Managing Participants and Permissions in a Stage

Stages is still an experimental feature being rolled out gradually. Check your Cloud Drive for the "Stages" option.

CipherDrive Stages uses participant-level permissions so that inviting someone does not automatically give that person unrestricted control of the canvas.

The owner chooses Ackaia identities and grants the capabilities each collaborator needs.

Stage access is identity-based

Each authorized participant uses a Stage-ready Ackaia identity.

The Stage key is wrapped individually for authorized identities. This allows CipherDrive to grant or remove Stage access without publishing the raw Stage key to the coordination layer.

Understand the published roles

The public Stages permission model describes three collaboration profiles: Guest, Editor, and Presenter.

Capability

Guest

Editor

Presenter

Draw, text and shapes

No

Allowed

Allowed

Insert Drive files

No

Allowed

Allowed

Move own objects

Allowed

Allowed

Allowed

Move any object

No

Allowed

Allowed

Control shared viewport

No

No

Allowed

Permissions can be more precise than the role name

Owners configure permissions individually. The published specification explicitly treats capabilities such as Move any and Delete any as elevated permissions.

When adding a participant, follow the principle of least privilege: grant only what that person needs for the collaboration.

Choose access based on the work

A practical way to assign permissions is:

These descriptions summarize the published capability matrix and should not replace a review of the actual permissions shown when access is granted.

Remove a participant

When a participant's access is removed:

  1. that identity immediately loses Stage access;

  2. CipherDrive rotates the Stage key;

  3. future Stage changes are protected under the rotated key;

  4. active key envelopes are secured for the remaining authorized members.

This is more than hiding the Stage from a user interface. Membership changes are part of the cryptographic access model.

Review access when the collaboration changes

Review participant access when: