Discovery Portal permissions are set at the tag level. For each discovery user, you independently toggle View and Upload access per tag. Upload permission automatically includes View. You can change permissions at any time.
How discovery portal permissions work
Each discovery user has an independent set of permissions for every tag in the case. Permissions are controlled through a table with two checkboxes per tag: View and Upload. The table appears both during the invitation process and when editing an existing user's permissions.
A discovery user can only see tags where they have View access. Tags without View permission are completely hidden from their interface.
View permission
When View is checked for a tag, the discovery user can see that tag in their folder panel, browse the files within it, open files in the document viewer, and download files. This is the most common permission for production scenarios where you need the other party to review documents but not add new ones.
Upload permission
When Upload is checked for a tag, the discovery user can also upload files to that tag. Upload permission automatically includes View access. If you check Upload, the View checkbox is enabled automatically. Conversely, if you uncheck View, Upload is also disabled.
Upload permission is useful when you need external parties to submit documents -- expert reports, supplemental productions, or responses to document requests.
Editing discovery portal permissions for an existing user
To change permissions for a user who's already accepted their invitation, open the Share Portal panel and go to the Discovery Users tab. Click the edit icon next to the user you want to modify. A dialog opens with the same tag permissions table, pre-populated with their current settings. Toggle the checkboxes as needed and click Save. Changes take effect immediately.
Removing access
You can fully remove a discovery user by clicking the delete icon next to their name on the Discovery Users tab. This revokes all access to the case. Any files the user uploaded remain in the case; only their access is removed.