> ## Documentation Index
> Fetch the complete documentation index at: https://docs.northernlogic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Vault permissions

> Grant the right people and tools access to the right vaults.

Vault access applies to its whole file tree. A folder is not an independent
membership boundary.

| Capability                              | Viewer | Editor | Vault admin |
| --------------------------------------- | ------ | ------ | ----------- |
| Browse, read, search, and export        | Yes    | Yes    | Yes         |
| Download a local replica when allowed   | Yes    | Yes    | Yes         |
| Create, edit, move, delete, and restore | No     | Yes    | Yes         |
| Resolve content conflicts               | No     | Yes    | Yes         |
| Manage vault membership and share links | No     | No     | Yes         |

Local synchronization additionally requires the vault's local-sync policy and
the connection's grants. A connection can never exceed the current access of its
owner.

## Grant a vault role

1. Open **Knowledge** and select the vault.
2. Open the vault-root context menu and its access controls.
3. Select an active person or agent and assign Viewer, Editor, or Vault admin.
4. For company and team vaults, you can also assign a group.
5. Have the recipient reopen the workspace and check the vault.

You need Vault admin access to manage these grants. Removing one grant may not
remove access if the person still has a stronger role through another group or
organization administration.

## Workspace roles and vault roles

Workspace owners and admins implicitly administer company and team vaults.
Ordinary members need direct or group-derived grants. The highest effective
vault role wins.

Personal vaults are different: only their owner and explicitly granted people or
agents receive access. Workspace administration alone gives no personal-vault
access. Groups cannot receive personal-vault grants, and the owner's grant
cannot be removed or demoted. A delegated personal vault admin can manage other
non-owner grants.

## Local-sync policy

A vault admin can disable local sync. This prevents authorized replica access
going forward; it does not erase previously downloaded files. Remote MCP
read/write access is separate from local sync and must be managed through its
connection grants.

For read-only access to a particular subtree without a vault membership, review
[share links](/collaboration/sharing).
