How do you all split folder permissions on a small team file server?
So we're a three person design studio, and our file server is a mini pc a client basically offloaded to us during an office upgrade. Two 4TB drives in it, running a NAS OS that reads windows ACLs (don't think the exact OS matters here, can name it in the comments if it does).
Permissions are three buckets I made by hand. There's a shared folder everyone can read, only I write to it, that's where final deliverables and common assets end up. Project folders where the other two get read/write. And one folder just for me, invoices, contracts, client quotes. It's been like this for almost a year I think, worst incident so far was one reboot where the drive bay didn't auto-mount and I had to go click it back in.
Last week a client asked in a meeting whether we can show who touched which file. We can't. No audit trail, I just had to say no in front of everyone and move on. That's been bugging me. On top of that we might take an intern who should only see one or two project folders, and I already can't remember which ACL line belongs to who. Adding a fourth person to this spreadsheet I keep in my head is going to break it.
As for what I've tried, I started reading up on Samba AD to put the box in a proper domain and bailed partway through the tutorial, it really does seem like overkill for three people. Groups would solve half of this but the OS we run doesn't do nested groups, so dead end there. Right now the fallback is telling everyone the rules out loud and me spot-checking folders now and then, which I don't love.
How do you all handle this at a similar size? Do you bother with full ACLs or do plain POSIX perms and groups hold up fine? Is a real LDAP/AD setup worth it for a handful of rules, or is there something lighter that does nested groups and an audit log? Also curious how you cut project folders, by client or by type, and what you do with temps. Grant access, then revoke everything and pray when they leave?
https://redd.it/1x36ojz
@r_SelfHosted
Post #54029
20