Alter Folder Permissions
Audience:
Low-code EngineersSkill Prerequisites:
Roles and permissions
Grants folder permissions to roles and/or users. The action can either append the new permissions to the ones the folder already has, or replace all existing permissions with the ones you configure.
Each row in the Permissions grid grants one permission (Read, Write or Browse) to a role, a user, or both. Permissions set by this action are always allow permissions. The action can't create deny permissions.
Typical Use Cases
- Give a user a private folder after registration, readable and writable only by that user
- Give a department role access to a folder that was just created with Get or Create Folder
- Lock a folder down to a new set of roles when a project's status changes
Don't use it to
- Remove a single permission while keeping the others. The action can only add permissions or replace all of them.
- Deny access. Only allow permissions are created.
- Protect sensitive files that are stored in a standard (public) folder. Anyone who knows a file's direct URL can download files from a standard folder, whatever the folder permissions. Use a secure folder type for sensitive documents. See Files.
Related Actions
| Action Name | Description |
|---|---|
| Get or Create Folder | Creates the folder you want to secure, and returns its path and ID as tokens. |
| Move Folder | Moves a folder. Non-administrators need permissions on both folders. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Folder | The folder to change permissions for. Select it from the list, or switch to expression mode and enter a folder ID or a folder path relative to the portal root (for example Clients/Acme/). | Yes | none selected | Yes |
| Append New Permissions | When checked, the permissions in the grid are added to the folder's existing permissions. When unchecked, all existing permissions on the folder are removed first and only the permissions in the grid are applied. | No | Unchecked | No |
| Permissions | A grid of permissions to grant. Each row has three columns, described in the next table. | Yes | empty | Yes |
Permissions grid columns
| Column | Description |
|---|---|
| RoleId or RoleName | The role to grant the permission to. Pick a role or enter a role ID or role name. Supports tokens. Leave empty to grant the permission to a user only. |
| UserId or Username | The user to grant the permission to, as a user ID or username. Supports tokens, for example [User:UserId]. Leave empty to grant the permission to a role only. |
| Permission | The permission key: Read (READ), Write (WRITE) or Browse (BROWSE). In expression mode you can enter any folder permission key defined on the site. |
You can fill in both a role and a user on the same row, but it's clearer to use one row for each role and one row for each user.
Considerations
- Replacing permissions is thorough. With
Append New Permissionsunchecked, every existing permission on the folder is cleared, including the ones granted to built-in roles such asRegistered Users. Administrators still have access. - Rows that don't resolve to a role or user. If the role and the user on a row can't be found, the permission is saved against neither and has no useful effect. Check role names and usernames carefully, especially when they come from tokens.
- Validation. The action fails if a row has an empty permission key or a key that doesn't exist, or if the folder can't be found.
- Existing subfolders aren't affected. Only the specified folder is changed.
Examples
To understand how to use the below examples, please see Running Examples.
1. Create a private folder for the current user
The first action creates the folder Members/<Username>/. The second action replaces its permissions so that only the current user can browse, read and write it.
[
{
"Title": "Get or Create Folder",
"ActionType": "GetOrCreateFolder",
"Description": "Create the user's private folder",
"Condition": null,
"Parameters": {
"FolderPath": {
"Expression": "Members/[User:Username]",
"Value": "",
"IsExpression": true,
"Parameters": {}
},
"FolderMappingConnection": {
"Expression": "",
"Value": "",
"IsExpression": false,
"Parameters": {}
},
"OutputTokenName": "PrivateFolder"
}
},
{
"Title": "Alter Folder Permissions",
"ActionType": "AlterFolderPermissions",
"Description": "Only the current user can access the folder",
"Condition": null,
"Parameters": {
"FolderIdentifier": {
"Expression": "[PrivateFolder:FolderId]",
"Value": "",
"IsExpression": true,
"Parameters": {}
},
"AppendNewPermissions": false,
"Permissions": [
{
"Role": { "Expression": "", "Value": "", "IsExpression": false, "Parameters": {} },
"User": "[User:UserId]",
"Permission": { "Expression": "", "Value": "BROWSE", "IsExpression": false, "Parameters": {} }
},
{
"Role": { "Expression": "", "Value": "", "IsExpression": false, "Parameters": {} },
"User": "[User:UserId]",
"Permission": { "Expression": "", "Value": "READ", "IsExpression": false, "Parameters": {} }
},
{
"Role": { "Expression": "", "Value": "", "IsExpression": false, "Parameters": {} },
"User": "[User:UserId]",
"Permission": { "Expression": "", "Value": "WRITE", "IsExpression": false, "Parameters": {} }
}
]
}
}
]
2. Give an existing role read access without changing other permissions
This action appends a Read permission for the Sales role to the Shared/Price Lists/ folder. All existing permissions are kept.
{
"Title": "Alter Folder Permissions",
"ActionType": "AlterFolderPermissions",
"Description": "Let Sales read the price lists",
"Condition": null,
"Parameters": {
"FolderIdentifier": {
"Expression": "Shared/Price Lists/",
"Value": "",
"IsExpression": true,
"Parameters": {}
},
"AppendNewPermissions": true,
"Permissions": [
{
"Role": { "Expression": "Sales", "Value": "", "IsExpression": true, "Parameters": {} },
"User": "",
"Permission": { "Expression": "", "Value": "READ", "IsExpression": false, "Parameters": {} }
}
]
}
}
Revised 09/25/2026