  • Check the Sharing panel before assuming somebody cannot see something.
  • Use export-forbidding levels sparingly — they stop share links and off-site OCR as well as downloads.