Access control is the set of rules that decides who can see, create, change, approve, export, or administer information. In a collaborative platform, it protects both confidentiality and daily work quality.

A role is a named responsibility, such as owner, admin, contributor, reviewer, or viewer. A permission is a specific allowed action, such as upload, edit, delete, approve, invite users, or manage settings. Good systems combine both: roles make access understandable, while permissions define what those roles can actually do.

Least privilege means each person receives only the access needed to do their current work. It is simple in theory and easy to forget in practice. Teams often over-share because it is faster in the moment, then forget to remove access when the work changes.

A healthy access model includes onboarding, offboarding, temporary access, regular permission reviews, and special care for administrator accounts. Accounts with broad access should use strong authentication and should not be shared between people.

For teams using shared digital workspaces, this thinking matters when choosing personal spaces, named shared workspaces (such as Team or Family), or project areas, adding people to shared work, and deciding whether a file belongs in a private draft area or a controlled shared record.

Related: WorkStudio Account Types (WSO ↗), WorkStudio Context (WSO ↗), 2-Step Authentication in WorkStudio (WSO ↗).