Inspect a Synology Folder Permission Rule Before Expanding Its Scope
When one person cannot open a Synology project folder, granting access to an entire share can create a much wider change than intended. File Station exposes information about individual permission rules that helps an administrator locate the relevant scope before editing it.
Identify the account and the exact path
Confirm the affected person's actual account and the folder they need. A display name in a chat message may not identify the login used by the computer. Reproduce the access result using the intended account, while keeping a known working account available for comparison.
In File Station, inspect the folder's Properties and Permission information. Synology documents an Inherit from field: a parent path identifies an inherited permission, while None indicates an explicitly specified rule. Also inspect whether the entry names the individual or a group. Membership can explain why two users have different results even when nobody added them directly to the folder.
Read where the rule applies
The Apply to setting distinguishes the current folder, child folders, child files and descendants. Read it together with the Allow or Deny type and the permissions selected. Record these fields before changing anything. Seeing a familiar account in the list does not by itself show that the rule grants the required action on the target document.
For an inherited rule, investigate the parent identified by the interface rather than repeatedly adding compensating entries at lower levels. An unknown principal also needs investigation; Synology notes that deleted users and disconnected directory services can leave unfamiliar entries. Do not replace an unknown entry with broad access simply to make the warning disappear.
If a change is authorised, keep its scope tied to the intended project and test both an allowed action and an action that should remain unavailable. Use harmless sample files for write testing. Preserve the original rule details so the adjustment can be reversed if another folder is affected. The outcome to document is the specific account, path and operation that now works.
Sources: Synology documentation 1.