Skip to main content

External users access control playbook

A practical guide for architecture studio workflows in Beech.

All guides

24 September 2026

Updated 24 September 2026 · Beech Product Education Team

A complete setup guide for inviting clients, site teams, and vendors as external users with role templates, scope limits, folder restrictions, expiry controls, and audit checks.

Intent: Explain external user setup end-to-end so firms can collaborate safely without exposing unrelated project data.

Who this helps: Admins and managers configuring controlled access for clients, site teams, and vendor collaborators.

External users let you collaborate with clients, site staff, and vendors without exposing your entire internal workspace. Think of this feature as a controlled access gateway: you decide what a person can see, what they can change, and when their access should end.

What this feature does in plain language

Beech external collaboration is not a generic guest account. It combines permissions (what actions are allowed) and scope (which part of project data is visible). This means you can allow a contractor to upload field photos to assigned tasks without giving access to unrelated files, billing information, or private internal notes.

  • Read-only external users are free and do not consume paid seats.
  • Any write permission makes the user billable as a paid seat.
  • Access can be granted per project and can expire automatically on a chosen date.
  • You can use built-in templates or create reusable firm templates.

Where to manage external users

Open Firm settings and go to the External collaboration panel. This screen has two tabs: Collaborators (invite people and assign project access) and Access templates (define reusable permission bundles).

Step-by-step: invite an external user correctly

  1. 1
    Open External collaboration and click Invite external

    Enter their email and optional title, such as Site Engineer or Client Representative.

  2. 2
    Choose the first project

    This project becomes their initial access context when they accept the invite.

  3. 3
    Choose an access role template

    Start with Client Viewer, Site Reporter, or Vendor Collaborator unless you have a validated custom template.

  4. 4
    Set optional expiry

    Use expiry for temporary access. The invitation itself expires in seven days, and project access can also have its own end date.

  5. 5
    Send invitation and verify pending state

    Confirm the invite appears under Pending invitations. Resend or revoke from the same panel if needed.

Pick the correct built-in template

TemplateBest forDefault scopeBilling impact
Client ViewerClients tracking progress and approved outputsPublished-only style visibilityRead-only, free
Site ReporterField users posting updates and attachmentsAssigned workWrite access, paid seat
Vendor CollaboratorVendors handling scoped tasks and controlled filesSelected foldersWrite access, paid seat

Understand scope before granting access

Scope is your safety boundary. Even if a permission allows an action (for example download), scope still limits where that action applies.

  • Published only: visible information intentionally published for externals.
  • Assigned work: task-level visibility tied to items assigned to that user.
  • Deliverables only: published deliverables without broader project access.
  • Selected folders: access only to chosen Vault folders.
  • Entire project: widest scope; use carefully and only when truly required.

Who should configure this

Admins should define governance policy and template standards. Managers can run day-to-day collaborator onboarding using those templates. Contributors should request access changes but should not independently design external access policy.

High-confidence setup pattern for most firms

  1. Define 2-4 approved templates and document when each one is allowed.
  2. Prefer read-only template first, then escalate only if a workflow explicitly requires writing.
  3. Set access expiry on every temporary collaboration.
  4. For vendor uploads, prefer Selected folders over broad Vault visibility.
  5. Review active grants weekly during project coordination.

Common mistakes and how to avoid them

  • Mistake 1: Granting write permissions by default. Start read-only and only add write rights when workflow evidence requires it.

  • Mistake 2: Using Entire project scope for convenience. Prefer Assigned work or Selected folders to reduce accidental data exposure.

  • Mistake 3: Forgetting expiry for short-term users, which leaves stale access active after handover.

  • Mistake 4: Creating too many similar custom templates. Keep templates minimal and reusable to reduce policy drift.

Troubleshooting

  1. 1
    Invite not accepted

    Check Pending invitations, resend if needed, and confirm recipient is using the same email address.

  2. 2
    User can not see expected files

    Inspect assigned scope first (especially Selected folders) and then verify the required file permissions are enabled.

  3. 3
    User can do more than intended

    Review active grant permissions and scope; remove write capabilities or narrow scope and save immediately.

  4. 4
    Seat usage is higher than expected

    Audit permissions for external users and remove unnecessary write capabilities because any write right makes the user billable.

  5. 5
    Need evidence for compliance review

    Use Firm settings audit logs to review external share and access events, then export reports for governance records.

Treat external access as a security boundary, not a convenience toggle. Every write grant and broad scope should have a clear business reason and a review date.

Prerequisites

  • Confirm you can access the project and the page referenced in this workflow.
  • Collect any drawing references, due dates, and ownership details before you start.

Expected outcome

By the end of this workflow, your team has one visible, repeatable process and cleaner handovers.

Common mistakes and prevention

  • Mistake 1: Skipping context fields (owner, due date, status notes), which makes follow-up harder.

  • Mistake 2: Treating chat updates as source of truth instead of recording the update in Beech.

Troubleshooting checklist

  1. 1
    Troubleshooting step 1

    If a control is missing, verify your role has permission for the action.

  2. 2
    Troubleshooting step 2

    If results look wrong, check filters and refresh to confirm latest synced data.