> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omni.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Update organization-level folder permissions

> Set the role every member of the organization holds on a folder, and/or turn [AccessBoost](/share#boosting-permissions-with-accessboost) on or off for that organization-wide access, without naming individual users or groups. The role cascades to every descendant folder and document, so a single call can re-permission an entire folder tree.

At least one of `organizationRole` or `organizationAccessBoost` is required.




## OpenAPI

````yaml /api/openapi.yaml put /v1/folders/{folderId}/permissions
openapi: 3.1.0
info:
  title: Omni API
  description: >
    The Omni REST API provides programmatic access to your Omni instance for
    managing users, documents, queries, schedules, and more.  
  version: 1.0.0
  contact:
    name: Omni Support
    url: https://docs.omni.co
servers:
  - url: https://{instance}.omniapp.co/api
    description: Production
    variables:
      instance:
        default: blobsrus
        description: Your production Omni instance subdomain
  - url: https://{instance}.playground.exploreomni.dev/api
    description: Playground
    variables:
      instance:
        default: blobsrus
        description: Your playground Omni instance subdomain
security:
  - bearerAuth: []
  - orgApiKey: []
tags:
  - name: Who Am I
    description: Inspect your own user permissions
  - name: AI
    description: AI-powered query generation
  - name: AI Credit Controls
    description: Manage organization-level AI credit usage
  - name: AI Credit Usage
    description: Monitor AI credit usage
  - name: AI Evals
    description: >-
      Manage prompt sets and runs used to score AI quality against curated
      prompt suites.
  - name: AI Model Suggestions
    description: Manage AI-generated suggestions for shared models
  - name: AI Routines
    description: >-
      Manage Routines, which are scheduled, recurring AI-powered tasks that run
      automatically on your data
  - name: Apps
    description: Draft and publish app documents.
  - name: Documents v2
    description: >
      A draft-based workflow for creating and editing documents: create a
      document, patch a draft, then publish.
  - name: Documents
    description: Create, retrieve, and manage documents
  - name: API Tokens
    description: >-
      Manage API tokens (Organization keys, Personal Access Tokens, MCP OAuth
      grants)
  - name: Connections
    description: Manage database connections
  - name: Connection environments
    description: Manage connection environments database connections
  - name: Content
    description: Unified content retrieval (documents and folders)
  - name: Content migration
    description: Export and import dashboards
  - name: Content validator
    description: Validate content against models and perform find/replace operations
  - name: Dashboard downloads
    description: Download dashboards and tiles as PDF, PNG, XLSX, CSV, or JSON files
  - name: Dashboard filters and controls
    description: Read and update dashboard filter and control default values
  - name: dbt
    description: Manage dbt configuration for connections
  - name: Document favorites
    description: Favorite and unfavorite documents
  - name: Document labels
    description: Apply and manage labels on documents
  - name: Document permissions
    description: Manage document-level access
  - name: Labels
    description: |
      Manage labels in the organization
  - name: Folders
    description: Create and organize content folders
  - name: Folder labels
    description: Apply and manage labels on folders
  - name: Folder permissions
    description: Manage folder-level access
  - name: Jobs
    description: Check status of asynchronous jobs
  - name: Models
    description: Create and manage data models
  - name: Model branches
    description: Manage model branches and merge changes
  - name: Model git configuration
    description: Manage git configuration for shared models
  - name: Queries
    description: Execute workbook queries
  - name: Schedules
    description: Create and manage scheduled tasks
  - name: Schedule recipients
    description: Manage schedule recipients
  - name: Schema refresh schedules
    description: Manage automated schema refresh schedules for connections
  - name: Topics
    description: Retrieve topic information from models
  - name: Uploads
    description: Manage file uploads
  - name: Users
    description: Manage users
  - name: User attributes
    description: Manage user attribute definitions
  - name: User groups
    description: Manage user groups
  - name: User model roles
    description: Manage model and connection role assignments for users
  - name: User group model roles
    description: Manage model and connection role assignments for user groups
  - name: Uploads
    description: Manage CSV and spreadsheet uploads
paths:
  /v1/folders/{folderId}/permissions:
    put:
      tags:
        - Folder permissions
      summary: Update organization-level folder permissions
      description: >
        Set the role every member of the organization holds on a folder, and/or
        turn [AccessBoost](/share#boosting-permissions-with-accessboost) on or
        off for that organization-wide access, without naming individual users
        or groups. The role cascades to every descendant folder and document, so
