Skip to main content
Question

Groups and Access Issue

  • August 20, 2026
  • 1 reply
  • 12 views

We are small team and we only have two groups. One is comprised of two Admins, and the rest is comprised of the rest of our team. For some reason, the group containing the full team has access to one of our admin folders, but we are unable to remove that full group. I would love any ideas you might have to help us remove the full group from this admin folder. Thank you.

1 reply

  • Community Manager
  • August 21, 2026

Hi ​@DL-TLA,

 

Welcome to the Box Community, I'm happy to help!

 

The reason you are likely unable to remove the full team group from your admin folder is due to Box's waterfall permissions model.

In Box, permissions automatically waterfall down from parent folders to all subfolders. Collaborators and groups can only be modified or removed at the exact folder level where they were initially invited. If the full team group was invited to a higher-level parent folder, their access is automatically inherited by all subfolders underneath it, and the option to remove them from a child folder will be unavailable.

 

Here are the best ways to resolve this and restrict access to the Admin folder:

If the full team group still needs access to the current parent folder, the cleanest solution is to separate the admin content:

  1. Move the Admin folder out of its current parent folder and place it directly under All Files (root level) or inside a dedicated, restricted parent folder.
  2. Moving the folder immediately breaks permission inheritance from the old parent folder.
  3. Invite only your Admin group to this relocated Admin folder.

 

If the full team group was added to the top parent folder by mistake:

  1. Navigate up to the parent folder where the group was originally invited.
  2. Open the collaborator list in the right-hand sidebar.
  3. Locate the full team group, click the permissions dropdown next to their name, and select Remove.
  4. You can then invite the full team group only to the specific subfolders they need access to, leaving the Admin folder restricted to Admins.

 

As an Admin, you can also manage group folder access centrally:

  1. Go to Admin Console > Users & Groups > Groups.
  2. Select your full team group and go to the Shared Folders tab.
  3. Review which folders the group is collaborated on and remove or adjust access as needed.

Please let us know if you have any questions. Thanks for posting!