In control of your data (Privacy and Security) - Admin should see all Company data

I have no support/technical question and have seen the support category. (Be aware that direct support questions will be deleted.)

on

Which general topic do you have

I have seen that there were several questions about the lack of an overview of Folder rights (Users, Groups) and being able to manage them.
In my opinion one of the most important features is the availability of data and to collaborate with it.
To be able to have a secure and privacy focused environment the Admin does need to see all the folders and groups and need to able to manage them. This is not the case right now. Users can create folders and files and the Admin isn’t aware of it.

Could you please focus on giving the Admin the necessary functionality to manage all the folders, files and rights so we can make a next step in a more secure environment.

No, the opposide is true! Look at a NC-Server used by a family. One family member is the admin, but this one does not need to have access to all folders and groups and need to able to manage them.

Let’s take the example of a daughter who has documents from a gynaecological examination. This is none of her brother’s or fathers business, if one of them is the administrator!

What the title of your post says is kind of the opposite of what you want to do, at least from the user’s point of view :wink:

What you could do when it comes to company data is to use Team Folders, where you can manage permissions centrally, and then set the storage quota for users to 0 bytes. Then they can no longer store anything in their personal accounts, but only in the team folders to which they have permissions.

2 Likes

I understand and agree what you’re saying. I only would expect that the daughter in this case has a separate User environment.

My point of view is from a company perspective. If the daughter would create a folder and invites other colleagues to collaborate then that folder should be visible by the admin.

Maybe it should be more explicit if you are create folders and files in your Personal environment or in your Company or Family environment. Can Teams Folders provide a solution for this to create folders in the Company environment.

When I create as a User a Team folder it isn’t visible for the Admin (or is this an Admin setting?)

And also that is good so. Take as example a team folder of the payroll accounting department. Should all administrators know what everyone else in the company earns?

1 Like

I don’t use it myself, but the description suggests that. Also, the first sentence of the ‘Readme’ document, which is linked on the ‘Apps’ page I linked, says:

Team folders can be configured through Team folders under Administration settings.

So yeah, I’d say it’s an Admin setting :wink:

I suggest you set up a test instance, read the docs, and then just play around with it. That should clarify a lot of things.

If any more questions or issues arise during testing, you might also want to search the forum and the internet for ‘Nextcloud Team Folders’ or ‘Groupfolders’ (the old name). Or, of course, you can always come back here with more specific questions. :slight_smile:

1 Like

Your answers got me thinking. Thank you!

1 Like

Thanks! I will look into this to see what is possible.

1 Like

@bb77 I looked into the Team Folders and together with managing the Sharing settings that gave me what I needed. Many thanks!

Now Users have their personal environment (folders) and the company environment (Team Folders).

2 Likes