Skip to main content
Category: Access and Security

Access Permissions

Also known as: Permissions, User Permissions, Access Rights
Simply put

Access permissions are the rules that determine what a particular user or group is allowed to do with a specific resource, such as a file, folder, or system object. They set out whether someone can, for example, view, edit, or manage a given item. Permissions are a core part of controlling who can reach and act on information within a system.

Formal definition

Access permissions define the type and scope of access granted to an identified user or group in relation to a specific object or object property, typically expressed as authorizations to perform particular operations (for example, read, write, or manage). In many implementations, permissions are grouped into permission levels that bundle a set of related authorizations, and they operate as part of a broader user management and access control process that governs which principals may access which resources. The exact model, granularity, and terminology depend on the platform and its configuration; the sources here describe permissions in the context of specific systems (such as Windows access control, SharePoint permission levels, and Android app permissions) rather than a single universal standard. This entry does not address how access permissions should be aligned with records retention, disposition, or recordkeeping-specific requirements, which fall outside the supplied evidence.

Why it matters

Access permissions are a foundational control for protecting the confidentiality and integrity of information held in a system. By determining what an identified user or group is allowed to do with a specific resource, permissions help ensure that only appropriate principals can view, edit, or manage particular items. Without well-defined permissions, systems typically cannot enforce a meaningful separation between those who may reach information and those who may not, which undermines the reliability of the wider access control process.

Permissions also underpin the broader user management process within which access is granted, reviewed, and revoked. As the evidence indicates, they operate as the authorization layer that connects an identified user or group to specific resources and to the operations, such as read or write, that may be performed on them. Where permissions are poorly scoped or inconsistently applied, users may accumulate access beyond what their role requires, which can weaken accountability for actions taken on a resource.

It is worth noting that the evidence here describes permissions in the context of specific platforms, such as Windows access control, SharePoint permission levels, and Android app permissions, rather than a single universal model. This entry does not address how access permissions should be aligned with records retention, disposition, or other recordkeeping-specific requirements, which fall outside the supplied evidence and would depend on organizational policy and, in many cases, jurisdictional obligations.

Who it's relevant to

Information governance officers
Access permissions are one of the controls that determine which users and groups can reach and act on information within a system. Those responsible for information governance may need to understand how permissions are structured across platforms, though the alignment of permissions with recordkeeping-specific requirements falls outside the scope of this entry.
System and platform administrators
Administrators typically configure and maintain permissions as part of the user management process, assigning the type and scope of access granted to users and groups. Because models differ across platforms such as Windows, SharePoint, and Android, administrators need to work within the specific terminology and granularity of the systems they manage.
Security and access control professionals
Permissions function as the authorization layer that connects identified principals to specific resources and the operations they may perform. Professionals responsible for access control use them to enforce which users or groups may access which resources, often through grouped permission levels rather than individual authorizations.
Application developers
Developers building applications, for example on mobile platforms such as Android, work with permission models that govern what an application may do and follow defined workflows for requesting and granting access. Understanding the relevant permission types is necessary for handling access appropriately within an app.

Inside Access Permissions

Access rights
The specific permissions granted to a user, role, or group that determine which records or record collections they may view, and the extent of that viewing capability. In recordkeeping contexts these are typically defined to support both operational use and the protection of records as evidence.
Action permissions
Permissions that govern what a user may do with a record beyond viewing, such as creating, editing, annotating, or classifying. In systems managing records, the ability to alter content is often tightly constrained to protect record integrity.
Disposition and destruction controls
Permissions that govern who may authorize or carry out disposition actions, which depending on organizational policy may include transfer, permanent preservation, or destruction. These are usually restricted to a limited set of authorized roles to preserve accountability.
Role- and group-based assignment
The common practice of assigning permissions to defined roles or groups rather than to individuals, so that access aligns with function and can be administered consistently. The precise model depends on the system and organizational policy.
Security classification alignment
The mapping of access permissions to security or sensitivity classifications applied to records, so that access to sensitive or restricted material is limited to appropriately cleared or authorized personnel. Requirements vary by jurisdiction and sector.
Audit and accountability logging
The recording of who accessed or acted upon a record and when, which supports the demonstration of record integrity and authenticity. Access permissions are often paired with logging so that the exercise of access itself leaves an evidential trail.

