EnglishCollaboration AppsDocumentsOverview

Documents

Documents is XBuddy’s central repository for company files — proposals, policies, SOPs, templates, signed contracts, invoices, and every other file the business produces. Every file lives in a permission-controlled folder tree, is versioned, carries a sensitivity level, and can be linked to the business records that need it (a Deal, an Employee, a Contract, an Invoice).

Documents is also the storage layer underneath many other apps. When you upload a receipt to an Expense, attach an offer letter to an Employee, or save a signed contract from E-Signatures, the file is actually created here — placed automatically into an app folder that the owning module manages. You rarely need to think about this; it’s what makes “attach a file to any record” work consistently across the whole platform.

It is used by everyone who stores or shares files — but especially operations, HR, legal, and finance teams that manage sensitive, versioned, and expiring documents, and by every other app that needs to store an attachment.

Before you start

Prerequisites

You needWhy
FoldersSensitivity is inherited from the parent folder, so where a file lands decides who sees it
A sensitivity conventionFour levels exist; deciding what “confidential” means for your company is a policy call, not a setting
Storage quota headroomEach company has a byte quota; an upload that would exceed it is refused at the moment of upload

Permissions

PermissionUnlocks
documents:readBrowse and open documents
documents:writeUpload, rename, move
documents:delete / :restoreMove to trash and bring back
documents:shareCreate share links
documents:publishPublish a document and require acknowledgement
documents:commentComment on a document
documents:confidentialSee documents marked confidential
documents:restrictedSee documents marked restricted
documents:exportExport
documents:bulk_opsBulk operations
documents:detachDetach a document from a record
documents:view_auditSee the access trail
documents:adminAdministration

Five axes decide whether you see a file

This is the part that surprises people. Visibility is not one check but five, ANDed:

AxisWhat it filters on
TenantSchema isolation
Companycompany_id — schema isolation is not company isolation
Data scopeOwner is the uploader; your tier is own, team or all
Sensitivitypublic · internal · confidential · restricted — the last two need their own permission
App keyA file that landed in an app folder is gated by that app’s own write/admin permission
⚠️

The same file behaves differently on two screens, and that is deliberate. On a record’s detail page the attachment list filters company and sensitivity — because the page has already checked you can open the project or invoice it hangs off. In the Documents app the same file filters all five axes.

So a colleague with projects:read sees the file on the project page but cannot browse to Apps / Projects / <project name> in Documents, because the app folder requires projects:write. Nothing is broken. Check app_key before reporting a bug.

⚠️

A share link bypasses all five. It carries a token, not your login, and it is the only way a file leaves the permission system. Treat creating one as publishing.

Key Features

  • Hierarchical folder tree with drag-and-drop upload (PDF, DOCX, XLSX, images, ZIP, and more)
  • App folders — files created by other modules (Finance, HR, CRM, Projects…) land automatically in a predictable, per-module location
  • Version history — every upload keeps prior versions, restorable at any time
  • Sensitivity levels (Public / Internal / Confidential / Restricted) that control who can even see a file exists, independent of folder permissions
  • Share links — token-based external links with expiry, download limits, and revocation
  • Entity attachments — attach the same file to CRM, HR, Projects, Finance, and any other record type, from that record’s own page
  • Full-text and AI search across file names, content, and tags
  • AI (RAG) indexing — documents become searchable and answerable by the XBuddy AI Copilot and Knowledge Base
  • Storage quota tracking per company, with usage breakdown and alerts
  • Granular sharing: internal users, roles, or external view-only links
  • Folder-level permissions with inheritance and per-folder overrides
  • Expiry monitoring — flag documents (contracts, certifications) nearing their expiry date
  • My Files and Shared With Me personal views
  • AI Hub for classification/insights and Workflows for automated routing

Screen map

ScreenRouteWhat it is forPermission
Library/documentsThe folder tree and file listdocuments:read
Document detail/documents/[id]Versions, comments, sharing, linked recordsdocuments:read
Overview/documents/overviewStorage, activity, what needs attentiondocuments:read
To read/documents/to-readPublished documents awaiting your acknowledgementdocuments:read
Reports/documents/reportsIndexdocuments:write
Activity/documents/reports/activityWho opened whatdocuments:view_audit
By folder / by user/documents/reports/by-folder, /documents/reports/by-userWhere the volume isdocuments:write
Expiry/documents/reports/expiryDocuments with an expiry date approachingdocuments:write
Storage/documents/reports/storageQuota consumptiondocuments:write
Settings/documents/settingsFolder policy, retention, defaultsdocuments:admin
Agents / workflows/documents/automation/agents, /documents/automation/workflowsAI agents and approval workflowsdocuments:write

Important features

Full feature reference

Nav itemPathDescription
Overview/documents/overviewLanding page with document counts, recent activity, storage usage, and an expiry-watch panel highlighting files nearing their expiry window.
Browse/documents/browseThe main folder-tree explorer — create folders, upload/drag files, tag, categorize, set sensitivity, link to entities, create share links, and manage folder access.
My Files/documents/my-filesA personal view of documents you own or uploaded, for quick access without navigating the full tree.
Shared With Me/documents/sharedFiles and folders other users or roles have shared with you, with your granted access level shown.
Reports/documents/reportsReporting on storage usage, document counts by folder/category, expiry pipeline, and sharing activity.
AI Hub/documents/aiAI-assisted classification, duplicate detection, stale-file cleanup suggestions, indexing status, and document insights.
Workflows/documents/workflowsAutomated document routing — e.g. auto-tag on upload, route for approval, notify on expiry.
Settings/documents/settingsConfigure max file size, allowed types, version retention, default sensitivity, storage quota view, default upload folder, and expiry-alert thresholds.

Integration points

ModuleHow Documents connects
Contract ManagementContract versions and signed copies are stored and versioned here, in a dedicated app folder
E-SignaturesSend a document for signing; the signed PDF is auto-saved back into Documents
ApprovalsA document can trigger an approval workflow; status syncs back
Knowledge BaseKB articles can attach or link supporting documents from the library
CRM / SalesProposals, NDAs, and presentations attach to Deals and Accounts
HROffer letters, employment contracts, and policies attach to Employee records
ProjectsSOWs, deliverables, and meeting notes attach to Project records
FinanceReceipts and supporting docs attach to invoices, bills, and expenses
AI CopilotIndexed document content is searchable and answerable through natural-language questions

Any file can be linked to multiple entities at once. Open a document → Links tab → Add Link to attach it to, say, both a Deal and its Contact.

AgentWhat it does here
Documents LibrarianClassifies uploads, detects near-duplicates, flags stale and expiring files, suggests tags and folder placement, and surfaces indexing status to keep the repository tidy and searchable.

In this guide