Practical guide

Review project access after the work changes

Last materially reviewed 2026-09-29

Quick answerReassess who still needs access after delivery, staffing changes or a new project phase; yesterday’s useful permission may no longer fit today’s task.
What to know

Review against current responsibilities

List the people and routes connected to the project and the task each still serves. Include former collaborators, client contacts and temporary delivery links. Do not remove access blindly from an active dependency, but do not assume it remains appropriate forever. Coordinate meaningful changes through the established project process so the review does not interrupt ongoing authorized work.

What to know

Check the actual permission

Inspect what the role allows, including modification or resharing where applicable. pCloud distinguishes View, Edit and Manage for folder invitations. A friendly role label should not substitute for understanding its effect on nested content. Keep permissions tied to a bounded project location rather than using a broad account-level workaround for a narrow collaboration need.

What to know

Record changes without secrets

Keep a concise private record of the review, remaining responsibility and any unresolved access question. Do not place passwords or recovery information in the project checklist. The record should explain the decision, not become another source of unauthorized access. General security guidance can inform the process but does not certify the resulting configuration.

What to know

A fictional phase change

A contractor helped prepare a release but no longer works on the project. The studio confirms there is no remaining editing task, reviews the supported access controls and updates the project record. The client’s valid delivery route is considered separately. This avoids both extremes: leaving every historical collaborator indefinitely connected or disrupting the client’s agreed retrieval window in a broad cleanup.

What to know

Put the decision into practice

Record why each continuing route still exists. A link with no current purpose is a review candidate, but removal should respect active obligations and authorized recovery needs. This creates a useful distinction between deliberate continuing access and forgotten historical access without encouraging indiscriminate cleanup of live projects.

Continue when useful

Next: Client permissions

Give each participant the smallest useful role for the task; receiving a file is not a reason to expose your entire working directory.

Open Client permissions →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. pCloud folder invitations — Merchant documentation · help.pcloud.com · Merchant-controlled · checked 2026-09-29
  2. NCSC: using SaaS securely — Research study · ncsc.gov.uk · Publisher independence not verified · checked 2026-09-29