Product spotlight

Per-folder access control

Per-folder access lets one CogniSuite data room serve every audience on a deal. The counterparty sees the diligence tree, the internal room stays internal, and a clean team folder opens to one named organization and nobody else. The same folder-read check governs the AI, so an answer is only ever grounded in documents the person asking was already allowed to open.

By the CogniSuite team

What per-folder access does for you on a live deal

You run one room. The bidder sees the diligence tree and the documents that answer its request list. The internal room holds the working material and stays closed to the other side by default. A clean team folder opens to one named organization and stays shut to everyone else on that side. There is no second room, and no documents circulating by email because the room could not express the rule.

Two things make that hold. A folder a party cannot read does not appear in its tree listing at all, because the listing and the file gate resolve access the same way. And the AI is bound by the same rules: chat, search and drafting each apply the same folder-read check before a document is admitted as a source, so an answer is only ever grounded in documents the person asking was already permitted to open. Each deal is also a separate database on its own subdomain, so one room's questions cannot reach another room's material.

What the three visibility settings mean

Every folder carries a visibility label that decides which organizations can see it at all, before any question of downloading. Three cover most deals.

Shared material is labeled external, with an equivalent all-buyers label for a room with several bidders. Internal material is labeled internal, visible to the deal team and the client they represent and not to the other side. Restricted material is labeled specific and scoped to one named organization: readable only by the org it names, not by every party on that side. A specific folder under an internal parent keeps that narrow scope rather than inheriting the wider internal audience, which is what makes it usable for clean team material.

Labels are inherited and they fail closed. A folder without its own label takes the nearest label set above it, and if nothing resolves it is treated as internal. Trees generated during deal setup are written the same way, so anything unspecified lands as internal rather than as visible.

One sequencing point. The canonical M&A structure offered at deal setup ships restricted categories as internal rather than specific, because a specific folder needs a target organization and none exists when the room is created. Those folders start closed, and you re-point them at the named party once it exists. Starting closed is the safer failure mode, and the step is manual.

How access resolves when several settings could apply

Visibility answers who a folder is for. A separate access grade answers what those people can do with it: full, watermark, view or none, plus a flag for whether that party can upload into the folder.

Grades resolve in a fixed order. A grant for one user in one organization wins first. Then a grant for that whole organization on that folder. Then the same two questions at the parent folder, and up the tree from there. The room-wide default applies only if nothing else answers. A grade on a top-level folder therefore covers most of a room.

Two limits. Deal team roles resolve to full access without consulting folder grants, so the model scopes client and counterparty organizations rather than compartmenting your own team. And the defaults are permissive: a room where nobody has written a folder grant allows reading and clean download. The restrictions are yours to configure.

How the room decides who counts as the counterparty

A room stores which side the engagement is on. On a sell-side mandate the internal client is the seller and the buyers are the counterparty. On a buy-side mandate that flips, and it is the seller who is external.

Anyone neither on the deal team nor with the internal client is treated as the counterparty, and their default grade on an internal folder is none. If the deal type is missing or unrecognized, the room falls back to sell-side behavior rather than opening anything up. Side awareness also drives the tree listing, so a counterparty does not see the names of the folders it is excluded from.

This is a default, not an absolute block. An explicit grant still opens a named internal folder to a counterparty, which is useful when one schedule has to cross the line. It also means the internal room is only as closed as your grant list.

What view-only and watermarked access actually prevent

Files are stored as clean originals. A watermark is applied at the moment a file is served, carrying the viewer's name, their organization, a UTC timestamp and a confidentiality marking. A folder-level setting beats the organization-wide setting in both directions.

The view grade is the strong one, and it is enforced separately from read access. A folder set to view opens in the viewer and cannot be exported. The single-file download is blocked. So is the native-format stream the viewer uses to render spreadsheets and Word files. And the file is skipped inside a bulk zip rather than quietly included, which is the path that most often undoes a per-folder rule.

Watermarking covers PDF, Word, Excel, PowerPoint and common image formats. Where a folder is set to watermark and a file type cannot be marked, the request is refused rather than served clean, and the viewer is told the file cannot be marked and asked to contact the deal team. Inside a bulk download that file is left out rather than included clean. A watermark grade never resolves to an unmarked original.

The honest limit is what a watermark is. It is a visible deterrent personalized to the viewer, not forensic marking. There is no invisible per-recipient tagging, and the Word implementation can be stripped by a determined recipient. Where material must not leave the room at all, view is the setting to use, and where its text must not be reproducible by that party, none is.

Why an AI answer cannot widen access

Every AI feature that reads deal documents applies the same folder-read check before a document is admitted as a candidate, and it is the check the file gate uses rather than a separate rule written per feature. The top results are counted from readable documents only, so a restricted document never takes a slot. This is not a filter applied to the output. A document the person asking cannot open is never a candidate.

Counterparty-facing drafts go further. When the AI drafts a response that will be shown to the other side, a document is eligible only if every counterparty organization that can see the relevant request list may read it. That check runs at the organization baseline, so a per-user override cannot widen it, and it denies rather than falling back to the deal team's own access when the situation cannot be resolved.

Two limits. Retrieval admits any folder the user has some access to, including view and watermark, so an AI answer can quote text from a document that user may only view watermarked. And because the counterparty rule is an intersection, a widely shared request list can produce an empty grounding set and a thin draft.

What the audit trail records

The per-deal log covers several dozen distinct action types. Document activity is recorded as views, detail views, downloads, copies and deletions, with bulk zip downloads marked separately. Folder grants set, reset or bulk applied are recorded, as are organization and user permission changes, lifecycle events, request and Q&A transitions, and AI questions. Events carry the source IP address of the actor alongside the account. The trail filters by action, actor, organization and time range, and exports as CSV.

The honest limits. Reading and exporting the trail is restricted to the advising firm's deal team, so it is an oversight tool rather than a mutual record a counterparty can inspect. Entries are written without blocking the underlying action, so logging is best effort. The log is not cryptographically tamper-evident. There is no hash chain, so the trail shows what happened without proving that nothing in it was later edited. And an IP address attributes an event to a connection, not to a person.

How to check the settings before anyone is invited

The deal team can set a session to view the room as a specific counterparty organization. This is not a UI preview. The permission resolver runs against that organization, so the folder list and the access grades you see are the ones that party would get. It requires a deal team role, and the switch is stored on the server rather than asserted by the browser.

Run it once per bidder org after the grants are written. It is the fastest way to confirm an internal folder is closed and a clean team folder scoped before invitations go out.

For the platform's wider security posture, see /security. The data room capabilities are summarized on /features.

General information, not legal, tax or financial advice. For how CogniSuite handles security and access, see Security. To see it on a live deal, book a walkthrough.

← All articles