Before you start
Who can use this feature
Available on all plans
In Figma, you work in files. Files can be organized into folders.
You can set permissions on each file and folder to control what people can do with it.
Note: Only owners and those with edit permissions on a file or folder can make changes to permissions on that file or folder.
Admins can also change permissions on resources they already have access to, even without edit access.
Overview
Every file and folder has a share modal, where you can see everyone who can access it and what they can do.
Open the share modal
- Open the file browser by logging in to your account at figma.com. If you’re in a specific Figma file, click the Figma menu > Back to files.
-
Open the folder.
- On the Starter or Professional plan, select All folders from the left sidebar. Then, select a folder.
- On the Organization or Enterprise plan, select All teams from the left sidebar. Select a team, then select a folder.
- On the Enterprise plan with workspaces enabled, select All workspaces from the left sidebar. Then, select a team from the Your teams tab. Select a folder in that team.
- Click Share.
- Open the file.
- Click Share.
What each permissions means
| Permission | On a folder | On a file |
|---|---|---|
| Can view | View the folder, but not create files or folders in it. They may still be able to edit individual files, depending on file permissions. | View and comment on the file, but not edit it. Can also copy and export assets, unless copying and exporting is restricted. |
| Can edit | Create files and folders in the folder. Edit access to files in a folder depend on individual file permissions. | Full file editing access. |
| Owner | The person who created the folder. They can create files and folders within it. | The person who created the file. They have full editing access. |
Note: To edit a file, someone needs both can edit permissions and a seat that includes the product the file was made with. Learn more about managing seats in Figma.
How access is organized
The share modal shows everyone who can access a file or folder, organized from broadest to most specific:
- Audience access: who can access this file or folder across your plan or workspace
- Inherited user roles: permissions passed down from individual user roles on the parent team or folder, if applicable
- Individual users roles: people or user groups who have been directly invited to this file or folder
Click on any row in the share modal to adjust permissions for that group. These three groups work differently from each other. See each section below for more details.
Audience access
Audience access controls whether your wider plan or workspace can reach a file or folder, and what they can do when they get there.
The options available depend on your plan:
-
Starter plan: always set to everyone in the plan
can edit - Professional and Organization plans: can set access for everyone on the plan
- Enterprise plan: can set access for everyone in their plan or a specific workspace
Every file and folder has its own audience access setting, and you can set the audience access independently on each resource. A file can be more restrictive than the folder it's in, or less.
Setting a folder’s audience access to can edit doesn't guarantee that someone can edit everything in it. To give someone access to a folder and everything inside it, invite them directly.
Example
The Fruit Folder is set to Anyone in Produce Co can edit. It contains two files.
- The Apple file is set to Anyone in Produce Co
can edit - The Banana file is set to Only invited people
Jules is a member of the Produce Co plan. Nobody has directly invited him to the folder or to either file.
- Jules can open Fruit Folder and create new folders and files within it, because audience access on the folder covers everyone in the plan.
- Jules can open Apple and edit it, because that file has its own audience access set to Anyone in Produce Co
can edit. - He can't see Banana, because that file is limited to invited people.
If Jules were invited to Fruit Folder directly instead, he'd have an individual user role, and he could open both files, as well as any other files in the folder.
Inherited user roles
Inherited permissions control whether individual user roles pass down from a parent team or folder.
When a file or folder inherits user roles, anyone who was directly invited to the parent gets the same level of access to everything inside it (through nested folders and down to their files).
A folder's inherited roles depend on where it sits in your folder structure:
- Top-level folders follow team permissions. Anyone on the team can access it based on their team roles and permissions (Organization and Enterprise plans). On the Starter and Professional plans there are no team roles, so people reach top-level folders through that folder’s audience access or a direct invite to the folder.
- Nested folders inherit roles from their parent folder — whoever has access to the parent via an individual user role also has access to it.
Example
Fruit Folder is in the Produce team.
