Skip to documentation
quickS3.com Open app
Browse documentation
Reference

Who can do what

A single table of what Owners, Admins, Members, share-link recipients, and AI clients can each do in an organisation and with your files.

Owner Admin Member AI user

In the organisation

OwnerAdminMember
Open filesEverythingWhat their custom roles allowWhat their custom roles allow
Invite people and cancel invitationsYesYesNo
Change Members’ and Admins’ roles, remove themYesYesNo
Make someone Owner, or remove an OwnerYesNoNo
Create, edit, and delete custom rolesYesYesNo
See the audit logYesYesNo
Test connectionsYesYesNo
Add, edit, and delete connectionsYesNoNo
Create bucketsYesNoNo
Rename the organisationYesNoNo
Connect and revoke their own AI clientsYesYesYes
See and revoke everyone’s AI clientsYesYesNo
Leave the organisation from PeopleYes, unless the last OwnerYesNo, ask an Owner or Admin

File actions

ActionNeeds
See a bucket on Overview, browse, preview, downloadRead
Create a share linkRead
Upload, overwrite, create folders, deleteWrite

Owners don’t need rules. For everyone else, at least one Allow rule must match and no Deny rule in any of their roles. The connection’s bucket scopes and the storage key can limit things further, for everyone.

Outside the organisation

Someone with a share link can download that one file until the link expires, without an account. The link stops working early if the person who created it loses Read on the file or leaves the organisation.

An AI client can do what the roles its user approved allow, until the access expires or is revoked. With Read it can list and create download and share links; with Write it can upload. It can never delete, create folders, or manage anything. Links it creates stop working when its access ends.