By default, every authenticated member of your workspace can see all sections and pages. Section-level permissions let Admins and Owners restrict specific sections so only certain roles or specific users can access them.
When you create a new section, it inherits open visibility β all workspace members (Owners, Admins, Editors, and Viewers) can browse its contents. You only need to configure permissions when you want to limit access.
Changes take effect immediately. Members who lose access no longer see the section in navigation, search results, or AI responses.
When you restrict a section by role, you choose which roles retain access. For example:
For finer control, restrict a section to individual users regardless of their role. This is useful for cross-functional projects or sensitive content that only certain people should see.
When you restrict to specific users:
Permissions cascade downward through the section hierarchy. When you restrict a parent section:
For example, if you restrict the "HR Policies" section to Admins only, every sub-section and page within "HR Policies" is also restricted to Admins. You can further narrow a sub-section (for instance, restricting "Compensation" to specific users), but you cannot open it back up to all roles while the parent remains restricted.
For more on organizing content into sections, see Sections.
Section permissions are enforced everywhere:
This means you can store sensitive information in restricted sections with confidence that it remains invisible to unauthorized members, even through AI-powered interactions. Learn more about how the AI agent handles permissions in the AI Knowledge Agent Overview.
Restrict sections containing compensation data, performance reviews, or policy drafts to the HR team (specific users) or Admins only.
Keep security runbooks, incident post-mortems, or infrastructure documentation restricted to your engineering team.
Create a section for board materials, strategic planning, or financial forecasts visible only to executives.
Restrict project sections to team members assigned to that client, preventing cross-contamination between accounts.
For workspace-wide settings and defaults, see Workspace Settings.