Granular Access Control: Per-Group, Per-Folder, Per-File Permissions
How to set folder-level and file-level permissions per user group in a Peony virtual data room: the four levels (No access, View, Download, Upload), how to revoke access, and why nothing applies until you click Save.
Last updated August 26, 2026
Granular access control is how one Peony data room serves several audiences at once — investors, buyers, and your own advisors reading the same virtual data room and each seeing a different subset of it. Every group gets its own security stack and its own permission table, and inside that table you set No access, View, Download, or Upload on any folder or any individual file. Nothing takes effect until you click Save.
Where to Set Permissions
Open the data room and click Permissions in the left sidebar. That one screen holds everything on this page.

The Permissions screen has two halves: a Groups column on the left, and the selected group's settings on the right under a Security tab and a Visitors tab.
Permissions Are Set Per Group
A group is a named audience — "Target Management", "Due Diligence Advisor", "Investor A". Each row in the Groups column carries its own Copy access link, a Resend invite to N shortcut, and an on/off toggle, so you can arm, share, or kill one audience without touching the others. Create new group at the bottom of the column adds another.

Select a group and the Security tab shows two stacked sections:
- Security control — "Enhance safety and customize advanced security controls for this group in the data room." Independent cards for Password protection, Expiry, Dynamic watermark, One-click NDA, Screenshot protection, Access questions, AI document Q&A, and Appearance, each showing its current state under the label (
Off,Never,On,Theme only). The exact set is dynamic — Email-gated access appears only on Link access groups. - Permissions — "Choose which folders and files this group can access, download, or upload into." The document tree with a permission slider on every row.
Because both sections live inside the group, two audiences can read the same room under completely different rules: buyers get an NDA gate and a watermark on a trimmed folder tree, your own advisors get the full tree with downloads on.
Create a new group whenever an audience needs different permissions — a different NDA, a different watermark, or a different set of visible folders. Groups also separate analytics and make revocation clean. See Permission & Security Settings for the full set of security controls.
The Four Permission Levels: No Access, View, Download, Upload
The Permissions table lists the room's folder tree under a Documents header, with four levels across the top: No access, View, Download, Upload. Every row has its own four-position slider, and the highlighted segment is the level that row currently grants.

- No access — the group does not see the folder or file at all. It is absent from their view of the room, not greyed out, so a file name alone can never leak.
- View — the group can open and read it in the browser, but cannot save a copy.
- Download — view plus save a local copy.
- Upload — view, download, and add new files into that folder. Upload applies to folders only; on a file row the Upload segment is struck through and cannot be selected.
The levels are inclusive, not four separate switches: Download also grants View, and Upload grants all three. There is no upload-only drop box — a group that can upload into a folder can also read it.
Per-Folder Permissions
Every folder in the tree — Commercial Due Diligence, Financial & Tax Due Diligence, HR Due Diligence, and so on — gets its own slider. Set the top-level room row to grant a baseline for the whole tree, then override individual folders below it. Children inherit the parent folder's level unless you set them explicitly.
The usual M&A pattern: View on the whole tree, Download on the teaser only, No access on customer lists and cap tables until an LOI is signed.
Per-File Permissions
Click the chevron next to a folder to expand it and the individual files appear as their own rows — Summary Financial Statements FY2023-FY2025.pdf, Tax Compliance Summary.pdf — each with its own slider. That is how you let a group download most of a folder while one sensitive file stays at View.
A file's own setting wins over the folder it sits in, so you do not have to restructure the room to protect a single document.
Revoking Access to a File, a Folder, or a Whole Group
There is no separate "revoke" button — revocation is the No access level.