-
John was invited to the Produce team with
can editpermissions. By default, he is givencan editpermissions on Fruit Folder. -
Jeanie was invited to the Produce team with
can viewpermissions. By default, she is givencan viewpermissions on Fruit Folder.
On Organization and Enterprise plans, you can change inherited permissions to limit any folder (top-level or nested) to specific people.
On Professional plans, you can't change inherited permissions—nested folders always inherit individual roles from their parent.
Starter plans only support one folder, so there are no inherited permissions.
To change inherited folder permissions on the Organization or Enterprise plans:
- Open the folder share modal.
- Under Who has access, click the row showing the parent access (e.g. "People from…"). For nested folders, this will be the name of the parent folder. For top-level folders, this will be the name of the team or plan.
- Click Change permissions.
-
Select an option:
- Anyone in [NAME] inherits access: Users on this folder inherit their permissions from the parent folder, team, or plan.
- Only people added to [Folder name] can access: Limits access to directly invited people only
- Click Save.
Note: This setting only controls whether individual user roles are inherited from the parent. It doesn't affect audience access on the resource itself. If this folder is set to Anyone in the [plan or workspace], members of the plan or workspace can still access it after you make this change. To update that, see Audience access.
Files always inherit user roles from the folder they're in, and you can't turn that off on an individual file. Anyone with an individual user role on the folder can open every file inside it.
You can give someone more access to a single file than their folder role gives them. You can't give them less.
Example
Jesse has can view permissions on
Fruit Folder through an individual user role,
so he can view both Apple and Banana
files.
-
Vanessa invites Jesse to Apple with
can editaccess. This works — Jesse can now edit Apple, and still only view Banana. -
Vanessa then tries to hide Banana from Jesse
by setting that file's audience access to
Only invited people. This doesn't work,
because his
can viewrole on the folder still passes down to it. To keep Banana away from Jesse, she would need to remove his role on Fruit Folder, or move Banana to a folder he can’t reach.
Individual user roles
An individual user role is access you give to a specific person or group on a resource by directly inviting them.
To invite someone, open the share modal for the file or folder, enter their email address, and choose can edit or can view. On Organization and Enterprise plans, you can also enter the name of a user group — everyone in the group gets the same permission, and access updates automatically when someone joins or leaves the group.
What you invite someone to determines how far their access reaches:
- Invite someone to a folder and their role passes down to everything inside it, including nested folders and their files.
- Invite someone to a file and they get access to just that file. Use this to share a single file without giving access to the rest of the folder.
You can give someone more access to a file than their folder role provides, but not less.
People with a role appear in the list in the share modal. This is the quickest way to tell how someone got access—if they aren't in the list, they're reaching the resource through audience access or an inherited role instead.
Troubleshooting
They most likely have audience access to the folder but no individual user role, and the files inside are limited to invited people. Audience access doesn't pass down to a folder's contents.
To check, open the folder's share modal and look for the person in the list of people. If they aren't listed, they're reaching the folder through audience access.
To fix it, choose whichever fits:
- Invite them to the folder directly. Their role will pass down to everything inside.
- On the Organization and Enterprise plans, add them to a user group and invite that group to the folder.
- Change the audience access on the files so your plan or workspace can reach them.
On the Starter and Professional plans, joining the plan doesn't grant access to content. New members need audience access or a direct invite to the folders and files they need. Learn more about inviting users to your Starter or Professional plan.
If you're adding someone to several folders, nest those folders inside one parent folder and invite the person to the parent instead of inviting them folder by folder.
Removing someone only removes their individual user role. They may still reach the resource through audience access, or through a role on a parent folder or team. Check the top row of the share modal, and check the parent folder's permissions. Learn more about removing or adjusting access.
can edit, but someone still can't edit the file
Editing takes both can edit permissions and a seat that
includes the product the file was made with. Someone with a Collab seat
can't edit a Figma Design file—they'd need to make a seat request.
Learn
more about managing seats in Figma.