Current Roles and Permissions
Current Roles and Permissions
This guide describes the access paths verified for Dossira’s current private preview. It does not imply that a named professional role, folder or room type creates a separate permission model.
Registered organisation members
A registered member has persistent organisation access. In supported flows, members can organise, upload, preview, download and share files.
The organisation should grant the technical role that exposes only the capabilities the person needs in its deployment. Public documentation does not map professional titles such as Chair, Director, Secretary, adviser or client to a fixed Dossira role.
Registered members can choose a passkey on supported devices. Email-password and magic-link sign-in are also available; passkeys are not mandatory or exclusive.
Confirmed-email external recipients
A confirmed-email recipient opens a deliberate share using PIN verification tied to the named email address. The recipient does not become a normal registered member and does not use a guest passkey.
Use this path when access should be associated with a named address. Select only the material intended for the share and set an expiry when access should be time-limited.
Explicitly created link shares
An anyone-with-link share uses the link itself as the access authority. It is broader than confirmed-email access and does not establish that every person using it is a named registered participant.
Use this path only when that broader model is appropriate. Revoke or reissue the share when its recipient group, purpose or scope changes.
Current permission boundaries
The current private preview does not provide:
- predefined Client, Board or Deal professional roles;
- granular agenda-section, folder or per-document permissions for registered members;
- guest uploads through the external-recipient flow;
- customer-facing comments, acknowledgements, approvals or decisions;
- a complete customer-facing membership-change or activity ledger; or
- a room sealing or close-and-export lifecycle.
For an external recipient who should receive only a subset, create a separate deliberate share containing that subset. This is a share boundary, not a granular permission applied to an agenda section or folder.
Changing or removing access
Remove registered member access when persistent participation ends. Expire, revoke or reissue external shares when their recipient, purpose or scope changes.
Revocation prevents future access through the revoked share. It cannot retrieve a file already downloaded or copied, and it does not prove that a former participant no longer possesses a copy.
Record access approvals, role changes and offboarding decisions in the system and procedure approved by the organisation. Dossira does not currently provide a complete customer-facing audit record for those events.