Who can view, comment on, decide on, or manage a proof is controlled at multiple levels. What a specific person can do with a specific proof depends on:
- Their reviewer permission on that proof (View, Comment, Approve, Manage)
- Their role's account-level permissions (User, Manager, Admin, Lite user), including any Enterprise custom permissions that override the role defaults
- Folder access - whether they're a member of the folder the proof is in, and whether that folder is public or private
- The proof's own security settings (authentication requirements, sharing scope, public link)
The following are always true, regardless of other settings:
- Proof owners have full Comment, Approve, and Manage rights by default (the owner can turn Comment and Approve off for themselves)
- Guests can only view, comment on, and decide on proofs they are invited to. No role or account permission extends a guest's access beyond that, because guests aren't licensed users
- Lite users (an Enterprise add-on) can log in and view, comment, and approve proofs like a User, but can not create or manage proofs or hold an account-wide "view all" permission regardless of other settings
- Administrators are never blocked by folder privacy or proof sharing settings
Permission layers
Reviewer permissions (set per proof)
The proof owner or someone with Manage permissions assigns each reviewer a permission level when adding them to a stage. This is the most specific layer - it applies to one reviewer, on one proof.
| Permission | What it allows |
|---|---|
| View |
Reviewers can see the proof only. No comments, replies, or approvals. View is the permission a reviewer gets when they are added to the proof but are not allowed to Comment, Approve, or Manage. |
| Comment | Add annotations and comments. Can delete their own comments if the proof isn't locked. |
| Approve | Submit or revoke a decision. Contributes to the stage or final decision. |
| Manage (licensed users only) | Upload new versions, lock/unlock the proof, delete versions or others' comments, add reviewers, change proof settings, and see all comments including private ones. |
| Share (guests only) | Forward the proof to other participants. |
| Proof owner | Assigned automatically to whoever creates the proof. Has every permission by default. |
For more detail, see Understand proof reviewer permissions.
Role-based account permissions
Every licensed user has a role (User, Manager, Admin, or Billing), and each role has a set of account-wide default permissions that apply across every proof and folder, not just ones the person was explicitly invited to.
Lite users (an Enterprise add-on) aren't a role - they're a separate, more limited user type. See the Lite user column below and Understand users, guests, and lite users.
| Default permission | User | Admin | Manager |
Lite user (Enterprise) |
|---|---|---|---|---|
| View, comment, and approve proofs they're invited to, or that are visible through folder access | ✔ | ✔ | ✔ | ✔ |
| Create, edit and manage their own proofs | ✔ | ✔ | ✔ | ✘ |
| View all proofs (account-wide) | ✘ | ✔ | ✔ | ✘ |
| Edit & manage all proofs (account-wide) | ✘ | ✔ | ✔ | ✘ |
| View, edit, and delete other users' private folders | ✘ | ✔ | ✔ | ✘ |
See Ziflow default roles and permissions for the full table across all roles.
Free and Standard editions don't have a User role. Only Manager, Billing, and Admin are available on those editions, so any licensed collaborator who isn't Billing or Admin defaults to Manager. This means licensed users in Free and Standard editions have account-wide View all proofs by default.
On Enterprise, administrators can override these defaults for the User and Manager roles in Settings > Permissions. That setting has an Account administration column with separate View All, Edit All, and Delete All toggles for each object type, including Proofs, Public folders, and Private folders - each toggle is independent:
- Proofs > View All controls whether the role can see every proof in the account, regardless of which folder it's in or who was invited
- Private folders > View All controls whether the role can browse into every private folder in the account
- Being added as a member of one specific folder (see Add users to a folder) is a third, separate mechanism that grants access to just that folder
Turning off Private folders > View All, or leaving someone off a specific private folder's member list, does not turn off Proofs > View All. If a role has that permission enabled, they'll still see every proof on their dashboard, including ones inside private folders they can't browse to directly.
Folder access
| Setting | What it controls |
|---|---|
| Public vs. private folder | Public: any licensed user can create proofs in it, but can't view its contents unless separately shared. Private: only the owner, administrators, and invited members can browse to it. |
| View only shared proof versions | Folder member sees only proof versions specifically shared with them. |
| View all proof versions (Pro, Enterprise) | Folder member sees every proof version in the folder and its subfolders, subject to each proof's own view settings. |
| View & manage all proof versions (Pro, Enterprise) | Full visibility and version control over everything in the folder. |
Folder access changes what a folder member can do once they're in that folder - it doesn't grant or remove any of the account-level or reviewer permissions described above. See About folders and Add users to a folder.
