Executive Meeting Documents - Restricted Access

Copper Contributor

Hi all 

 

We have a new SPO hub architecture and use Teams sites for our private work areas.  What I am wanting to do is the following 

  • Executive Meetings are held every month or so
  • Documents have to be submitted by various other senior leaders into one document library just for that particular meeting

 

Due to sensitivity of some of those documents, we want the ability for 

  • Exec PA's and Exec team to be able to view, download, edit and update the entire list of documents 
  • Author of the document to be able view, download, edit and update their document
  • All other contributors are able to see the list of document items but NOT be able to download any other documents apart from their own 

 

Surely I am just missing something simple here  

 

Thanks

Steve

 

 

2 Replies

Hi @stevec1,

 

This is not a simple scenario. Each contributing group will require a unique storage location and permissions to achieve what you describe within a single document library.

 

Each contributing group should be added to a new site security group with contribute permissions. The Exec PA's and Exec team should be added to the site members group.

 

The unique storage location can be a folder. The folder will have unique permissions that only allow the newly contributing group contribute access. All other groups will have read access.

 

You can add a "no-folder" view to the document library to see all of the documents.

 

I'm sure there are other ways of doing this. I hope this helps.

 

Norm

 

 

 

 

No, that is a complex scenario in regards to documents in a library. Not something you can just flip an option on and do. You are looking at Sensitivity labels and applying some sort of conditional access policies and training people to label their documents etc. in order to adhere to the policies.

Also you would have to come up with a way to structure the content around each meeting. I would probably do it with views and a metadata column labeling the meeting some way, so you can have groupings and default the metadata column for the Meeting name defaulted to the next meeting etc. Since trying to separating them between libraries will cause a bit of overhead.

Anyway, here are some of the label options. Sensitivity labels being the newest but limited in use since the Web app support isn't released yet(in preview). Good article by Joanne here she recently did covering the different types. https://joannecklein.com/2019/12/24/demystifying-labels-in-office-365/ but you can tie these labels and what not to different rule sets, but not sure how granular you can get as far as saying, you can only download your own, I don't think that's possible. You can be assigned certain rights to certain labels, but don't think you can be restricted to just your own documents for download.

Anyway, you are missing something simple since there isn't a simple answer unfortunately.


If you used lists instead, you can use list item permission to restrict items to only the person submitting and owners of the list, but it's not as user friendly when it comes to document library, but you can attach documents to list items etc. It's an option I've used in the past. Not ideal but it works.