Document Access Control and Secure Sharing in TouteGestion
How to restrict internal documents, grant user or role access and create controlled external share links without making private storage public.
Internal access and external sharing are different
TouteGestion separates access inside the organisation from controlled sharing outside it. Internal grants determine which users or roles can work with a restricted document. External share links provide a separate controlled path without changing the underlying private-storage model.
Restrict a document
A user with documents.access.manage can mark a document restricted. This establishes the document-level access boundary before explicit grants are added.
Grant access to a user or role
Access can be granted to an individual organisation member, resolved by email, or to a role. The available access levels are view, edit and manage. User grants are limited to profiles in the same organisation.
Remove access
Administrators with the access-management permission can remove an existing document grant. This allows access to be withdrawn without deleting the document or creating a replacement copy.
Signed internal downloads
Authenticated document downloads require documents.documents.read and use a short-lived signed URL. The current action creates a 300-second signed download URL for the requested stored file.
Practical example
A legal team can restrict a contract to a specific internal role, grant a named colleague edit access and issue a password-protected, expiring external link to a counterparty. These are separate controls, so external sharing does not require opening the document to the whole organisation.
Review this workflow in the product.
See how governed records, access and lifecycle controls fit your organisation.
