Overview
Grant or deny resource-level File-Vault access for configured users, roles, teams, groups, or applications.
Prerequisites
Permissions required
Steps (4)
-
1
Choose the resource
Identify the governed file or folder that needs additional access control.
Tips
Validation
Success criteria
-
2
Choose the principal
Select the supported principal type and identifier represented in the File-Vault ACL.
Tips
Validation
Success criteria
-
3
Choose permission and effect
Set the resource permission code and explicit allow or deny effect.
Tips
Validation
Success criteria
-
4
Verify access behavior
Test the resource with the intended workspace permission and principal context.
Tips
Validation
Success criteria
About this guide
File-Vault provides a governed workspace for files and documents. Teams use a familiar File Explorer to browse folders, search, upload, preview, download, copy, move, rename, trash, restore, share, inspect versions, and manage metadata without exposing physical storage paths.
Governance controls include document categories and types, classification, retention, download and link policies, resource ACLs, folder templates, routing rules, legal holds, audit records, security-review records, webhook subscriptions, and usage reporting. Access is evaluated through workspace permissions and File-Vault resource policy before protected operations are performed.
Other applications can use File-Vault as their secure file layer through explicit capabilities for upload planning, secure upload, binding, unbinding, search, signed delivery, folders, versions, shares, audit, reports, webhooks, and ContextResolver. Handler, RCP, and Bridge v2 converge on the same operation and resource authorization model.