Limits, troubleshooting & FAQ
Limits and constraints
| Constraint | Detail |
|---|---|
| Storage quota is per company | Reserved atomically at upload; an upload that would exceed it is refused, not truncated |
| Attachment uploads do not let you choose a folder | The server decides from the registry — this is what makes app-key visibility enforceable |
| Sensitivity inherits from the parent folder and only ratchets up | Moving a file never lowers its level |
| Deleting is a soft delete | The file goes to trash and is restorable; the underlying object is purged later by storage hygiene |
| Restoring re-reserves quota | A restore can fail if the company is now at its limit |
| A share link is outside the permission system | Revoke it to close the door; changing sensitivity also revokes access on the newer path |
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| A colleague sees the file on a record but not in Documents | The app folder requires that app’s write permission | Expected. Grant the app permission, or move the file out of the app folder |
| A file “disappeared” after someone moved it | Its sensitivity was raised by inheritance | Check the folder’s level; you need the matching permission |
| Upload refused | The company storage quota is full | Check /documents/reports/storage, delete or archive |
| Restore fails | Quota was consumed while the file sat in trash | Free space first |
| A share link still works after you changed permissions | Links carry a token, not a login | Revoke the link explicitly |
| Attachments vanished after a restore from backup | Files live in object storage, which is outside the database backup scope | Report it — this is an infrastructure gap, not a permissions one |
FAQ
Q: How many versions are kept? All versions are kept indefinitely by default. You can enable auto-purge of versions older than N days in /documents/settings → Version Retention.
Q: Can external users (clients, vendors) access files? Yes — use a share link for a view-only or comment-enabled link. It can be password-protected, capped by download count, and set to expire; external users don’t need an XBuddy account.
Q: What happens if two people edit the same document at once? The second save creates a new version; both are preserved. Use Version History to reconcile changes.
Q: Can I recover a deleted document? Deleted files go to Trash and are held before permanent deletion. Restore from there. Note that soft-deleted files still count against your storage quota until they’re purged from Trash.
Q: How do I hide a subfolder from a role that can see its parent? Open the subfolder → Manage Access → disable Inherit parent permissions → set explicit rules so the parent’s permissions no longer cascade.
Q: How does expiry monitoring know when a file expires? It reads the Expiry date you set in the document’s metadata. Files without an expiry date are simply excluded from the expiry panel.
Q: What’s the difference between folder permissions and sensitivity level?
Folder permissions decide who can browse into a folder. Sensitivity level is a second check on top of that — even someone with folder access can’t open a file whose sensitivity level exceeds their documents:confidential / documents:restricted grant. Both checks must pass.
Q: If I upload a file from inside, say, the Finance app, why can’t I choose the folder?
Files uploaded from inside another app (an Invoice, an Employee record, a Deal) are automatically filed into that module’s app folder, so every file of that type lands in a consistent, predictable place. If you need full manual control over placement, upload the file directly in /documents/browse and link it to the record afterward via Attach Existing.
Q: Does deleting a file from a record’s Attachments panel delete the file itself? No — Unlink only removes the connection between the file and that record. The underlying file stays in Documents and remains reachable from Browse or from any other record it’s linked to. To permanently remove the file, delete it from Documents directly.
Q: Why can’t I find a document in search even though I know it exists? Either it hasn’t finished indexing yet (check AI Hub for status), or its sensitivity level is above what your role grants — in which case search correctly hides it rather than showing an “access denied” result.