State of M&A Data Rooms — Q2 2026 Read the report →

Granular Access Control: Per-Group, Per-Folder, Per-File Permissions

How to set folder-level and file-level permissions per user group in a Peony virtual data room: the four levels (No access, View, Download, Upload), how to revoke access, and why nothing applies until you click Save.

Last updated September 27, 2026

Granular access control is how one Peony data room serves several audiences at once — investors, buyers, and your own advisors reading the same virtual data room and each seeing a different subset of it. Every group gets its own security stack and its own permission table, and inside that table you set No access, View, Download, or Upload on any folder or any individual file. Nothing takes effect until you click Save.

Where to Set Permissions

Open the data room and click Permissions in the left sidebar. That one screen holds everything on this page.

The Permissions screen has two halves: a Groups column on the left, and the selected group's settings on the right under a Security tab and a Visitors tab.

Permissions Are Set Per Group

A group is a named audience — "Target Management", "Due Diligence Advisor", "Investor A". Each row in the Groups column carries its own Copy access link, a Resend invite to N shortcut, and an on/off toggle, so you can arm, share, or kill one audience without touching the others. Create new group at the bottom of the column adds another.

Select a group and the Security tab shows two stacked sections:

  • Security control — "Enhance safety and customize advanced security controls for this group in the data room." Independent cards for Password protection, Expiry, Dynamic watermark, One-click NDA, Screenshot protection, Access questions, AI document Q&A, and Appearance, each showing its current state under the label (Off, Never, On, Theme only). The exact set is dynamic — Email-gated access appears only on Link access groups.
  • Permissions — "Choose which folders and files this group can access, download, or upload into." The document tree with a permission slider on every row.

Because both sections live inside the group, two audiences can read the same room under completely different rules: buyers get an NDA gate and a watermark on a trimmed folder tree, your own advisors get the full tree with downloads on.

Create a new group whenever an audience needs different permissions — a different NDA, a different watermark, or a different set of visible folders. Groups also separate analytics and make revocation clean. See Permission & Security Settings for the full set of security controls.

Hide New Content by Default

By default, a file or folder you upload inherits access from every existing group, so everyone who could see the room can see it the moment it lands. That's rarely what you want mid-deal: you add a sensitive document and then have to switch it off group by group.

To flip the default, open the data room's Settings tab (the room's own settings, not the workspace menu) and turn on Hide new content by default. From then on, new files and folders stay hidden from every sharing link until you grant access to them in Permissions, group by group.

It only changes what happens to content added after you turn it on. Files already in the room keep the access they have. Remember to open Permissions and grant the new file to the right groups, then click Save, or nobody outside your team will see it.

The Four Permission Levels: No Access, View, Download, Upload

The Permissions table lists the room's folder tree under a Documents header, with four levels across the top: No access, View, Download, Upload. Every row has its own four-position slider, and the highlighted segment is the level that row currently grants.

LevelVisibleOpen in browserSave a copyAdd files
No accessNoNoNoNo
ViewYesYesNoNo
DownloadYesYesYesNo
UploadYesYesYesYes (folders only)

A folder or file at No access is absent from the group's view of the room, not greyed out, so a file name alone can never leak. Upload applies to folders only; on a file row the Upload segment is struck through and cannot be selected.

The levels are inclusive, not four separate switches: Download also grants View, and Upload grants all three. There is no upload-only drop box — a group that can upload into a folder can also read it.

Printing

There is no separate print switch in the permissions table: printing follows the Download level. Set a folder or file to View or No access and it cannot be downloaded, and on most common formats (for example PDF) and modern devices printing is disabled along with it. Because the permission levels are hierarchical, this happens automatically, with nothing extra to turn on.

Printing is only blocked where the file or device honours that. There are too many combinations of devices, operating systems and file formats to promise it everywhere, so for anything sensitive keep Dynamic watermark, a One-click NDA, or both switched on in the group's Security control cards. A print or a photo of the screen then still carries the viewer's identity. See Dynamic Watermarks and NDA Gates.

Per-Folder Permissions

Every folder in the tree — Commercial Due Diligence, Financial & Tax Due Diligence, HR Due Diligence, and so on — gets its own slider. Set the top-level room row to grant a baseline for the whole tree, then override individual folders below it. Children inherit the parent folder's level unless you set them explicitly.

The usual M&A pattern: View on the whole tree, Download on the teaser only, No access on customer lists and cap tables until an LOI is signed.