Proof security settings
Set by the proof creator (or account-wide by an administrator as a default), these control access at the proof itself, independent of role or folder.
| Setting | What it controls |
|---|---|
| Access | Whether users and guests must authenticate to open the proof. |
| Allow sharing proofs with (Enterprise) | Limits who the proof can be shared with: anyone, users in your account, or users in your account and trusted accounts. |
| Show proof public link | If disabled, removes the proof's public URL from the application and the Proof Viewer entirely. |
| Proof subscriptions | If enabled, lets anyone subscribe to the proof and comment or decide on it. |
See Configure proof security when creating a proof and Configure default proof settings.
Version and workflow visibility (within a proof)
These are a different kind of setting from everything above: they don't control whether someone can access a proof at all, only how much they can see once they're already a reviewer on it.
| Setting | What it controls |
|---|---|
| To view previous versions | If enabled, reviewers see every version of the proof, regardless of stage. Off by default - otherwise reviewers only see versions from the stage they're assigned to. |
| To view full workflow | If enabled, gives all users and guest reviewers full visibility into the entire workflow. By default, they only see the stages they're assigned to. |
| Allow mentioning | Controls who a reviewer can @mention: only reviewers on the proof, only reviewers on the same stage, only active users in the account, or all users and guests in the account. |
These are configured account-wide by an administrator (Settings > Proof Settings > General). On Enterprise, they can also be overridden per role through Settings > Permissions, the same way Proofs and Folders visibility can.
See Configure default proof settings.
Who controls proof permissions
| Role | Can do | Cannot do |
| Admin |
|
Cannot be excluded from any folder or proof Private folder settings and proof sharing restrictions don't apply to Admins |
| Manager |
By default:
(Enterprise can change with custom permissions) |
Cannot see proofs their custom permissions block, even if added to the relevant folder |
| Proof owners / reviewers with Manage |
|
Cannot override another person's account-level permission A Manager with Proofs > View All keeps that visibility regardless of what the proof creator sets on that proof |
| Licensed users (User role) |
View, comment, and approve proofs they're invited to, or that are visible through folder access they've been given (Enterprise can change with custom permissions) |
Cannot see proofs outside folders they have access to, or private folders they aren't a member of, unless granted broader visibility through Enterprise custom permissions |
|
Lite user (Enterprise) |
Log in, view the dashboard, view, comment, approve proofs they're invited to or that are visible through folder access | Cannot create or manage proofs, invite reviewers, or get account-wide "view all" access - always limited to what they're personally invited to or given folder access to |
| Guests | View, comment, and approve only proofs they are invited to |
Cannot access the dashboard, folders. Cannot access any proof they weren't invited to, regardless of anyone else's account or folder settings |
Where proof permission behavior is defined
Proof permission behavior is configured in multiple places:
- Proof stage setup - reviewer permissions (View, Comment, Approve, Manage) per stage
- Proof creation - Security section - access/authentication requirements, sharing scope, public link, subscriptions
- Folder sharing settings - folder privacy (public/private) and per-member folder view access
- Ziflow default roles and permissions - account-wide defaults by role
- Settings > Permissions (Enterprise) - administrator-configured View All / Edit All / Delete All overrides per object, per role
- Admin default proof settings - the organization-wide starting point applied when a proof is created
Why can someone see a proof I didn't expect them to?
If a proof is visible to someone you thought was restricted, check in this order:
- Do they hold the Manager or Admin role? Both include account-wide "edit & manage all proofs" by default
- On Enterprise, does their role have Settings > Permissions > Proofs > View All enabled? This is not limited by folder access
- Is Allow sharing proofs with set to Anyone, or does it include trusted accounts, extending reach outside your organization?
- Is Show proof public link enabled, exposing a link that bypasses folder and reviewer restrictions?
Why can't someone see a proof I expected them to?
- Are they added as a reviewer on the correct stage, or given folder view access to the folder the proof is in?
- Do they hold an account-wide "view all proofs" permission (the Manager or Admin role, or an Enterprise custom permission)?
- If neither of those applies, check the folder:
- Are they a member of the folder the proof is in?
- If they are, is their folder access set to View all proof versions? If it's set to View only shared proof versions instead, they'll only see proofs that were specifically shared with them - not everything else in the folder.
- Does the proof's Access setting require authentication they haven't completed?
- Are they a guest? Guests only see proofs they are invited to - no folder or role setting changes that
Related articles
Understand proof reviewer permissions
Ziflow default roles and permissions
Create custom permissions for user and manager roles
Configure proof security when creating a proof
Related to
Comments
0 comments
Please sign in to leave a comment.