Common questions

Answers to the questions practitioners most commonly ask about Access Permissions.

Are access permissions the same thing as security classifications?
No, though the two are related and often applied together. Access permissions define who may perform which actions on a record, such as viewing, editing, or deleting it, whereas a security classification is a label indicating the sensitivity of the information and the level of protection it warrants. Permissions are the operational controls that enforce access decisions, while a classification helps inform what those permissions should be. A record may carry a classification without that alone determining every permission, since access typically also depends on role, business need, and organizational policy.
Does setting access permissions on a record satisfy an organization's retention and disposition obligations?
Not on its own. Access permissions govern who can interact with a record and how, but they are distinct from retention and disposition controls, which govern how long a record is kept and what happens to it at the end of its retention period. Restricting access does not retain, transfer, or destroy a record, and a record may remain subject to disposition rules regardless of how tightly its access is controlled. The two sets of controls typically operate together within a recordkeeping system but address different requirements.
How are access permissions usually assigned in a recordkeeping system?
Permissions are often assigned on the basis of roles or groups rather than to named individuals, an approach commonly described as role-based access control. This ties access to a person's function or responsibilities, which can make permissions easier to administer and review as staff change. Depending on the system and organizational policy, permissions may also be set at different levels, such as by classification, folder, or individual record, and may combine role, business need, and other attributes.
What actions can access permissions typically control for a record?
Permissions often distinguish between actions such as viewing, creating, editing, copying, moving, and deleting a record, as well as administrative functions like changing metadata or altering the permissions themselves. Separating these actions allows an organization to grant read access while restricting the ability to modify or destroy a record, which supports the integrity and authenticity properties expected of records. The exact granularity available depends on the system in use and how it has been configured.
How do access permissions relate to maintaining the integrity of a record?
By restricting who can edit, delete, or otherwise alter a record, permissions help protect its integrity, meaning its completeness and freedom from unauthorized change over time. Controls that limit modification while permitting appropriate viewing can help ensure that an authoritative record remains reliable evidence of the activity it documents. Permissions typically work alongside other measures such as audit logging and version control to support integrity, rather than serving as the sole safeguard.
How should access permissions be reviewed and kept current?
Access permissions are generally reviewed periodically to confirm that they still reflect current roles, responsibilities, and business needs, since access that was once appropriate can become excessive as duties change or staff move on. Many organizations align these reviews with joiner, mover, and leaver processes so that permissions are updated when someone's role changes or they depart. The frequency and rigor of review typically depend on the sensitivity of the records involved and on organizational policy and any applicable requirements.

Common misconceptions

Access permissions and retention rules are the same thing.
They address different concerns. Access permissions govern who may view or act upon a record, while retention rules govern how long a record is kept before disposition. A user may hold access permissions to records that remain subject to independent retention and disposition schedules, and vice versa.
Granting someone permission to view a record is the same as granting permission to change or delete it.
In recordkeeping systems these are typically distinct permission types. Viewing rights are commonly separated from editing, classification, and disposition rights precisely to protect the integrity and reliability of records as evidence. Permission to see a record does not imply permission to alter or destroy it.
Restricting access is sufficient to protect a record's authenticity and integrity.
Access permissions are one control among several. Protecting a record as trustworthy evidence typically also depends on capture, classification, audit logging, and integrity controls. Access restriction limits who can interact with a record but does not by itself establish that the record is authentic, reliable, or unaltered.

Best practices

Assign permissions to defined roles or groups aligned to organizational function rather than to individuals where practicable, so that access can be administered consistently and reviewed against need.
Separate viewing rights from editing, classification, and disposition rights, reserving the ability to alter or destroy records for a limited set of authorized roles to protect record integrity.
Align access permissions with any applicable security or sensitivity classifications, and confirm that requirements are interpreted in light of the relevant jurisdiction and sector, since obligations vary.
Pair access permissions with audit logging so that access and actions taken on records are recorded, supporting later demonstration of authenticity and accountability.
Review permissions periodically and when roles change, revoking access that is no longer required to keep entitlements consistent with current need.
Coordinate access controls with retention and disposition schedules rather than treating them as interchangeable, ensuring that neither undermines the other.