Solutions
Products
Resources
Company
Partners
Request a demo

File cabinet permissions vs. dialogs: getting the difference right

File cabinet permissions vs. dialogs: getting the difference right 

In DocuWare, file cabinet permissions secure your documents while dialogs shape how users see and work with them. They're easy to confuse but it’s important to know their differences. Read the full article to understand why dialogs were never a security layer — and how to keep your configurations solid.

Content:

 

Two tools, two jobs — and why mixing them up can quietly undermine document security

DocuWare gives you two ways to control how people work with documents: file cabinet permissions and dialogs. They often work side by side, so it's easy to assume they do the same thing. They don't — and one of the most common configuration pitfalls is asking a dialog to do a job it was never built for.

In short: permissions secure documents. Dialogs shape how users see and work with them. A dialog is not a permission layer. That has always been true in DocuWare, and it's crucial getting right in every setup.

 

Permissions: the security layer 

File cabinet permissions decide what a user is actually allowed to access — which documents, which index fields, and which operations (search, view, edit, delete, export, and so on). They're enforced by the platform itself, at the data level, no matter how a user reaches the file cabinet.

This is the layer that secures your documents and index data. No permission, no access — whether the user comes in through a client, the API, or an integration.

Reference: File cabinet permissions

 

Dialogs: views for faster, focused work 

Dialogs are customizable views that let users search, display results, store, and interact with documents. They show relevant fields in the right order, can pre-filter by department, and simplify information to the essentials. They make everyday work quicker and cleaner.

But a dialog only filters what's shown. It doesn't change what a user is allowed to access. For example, if a search dialog hard-codes a field as filter, or a result list leaves out a field, matching documents and data are still permitted — they just don't appear in that view.

Reference: File cabinet dialogs

 

Why a dialog can't secure documents

A setup that relies on hidden or narrowed dialogs to keep certain documents out of reach is practicing security by obscurity — and obscurity isn't security.

Because a dialog only filters the presentation, the data underneath stays accessible to anyone who holds the permission. A document hidden from a dialog can still be reached:

  • through theDocuWare Platform / API,
  • by inspecting browser traffic, or
  • through any other client or integration on the same file cabinet.

If the permission allows it, the data is reachable. The dialog was simply not showing it. 

 

How to set it up right 

The best approach is to control access with file cabinet permissions — not with dialogs.

  • Spot the dialogs doing security work.Wherever a setup leans on a missing field or a hidden search dialog to keep documents out of view, treat it as a permission gap.
  • Apply restrictions at the permission layer.Use file cabinet permissions to define what each user or role may genuinely access. This ensures consistent control across all clients, APIs, and integrations.
  • Keep dialogs for what they're great at.Tailored views, simpler masks, department-specific result lists — that's where dialogs shine.  Just don't ask  them to lock anything down. 
  • Review proactively.A quick look at file cabinet permission profiles confirms that what's hidden is also genuinely restricted, and leaves your customers with a cleaner, sturdier setup.

 

The bottom line

  • Permissions secure documents. Dialogs shape how users work with them.
  • Dialogsfilter what's shown, not what's allowed.
  • Relying on hidden dialogs issecurity by obscurity— the data is still reachable via the API, browser traffic, or other clients.
  • So: keep file cabinet permissions properly set and replace any dialog-based "hiding" with proper controls at the permission level.



Comments