Skip to main contentSkip to navigation
Help Center/Administration/Permission Management
Back to Administration

Permission Management

Configure user roles and permissions across your workspace. Understand role-based access control for enterprise teams.

5 min read
Updated 2/10/2026

DealView uses role-based access control (RBAC) to manage who can view, edit, and administer contracts and settings.

Role Overview

Built-in Roles

RoleDescriptionTypical Users
OwnerFull control, billing accessAccount creator
AdminManage users, settings, all contractsIT admins, legal leads
EditorCreate, edit, delete own contractsLegal team, contract managers
ViewerRead-only accessExecutives, auditors
Enterprise Feature

Custom roles are available on Professional and Enterprise plans.

Role Capabilities

CapabilityOwnerAdminEditorViewer
View contractsYesYesYesYes
Upload contractsYesYesYesNo
Edit contractsYesYesOwnNo
Delete contractsYesYesOwnNo
Manage foldersYesYesYesNo
Invite usersYesYesNoNo
Change settingsYesYesNoNo
Manage billingYesNoNoNo
Delete workspaceYesNoNoNo

Permission Hierarchy

DealView permissions follow a hierarchy:

Workspace → Folder → Contract

How Inheritance Works

  1. Workspace permissions set the default for all content
  2. Folder permissions can restrict access within the workspace
  3. Contract permissions can further restrict specific items
Restrictive Only

Permissions can only become more restrictive down the hierarchy. A folder can't grant more access than the workspace allows.

Example Scenario

Workspace: All users can view
└── HR Folder: Only HR team can view
    └── Salary Contract: Only HR Director can view

Managing User Permissions

Inviting Users

  1. Go to Settings > Team
  2. Click Invite Member
  3. Enter email address
  4. Select role
  5. Optionally restrict to specific folders
  6. Send invitation

Changing User Roles

  1. Go to Settings > Team
  2. Find the user
  3. Click the role dropdown
  4. Select new role
  5. Confirm change

Changes take effect immediately on next page load.

Removing Users

  1. Go to Settings > Team
  2. Find the user
  3. Click Remove
  4. Choose what happens to their content:
    • Transfer to another user
    • Keep in workspace (admin access)
    • Delete (not recommended)
Content Ownership

When removing users, always transfer their contracts to ensure continuity.

Folder Permissions

Setting Folder Access

  1. Navigate to the folder
  2. Click Folder Settings (gear icon)
  3. Select Permissions tab
  4. Choose access level:
    • Inherit - Use workspace defaults
    • Restricted - Only specified users/roles
    • Private - Only you and admins

Folder Permission Options

SettingDescription
Inherit from workspaceDefault workspace permissions apply
Specific usersOnly named users can access
Specific rolesOnly users with certain roles
PrivateHidden from all except owner and admins

Nested Folder Behavior

Child folders inherit parent permissions unless explicitly overridden.

Sales (All editors)
└── Confidential (Only Sales Manager)
    └── Pending Deals (Inherits: Only Sales Manager)

Contract-Level Permissions

When to Use

Use contract-level permissions for:

  • Highly sensitive agreements
  • Board-level contracts
  • HR/personnel matters
  • Confidential negotiations

Setting Contract Access

  1. Open the contract
  2. Click Settings (gear icon)
  3. Select Access tab
  4. Add or remove users/roles
  5. Save changes

Custom Roles (Enterprise)

Create roles tailored to your organization.

Creating Custom Roles

  1. Go to Settings > Roles
  2. Click Create Role
  3. Name the role (e.g., "External Counsel")
  4. Select permissions:
    • Contract access levels
    • Feature access
    • Administrative capabilities
  5. Save role

Custom Role Examples

Custom RolePermissions
External CounselView assigned contracts, add comments
Department HeadFull access to department folder only
AuditorView all, download reports, no edit
ContractorView specific contracts, limited time

Role Templates

Start from templates:

  • Reviewer - Read and comment only
  • Contributor - Upload and edit own
  • Manager - Full access to specific folders
  • Auditor - Read-only with export

Permission Best Practices

Principle of Least Privilege

Grant the minimum access needed:

  1. Start with Viewer role
  2. Upgrade to Editor when needed
  3. Reserve Admin for those who need it
  4. Limit Owner to account managers

Folder-Based Organization

Organize by access needs:

workspace/
├── All Company/        (Everyone)
├── Legal Team/         (Legal only)
├── HR Contracts/       (HR only)
└── Executive/          (Executives + Legal)

Regular Audits

Review permissions periodically:

  1. Check who has Admin access
  2. Review external user access
  3. Remove inactive users
  4. Verify folder permissions match needs

Common Permission Scenarios

Scenario: External Law Firm

Goal: Law firm reviews specific contracts

  1. Create "External Counsel" custom role
  2. Create folder for their contracts
  3. Set folder permissions to External Counsel role
  4. Invite law firm users with External Counsel role

Scenario: Department Isolation

Goal: HR can only see HR contracts

  1. Create "HR Contracts" folder
  2. Set folder to "Restricted"
  3. Add only HR team members
  4. Move all HR contracts to folder

Scenario: Read-Only Auditor

Goal: Auditor views all, edits nothing

  1. Invite auditor with Viewer role
  2. Grant workspace-wide view access
  3. Enable "Export Reports" permission
  4. Set time-limited access (Enterprise)

Troubleshooting

User can't see a contract?

  • Check folder permissions
  • Verify user role
  • Look for contract-level restrictions
  • Confirm user accepted invitation

User has too much access?

  • Review their role assignment
  • Check folder permissions
  • Look for inherited permissions
  • Consider custom role

Permission change not working?

  • User may need to refresh page
  • Clear browser cache
  • Re-login if using SSO
  • Contact support if persists

Audit Logs

Track permission changes:

  1. Go to Settings > Security > Audit Logs
  2. Filter by "Permission" events
  3. View who changed what, when

Available events:

  • User role changes
  • Folder permission changes
  • Contract access modifications
  • User invitations and removals

Related Articles

Was this article helpful?

Need more help? Contact support