Content visibility
Who can see what, and why roles are not the answer.
This is the page worth reading properly. Visibility in LensHub is decided by ownership, not by role.
Two kinds of content
Shared — no owner. Everyone in the organization can find it. Most content is this: a wiki, a shared repository, a ticket tracker.
Private — has an owner. Only that person can find it. Nobody else, at any role, including administrators.
Where ownership comes from
Content inherits it from the connector that produced it.
- A connector marked global produces shared content
- A connector owned by a person produces content only that person can see
So the decision is made once, when the connector is created, and applies to everything it brings in.
Widening access without changing roles
An access profile shares specific connectors with specific people. That is how you give someone access to one repository without making them an administrator, and without making the content shared with everyone.
Access profiles only ever add visibility. They cannot take it away.
What administrators can and cannot do
| Can | Cannot | |
|---|---|---|
| Org admin | Manage connectors, people, settings; see that private content exists | Read another person's private content |
Administrators can see counts — that someone has fifty private documents — which is what makes it possible to clean up after someone leaves without reading their material.
When someone leaves
Their private content does not disappear and does not become public. An administrator can see it exists and reassign or remove it deliberately.
Before connecting a source, decide whether it should be global. Everything it brings in follows that choice, and changing it later means re-syncing.