Worthic uses two layers of document permission: user role and access scope. The role decides whether a user can change workspace data. The scope decides which reporting lines, accounts, folders, and documents are visible to that user.
This matters because the Document Library contains both workspace documents in Worthic HQ and personal documents in My files. Worthic HQ is shared workspace storage. My files is private to the individual user.
User roles
Workspace users generally fall into three practical permission groups:
- Owner / platform admin users have full workspace control. They can manage members and roles, manage workspace settings, and perform owner-level document actions such as renaming or deleting Worthic HQ documents where allowed.
- Editor users can change workspace data. In document workflows, this means they can upload documents for workspace review, confirm review actions, file documents into Worthic HQ, tag documents, move documents where permitted, and perform normal document-management work inside their access scope.
- Viewer users can view workspace data and documents they have access to, but cannot change workspace data. When a viewer uploads a document, Worthic treats it as a personal reference file: it is saved to My files and bypasses workspace analysis, routing, extraction, and transaction creation.
Access scope
A user may have access to all reporting lines in a workspace, or only selected reporting lines. That scope is used throughout the document system.
If a document is linked to a reporting line, it is visible only to users whose scope includes that reporting line. If a document is linked to a transaction, visibility follows the transaction’s reporting-line context. If a document is linked to an account, visibility depends on whether the user has access to the reporting lines connected to that account.
For accounts shared across in-scope and out-of-scope reporting lines, Worthic limits access. A user may see only transaction-linked documents that relate to their permitted reporting lines, rather than the full account document set.
Library visibility
The Library only shows documents and folders the current user is allowed to see.
In Worthic HQ, reporting-line folders are visible only when the user has access to that reporting line. Account folders are visible only when the user has access to the linked account context. If the user has limited account access, Worthic restricts visibility to transaction-linked material where the transaction falls within their permitted scope.
In My files, documents and folders are private to the user who owns them. Other workspace members do not see another user’s My files documents just because they share the same workspace.
Document actions
Permission also controls what actions are available. Editors and owners can work through the document review flow, confirm recommendations, file documents into the Library, tag documents, and send unresolved documents to the Inbox. Viewers can save personal documents and view documents within their scope, but cannot make workspace-level changes.
Copying a Worthic HQ document to My files creates a personal copy for the user. It does not make the original private, and it does not bypass the user’s workspace visibility rules.
Only the workspace owner can rename or move a Worthic HQ document. Renaming changes its display name only and does not alter the original file, Library path, or document links. Moving is only possible within the same account or reporting line folder structure, and to folders relating to the same document type. These restrictions are designed to preserve the integrity of document links and user scope restrictions.