Capabilities
The full list of the 44 capabilities, one action each, grouped by what they touch.
The full list of the 44 capabilities. One capability is one action, never a bundle: if a name would cover two things an administrator might want to separate, it is two capabilities.
A role is a named set of these, owned by a team. A folder share is the same set applied inside one folder, where it replaces the team role and may exceed it. An API token carries its own set, capped by what its creator can still do.
Capabilities marked Sensitive below are flagged Sensitive in the role editor.
The floor
Prop
Type
Every member of a team has view. It cannot be taken away.
By category
Categories exist so you can find a capability. There is no category-level switch, on purpose: granting ten things with one click is how people grant nine they did not mean to.
Not capabilities
Three grants sit outside the list, because they are not team-scoped actions.
Prop
Type
Two-factor is a policy, not a capability
A team or a role can require it. A member who has not enrolled resolves nothing there at all.
See also
Did this page help you?