Permission Inheritance
Omni respects the permissions from your source systems. You only see content you already have access to in the original application - if you can’t view a document in Google Drive, you won’t see it in Omni either.How It Works
Every document indexed by Omni carries a permissions record alongside its content. The record has three fields:public, a list of authorized user emails, and a list of authorized group identifiers. Group memberships are synced from each connector and stored against your user profile.
When you search, Omni:
- Finds matching content across all sources
- Filters results to documents where any of the following holds:
- The document is marked public
- Your email is in the document’s user list
- Your email domain matches a group in the document’s group list
- You belong to one of the document’s listed groups
- Returns only content you’re authorized to view
FAQ
Why can't I see a document I know exists?
Why can't I see a document I know exists?
Check your permissions in the source application (Google Drive, Confluence, etc.). Omni mirrors those permissions.
I just got access to a shared drive. When will it appear?
I just got access to a shared drive. When will it appear?
Can admins see my searches?
Can admins see my searches?
Search history is private. Admins can see aggregate usage metrics but not individual queries.