All updates
Teams

Server drives are private by default

A newly connected SSH/SFTP drive now starts closed to the rest of your workspace, so access to a live filesystem is something you grant rather than something you remember to remove.

A server drive isn't a bucket. Its root is a real filesystem — a web root, a home directory, an application folder — and the cost of the wrong person having write access there is different in kind.

New server drives now start restricted. When you connect one, you and your organization's admins can use it immediately; everyone else sees nothing until they're granted access. Inviting a teammate no longer hands them every server in the workspace by default.

  • Grant per person or per group, for the whole drive or for a single folder.
  • A block always beats a grant, so you can open a drive broadly and still fence off one directory.
  • The lock badge is on the drive itself, in the bucket list — you can see that a drive is restricted without opening its permissions.

Folder-level rules are enforced everywhere on server drives, not just in the file list: browsing, downloading, renaming, deleting, creating folders and uploading all consult the same rules.

Cloud buckets are unchanged — they still default to open for the whole workspace, which suits shared object storage. Server drives you already connected are also unchanged, so nothing anyone relies on today stops working. If you'd like an existing drive closed, set it to Restricted on its Permissions tab.