Per-File Permissions

Click the chevron next to a folder to expand it and the individual files appear as their own rows — Summary Financial Statements FY2023-FY2025.pdf, Tax Compliance Summary.pdf — each with its own slider. That is how you let a group download most of a folder while one sensitive file stays at View.

A file's own setting wins over the folder it sits in, so you do not have to restructure the room to protect a single document.

Revoking Access to a File, a Folder, or a Whole Group

There is no separate "revoke" button — revocation is the No access level.

To revokeDo this
One file or folder from one groupDrag that row's slider to No access. The item disappears from that group's view of the room; every other group is unaffected.
A whole groupSwitch the group's toggle off in the Groups column. Its access link stops working, and anyone who opens it sees Failed to load link. Link not found. Other groups' links are untouched. Setting the room's top-level row to No access reaches the same end through the permission table.
One personOpen the group's Visitors tab and remove their email. See Permission & Security Settings.

Changes apply the next time the viewer opens or refreshes the room. Someone with the document already open on screen keeps seeing it until they reload.

You Must Click Save

Nothing applies until you click Save

Nothing you change on this screen takes effect until you click Save at the bottom right. Sliders, toggles, and security cards all update the form only — moving a slider does not write anything to the room.

This is the single most common "my permissions didn't work" ticket. The failure looks exactly like a bug: you set a folder to No access, navigate to another group or close the panel, come back, and the folder is visible again. It was never saved.

Three habits that avoid it:

  • Save before you switch groups. Selecting a different group in the Groups column discards unsaved changes on the current one.
  • Save before you leave the Permissions tab. Cancel sits next to Save and is easy to hit on the way out.
  • Verify from the viewer side. Open the group's access link in an incognito window and confirm the tree matches what you intended.

Pricing

Per-group, per-folder and per-file permissions, plus the Upload level: Data Room+. Free and Business — link-level View / Download defaults only. A 7-day Data Room trial lets you test the permission table before you buy. See Plans and Pricing.

Common Mistakes

  • Not clicking Save. See the section above — it is the top cause of permissions that appear not to apply.
  • Reusing one group for every audience. You lose per-group analytics, and revoking one viewer hits everyone else in the group.
  • Assuming a new folder is hidden. A folder you add inherits access from every existing group, unless Hide new content by default is on in the room's Settings. Either turn that on or set the folder to No access per group. See Hide New Content by Default.
  • Relying on security controls to hide files. Watermarks, NDAs, and screenshot protection do not limit which files a group sees. Only the Permissions table does that.
  • Leaving Download on while expecting the watermark to hold. Pair Dynamic Watermarks with the file set to View.

Common Questions

How do I give two investors access to different folders in the same data room?

Put each investor in its own group on the Permissions tab, then set that group's folder tree independently. Both open the same room and each sees only the folders you granted them — you do not need a second data room, and neither investor can tell what the other was shown.

That group's toggle is switched off in the Groups column, which disables its access link. Switch it back on to restore access, or leave it off if the revocation was intentional. It affects only that group.

I moved the slider and it reverted. Why?

The change was not saved. Click Save at the bottom right before switching groups or leaving the Permissions tab — Cancel discards everything.

Can one file be more restricted than the folder around it?

Yes. Expand the folder, and set that file's own slider. The file-level setting wins over the folder's.

Does No access hide the file, or show it locked?

It hides it. A folder or file at No access is not in that group's view of the room at all.

How fast does a revocation take effect?

On the viewer's next load of the room. A viewer with the page already open keeps seeing it until they refresh.

Can I stop visitors from printing a document?

Set the file or folder to View (or No access) in the group's Permissions table. Printing follows the Download level, so with download off, printing is disabled too on most common formats such as PDF and on modern devices. It cannot be guaranteed on every device and file format, so also keep a dynamic watermark, an NDA, or both switched on for sensitive material. There is no separate print setting.

Why can't I set Upload on a file?

Upload is a folder-level permission — it means "add files into this folder", so it has no meaning on a single file. The segment is struck through on file rows.

Can a group upload files without being able to read what's already in the folder?

No. The levels are inclusive, so Upload also grants View and Download on that folder. If you need a collection point nobody can read back, use a separate folder that holds nothing else.

Do these permissions carry across data rooms?

No. Groups and their permission tables are scoped to a single data room, so an audience that needs access to two rooms is created in each.

How do visitors download a file?

They open the file and click the download icon in the top-right corner of the viewer. If there's no download icon, their group is set to View for that file or folder — switch it to Download here.

On the Roadmap

  • A per-room default so newly added folders start at No access for existing groups, rather than inheriting visibility. Until it ships, split content that needs hard separation into its own data room.

Next Steps