Skip to content

Permissions

Orbit uses Microsoft 365 as the workspace permission source.

That means Microsoft 365 access decides who can view or edit the files in a workspace. Orbit adds product UI for inviting people, note-specific shares, and tenant administration, but workspace access remains tied to Microsoft 365.

Workspace permissions control access to the workspace files.

Common role labels:

RoleTypical capability
readView accessible workspace notes and files.
writeCreate, edit, rename, move, import, and delete workspace content where Microsoft 365 allows it.
managerManage workspace-level settings when that role is shown for the workspace.
ownerOwn or administer the connected Microsoft 365 location when Microsoft 365 grants that authority.

The exact authority can depend on the SharePoint or OneDrive permission behind the workspace.

Invite user dialog showing workspace access managed through Microsoft 365

Note-specific shares grant access to one note.

Current note-specific shares are designed for people in your Microsoft 365 tenant. External guest access depends on your tenant policy and Orbit availability.

Use them when:

  • A reviewer needs one note.
  • A stakeholder should not browse the whole workspace.
  • You need an expiring organization link.
  • You are sharing into a Teams conversation.

Existing access links do not grant new permission. They only copy a route to the note.

Use this when everyone in the audience already has workspace access.

Organization links can grant access to people in your tenant. Choose view or edit carefully and set an expiration date when the need is temporary.

If a site owner, file owner, or admin changes permissions in Microsoft 365, Orbit follows those changes.

Examples:

  • A user removed from a SharePoint site may lose Orbit access.
  • A security group added to a folder may gain Orbit access.
  • A file-level permission removed in Microsoft 365 may break a note share.

If someone cannot open a note:

  1. Confirm the note link is correct.
  2. Confirm whether they need workspace access or note-specific access.
  3. Check the workspace Access settings.
  4. Open the Microsoft 365 location and verify permissions.
  5. Ask an owner or tenant admin to review blocked consent or policy issues.

For the broader storage and access model, see Data Handling and Permissions.

Why can someone still open a note after I revoke a note share?

Section titled “Why can someone still open a note after I revoke a note share?”

They may still have workspace access through Microsoft 365. Remove workspace access if they should not see any notes in the workspace.

No. Mentions can notify a person, but access still comes from workspace permissions or note-specific sharing.