In this guide
Democratic ownership does not mean every document belongs in a folder everyone can open. A co-op can make decisions transparent while restricting personnel information, member applications and commercially sensitive material to the people who need them. The aim is understandable access, supported by a clear place to find approved records.
Start by sorting information according to purpose and audience. Avoid designing the structure solely around the person who currently maintains it. A folder called “Sam's things” becomes hard to interpret when Sam leaves; “Approved member meeting records” explains both its purpose and likely audience.
Propose a small folder model
- Member information: approved updates, joining information, policies and records appropriate for members.
- Board or committee: working agendas, draft papers and restricted governance material, with a process for publishing approved versions.
- Operations: procedures, rotas and active project files for the people doing that work.
- Finance: records accessible to authorised finance roles and agreed advisers.
- People and confidential cases: separately restricted records with explicit owners.
- Public material: copies or approved documents intended for external access.
This is a proposed model, not a universal rule about member rights. Your constitution, policies and applicable obligations determine which records members should receive. Translate those decisions into permissions, and use an adviser where the underlying rights are unclear.
Prefer groups based on current responsibilities when the platform supports them. Adding a new finance worker to an agreed group is easier to review than finding dozens of individual file permissions. Still check inherited and individually granted access: a group name does not prove the whole structure is correct.
Choose an organisational home for shared work
Confirm who owns files and what happens when an account is deleted. Google describes files in shared drives as owned by the organisation. Other storage locations and products use different models. Ask your administrator to demonstrate the behaviour rather than assuming every shared folder has organisational ownership.
Create a simple convention for drafts and approved records. For example, a committee edits an agenda in its working area, then publishes an approved member-facing version in the member area. Mark the status and date clearly. Avoid several documents all described as “final” with no indication of which was approved.
Where possible, link to the agreed source rather than attaching new copies to every email. For a formal record that should not change silently, use a controlled publication process and retain the approved version. Write down who may correct it and how changes are recorded.
Share with visitors deliberately
Before giving an accountant or contractor access, identify the smallest useful set of files. Use a dedicated area, named recipients and an expiry or scheduled review where supported. Do not give them the entire finance workspace simply because it is quicker during setup.
Google's shared-drive permission guidance shows that drive-level restrictions and file-level permissions interact. Check your platform's actual behaviour. A setting change can alter access in ways that are difficult to infer from one file's sharing dialog.
Record why access exists and who will review it. If a recipient needs a downloaded copy, recognise that later removing the sharing link does not retrieve copies already obtained. Share only what is appropriate for that purpose.
Test with three roles and one change
- Create fictional sample documents in each area.
- Check what an ordinary member can open and search for.
- Check what an authorised committee or worker role can edit.
- Check what an external adviser can access through their invitation.
- Remove a test role and verify that its previous access has ended.
- Confirm that an approved public document is available without exposing its working folder.
Ask each tester to find one document using the instructions. Permission correctness and findability are separate questions. A secure folder that nobody can navigate will encourage people to create unofficial copies.
Review access when responsibilities change, following your onboarding and offboarding process. Treat copied records and backups within your member-data retention decisions, rather than accumulating them indefinitely.
Use the technology health check to identify which ownership and sharing decisions need attention first.