Documents
Documents is XBuddy’s central repository for company files — proposals, policies, SOPs, templates, signed contracts, invoices, and every other file the business produces. Every file lives in a permission-controlled folder tree, is versioned, carries a sensitivity level, and can be linked to the business records that need it (a Deal, an Employee, a Contract, an Invoice).
Documents is also the storage layer underneath many other apps. When you upload a receipt to an Expense, attach an offer letter to an Employee, or save a signed contract from E-Signatures, the file is actually created here — placed automatically into an app folder that the owning module manages. You rarely need to think about this; it’s what makes “attach a file to any record” work consistently across the whole platform.
It is used by everyone who stores or shares files — but especially operations, HR, legal, and finance teams that manage sensitive, versioned, and expiring documents, and by every other app that needs to store an attachment.
Before you start
Prerequisites
| You need | Why |
|---|---|
| Folders | Sensitivity is inherited from the parent folder, so where a file lands decides who sees it |
| A sensitivity convention | Four levels exist; deciding what “confidential” means for your company is a policy call, not a setting |
| Storage quota headroom | Each company has a byte quota; an upload that would exceed it is refused at the moment of upload |
Permissions
| Permission | Unlocks |
|---|---|
documents:read | Browse and open documents |
documents:write | Upload, rename, move |
documents:delete / :restore | Move to trash and bring back |
documents:share | Create share links |
documents:publish | Publish a document and require acknowledgement |
documents:comment | Comment on a document |
documents:confidential | See documents marked confidential |
documents:restricted | See documents marked restricted |
documents:export | Export |
documents:bulk_ops | Bulk operations |
documents:detach | Detach a document from a record |
documents:view_audit | See the access trail |
documents:admin | Administration |
Five axes decide whether you see a file
This is the part that surprises people. Visibility is not one check but five, ANDed:
| Axis | What it filters on |
|---|---|
| Tenant | Schema isolation |
| Company | company_id — schema isolation is not company isolation |
| Data scope | Owner is the uploader; your tier is own, team or all |
| Sensitivity | public · internal · confidential · restricted — the last two need their own permission |
| App key | A file that landed in an app folder is gated by that app’s own write/admin permission |
The same file behaves differently on two screens, and that is deliberate. On a record’s detail page the attachment list filters company and sensitivity — because the page has already checked you can open the project or invoice it hangs off. In the Documents app the same file filters all five axes.
So a colleague with projects:read sees the file on the project page but cannot browse to Apps / Projects / <project name> in Documents, because the app folder requires projects:write. Nothing is broken. Check app_key before reporting a bug.
A share link bypasses all five. It carries a token, not your login, and it is the only way a file leaves the permission system. Treat creating one as publishing.
Key Features
- Hierarchical folder tree with drag-and-drop upload (PDF, DOCX, XLSX, images, ZIP, and more)
- App folders — files created by other modules (Finance, HR, CRM, Projects…) land automatically in a predictable, per-module location
- Version history — every upload keeps prior versions, restorable at any time
- Sensitivity levels (Public / Internal / Confidential / Restricted) that control who can even see a file exists, independent of folder permissions
- Share links — token-based external links with expiry, download limits, and revocation
- Entity attachments — attach the same file to CRM, HR, Projects, Finance, and any other record type, from that record’s own page
- Full-text and AI search across file names, content, and tags
- AI (RAG) indexing — documents become searchable and answerable by the XBuddy AI Copilot and Knowledge Base
- Storage quota tracking per company, with usage breakdown and alerts
- Granular sharing: internal users, roles, or external view-only links
- Folder-level permissions with inheritance and per-folder overrides
- Expiry monitoring — flag documents (contracts, certifications) nearing their expiry date
- My Files and Shared With Me personal views
- AI Hub for classification/insights and Workflows for automated routing
Screen map
| Screen | Route | What it is for | Permission |
|---|---|---|---|
| Library | /documents | The folder tree and file list | documents:read |
| Document detail | /documents/[id] | Versions, comments, sharing, linked records | documents:read |
| Overview | /documents/overview | Storage, activity, what needs attention | documents:read |
| To read | /documents/to-read | Published documents awaiting your acknowledgement | documents:read |
| Reports | /documents/reports | Index | documents:write |
| Activity | /documents/reports/activity | Who opened what | documents:view_audit |
| By folder / by user | /documents/reports/by-folder, /documents/reports/by-user | Where the volume is | documents:write |
| Expiry | /documents/reports/expiry | Documents with an expiry date approaching | documents:write |
| Storage | /documents/reports/storage | Quota consumption | documents:write |
| Settings | /documents/settings | Folder policy, retention, defaults | documents:admin |
| Agents / workflows | /documents/automation/agents, /documents/automation/workflows | AI agents and approval workflows | documents:write |
Important features
Full feature reference
| Nav item | Path | Description |
|---|---|---|
| Overview | /documents/overview | Landing page with document counts, recent activity, storage usage, and an expiry-watch panel highlighting files nearing their expiry window. |
| Browse | /documents/browse | The main folder-tree explorer — create folders, upload/drag files, tag, categorize, set sensitivity, link to entities, create share links, and manage folder access. |
| My Files | /documents/my-files | A personal view of documents you own or uploaded, for quick access without navigating the full tree. |
| Shared With Me | /documents/shared | Files and folders other users or roles have shared with you, with your granted access level shown. |
| Reports | /documents/reports | Reporting on storage usage, document counts by folder/category, expiry pipeline, and sharing activity. |
| AI Hub | /documents/ai | AI-assisted classification, duplicate detection, stale-file cleanup suggestions, indexing status, and document insights. |
| Workflows | /documents/workflows | Automated document routing — e.g. auto-tag on upload, route for approval, notify on expiry. |
| Settings | /documents/settings | Configure max file size, allowed types, version retention, default sensitivity, storage quota view, default upload folder, and expiry-alert thresholds. |
Integration points
| Module | How Documents connects |
|---|---|
| Contract Management | Contract versions and signed copies are stored and versioned here, in a dedicated app folder |
| E-Signatures | Send a document for signing; the signed PDF is auto-saved back into Documents |
| Approvals | A document can trigger an approval workflow; status syncs back |
| Knowledge Base | KB articles can attach or link supporting documents from the library |
| CRM / Sales | Proposals, NDAs, and presentations attach to Deals and Accounts |
| HR | Offer letters, employment contracts, and policies attach to Employee records |
| Projects | SOWs, deliverables, and meeting notes attach to Project records |
| Finance | Receipts and supporting docs attach to invoices, bills, and expenses |
| AI Copilot | Indexed document content is searchable and answerable through natural-language questions |
Any file can be linked to multiple entities at once. Open a document → Links tab → Add Link to attach it to, say, both a Deal and its Contact.
Related AI agents
| Agent | What it does here |
|---|---|
| Documents Librarian | Classifies uploads, detects near-duplicates, flags stale and expiring files, suggests tags and folder placement, and surfaces indexing status to keep the repository tidy and searchable. |