When do I set permissions at site level vs list or library level?
Common mistake: tweaking permissions per file or per folder. Works for a while, but over time nobody knows who has access to what. Rule of thumb: as high in the hierarchy as possible, and through groups as much as possible.
Try this first
- 1By default everything on a SharePoint site inherits site permissions: members can edit, visitors can read, owners manage. For most SMB cases that's enough.
- 2Only break inheritance when there's a real business reason. For example an HR library with personnel files inside a broader HR site. Then you break inheritance on that library and grant access only to HR members.
- 3Don't break inheritance at folder level, and definitely not at file level. That creates 'broken inheritance' you'll never find again later. Better a separate library, or even a separate site, than ten broken folders.
- 4Work with Microsoft 365 groups or Entra security groups, not individuals. Removing or adding a colleague then becomes one action in Entra, not visiting 12 sites.
- 5Audit site permissions quarterly via Site Settings > Site permissions or PowerShell (Get-SPOSiteGroup, Get-PnPGroupPermissions). A list of who has access where avoids unpleasant surprises.
- 6For exceptions: if one person temporarily needs more, use 'Share' on a file or folder with an expiration date. That's a share link with expiry, not a permission change.
When to bring us in
If you have sites with extensive broken inheritance and nobody knows who has access where, it's often cheaper to rebuild the site than to untangle. Four hours and you have order, instead of endless audit work.
See also
- Outlook crashes or freezes on large attachmentsUsually the mailbox cache is the culprit, not Outlook itself. Shrinking or relocating usually helps within ten minutes.
- Teams: they cannot hear me, or I hear nothingIn our experience Teams usually picked the wrong audio device after a Windows update or a new headset.
- OneDrive has stopped syncingThe cloud icon is grey or has a warning. Locally changed files are not showing up for colleagues.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.