- Revoke one file or folder from one group — drag that row's slider to No access. The item disappears from that group's view of the room; every other group is unaffected.
- Revoke a whole group — switch the group's toggle off in the Groups column. Its access link stops working, and anyone who opens it sees Failed to load link. Link not found. Other groups' links are untouched. Setting the room's top-level row to No access reaches the same end through the permission table.
- Revoke one person — open the group's Visitors tab and remove their email. See Permission & Security Settings.
Changes apply the next time the viewer opens or refreshes the room. Someone with the document already open on screen keeps seeing it until they reload.
You Must Click Save
Nothing you change on this screen takes effect until you click Save at the bottom right. Sliders, toggles, and security cards all update the form only — moving a slider does not write anything to the room.
This is the single most common "my permissions didn't work" ticket. The failure looks exactly like a bug: you set a folder to No access, navigate to another group or close the panel, come back, and the folder is visible again. It was never saved.
Three habits that avoid it:
- Save before you switch groups. Selecting a different group in the Groups column discards unsaved changes on the current one.
- Save before you leave the Permissions tab. Cancel sits next to Save and is easy to hit on the way out.
- Verify from the viewer side. Open the group's access link in an incognito window and confirm the tree matches what you intended.
Pricing
Granular per-folder and per-file permissions — and the Upload level — require the Data Room plan ($52/admin/month) or above.
- Free ($0, up to 3 admins) — link-level View / Download defaults only
- Business ($30/admin/month) — link-level View / Download defaults only
- Data Room ($52/admin/month) — full per-group, per-folder, per-file permissions plus Upload
- Deal Team ($64/admin/month, min 4 admins) and Enterprise — includes everything in Data Room
Viewers are free and unlimited on every plan; billing is per admin seat. A 7-day Data Room trial lets you test the permission table before you buy.
Common Mistakes
- Not clicking Save. See the section above — it is the top cause of permissions that appear not to apply.
- Reusing one group for every audience. You lose per-group analytics, and revoking one viewer hits everyone else in the group.
- Assuming a new folder is hidden. A folder you add inherits access from every existing group. Set it to No access per group manually if it should not be visible.
- Relying on security controls to hide files. Watermarks, NDAs, and screenshot protection do not limit which files a group sees. Only the Permissions table does that.
- Leaving Download on while expecting the watermark to hold. Pair Dynamic Watermarks with the file set to View.
Common Questions
How do I give two investors access to different folders in the same data room?
Put each investor in its own group on the Permissions tab, then set that group's folder tree independently. Both open the same room and each sees only the folders you granted them — you do not need a second data room, and neither investor can tell what the other was shown.
A viewer says the link shows "Failed to load link. Link not found." What happened?
That group's toggle is switched off in the Groups column, which disables its access link. Switch it back on to restore access, or leave it off if the revocation was intentional. It affects only that group.
I moved the slider and it reverted. Why?
The change was not saved. Click Save at the bottom right before switching groups or leaving the Permissions tab — Cancel discards everything.
Can one file be more restricted than the folder around it?
Yes. Expand the folder, and set that file's own slider. The file-level setting wins over the folder's.
Does No access hide the file, or show it locked?
It hides it. A folder or file at No access is not in that group's view of the room at all.
How fast does a revocation take effect?
On the viewer's next load of the room. A viewer with the page already open keeps seeing it until they refresh.
Why can't I set Upload on a file?
Upload is a folder-level permission — it means "add files into this folder", so it has no meaning on a single file. The segment is struck through on file rows.
Can a group upload files without being able to read what's already in the folder?
No. The levels are inclusive, so Upload also grants View and Download on that folder. If you need a collection point nobody can read back, use a separate folder that holds nothing else.
Do these permissions carry across data rooms?
No. Groups and their permission tables are scoped to a single data room, so an audience that needs access to two rooms is created in each.
On the Roadmap
- A per-room default so newly added folders start at No access for existing groups, rather than inheriting visibility. Until it ships, split content that needs hard separation into its own data room.
Next Steps
- Permission & Security Settings — access modes, groups, and the full security stack
- Access Control Layers — which controls to stack for each use case
- Dynamic Watermarks: Setup and Limits
- NDA Gates: Signed Before Access
- Admins vs Viewers