        a single call can re-permission an entire folder tree.


        At least one of `organizationRole` or `organizationAccessBoost` is
        required.
      operationId: foldersUpdatePermissionSettings
      parameters:
        - name: folderId
          in: path
          required: true
          schema:
            type: string
            format: uuid
          description: >-
            The UUID of the folder. Use the [List
            folders](/api/folders/list-folders) endpoint to retrieve folder IDs.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                organizationAccessBoost:
                  type: boolean
                  description: >
                    Whether everyone in the organization gets
                    [AccessBoost](/share#boosting-permissions-with-accessboost)
                    on this folder. Setting this to `true` requires an
                    organization role that grants access, either sent in the
                    same request or already on the folder; otherwise the request
                    is rejected.
                organizationRole:
                  description: >
                    The role every member of the organization holds on the
                    folder. Must be one of `NO_ACCESS`, `VIEWER`, `EDITOR`, or
                    `MANAGER`. `OWNER` cannot be granted at the organization
                    level. Pass `null` to clear the organization role.
                  type: string
                  enum:
                    - NO_ACCESS
                    - VIEWER
                    - EDITOR
                    - MANAGER
                    - OWNER
              additionalProperties: false
              minProperties: 1
            examples:
              setOrganizationRole:
                summary: Set the organization role
                value:
                  organizationRole: VIEWER
              clearOrganizationRole:
                summary: Clear the organization role
                value:
                  organizationRole: null
              enableAccessBoost:
                summary: Enable AccessBoost for the organization's access
                value:
                  organizationAccessBoost: true
      responses:
        '200':
          description: Permission settings updated successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    description: Whether the permission settings were updated successfully
                required:
                  - success
        '400':
          description: >
            Bad Request


            Possible causes:


            - Neither `organizationRole` nor `organizationAccessBoost` was
            provided, or an unrecognized field was included

            - `organizationRole` was set to `OWNER`, which cannot be granted at
            the organization level

            - `organizationAccessBoost: true` was combined with a role that
            grants no access — either the one in the request, or the folder's
            current role when the request omits `organizationRole`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError400'
        '403':
          description: >
            Forbidden


            Possible causes:


            - `User does not have permission to manage folder permissions` - The
            user sending the API request must have **Manager** permissions for
            the folder.

            - AccessBoost is turned off for the organization

            - A user-scoped key lacks boost provisioning
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError403'
        '404':
          description: |
            Not Found

            Possible error messages:

            - `Folder with identifier "<folderId>" not found`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError404'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security:
        - bearerAuth: []
components:
  schemas:
    ApiError400:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message describing what went wrong.
        status:
          type: integer
          description: HTTP status code of the error.
          example: 400
      required:
        - detail
        - status
    ApiError403:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message describing what went wrong.
        status:
          type: integer
          description: HTTP status code of the error.
          example: 403
      required:
        - detail
        - status
    ApiError404:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message describing what went wrong.
        status:
          type: integer
          description: HTTP status code of the error.
          example: 404
      required:
        - detail
        - status
    Error:
      type: object
      properties:
        error:
          type: string
          description: HTTP response code for the error
          example: <response_code>
        message:
          type: string
          description: Detailed error description
          example: <error_reason>
  responses:
    TooManyRequests:
      description: Too Many Requests - Rate limit exceeded (60 requests/minute)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Can be either an [Organization API
        Key](/api/authentication#organization-api-keys) or [Personal Access
        Token (PAT)](/api/authentication#token-types).


        Include in the `Authorization` header as: `Bearer YOUR_TOKEN`
    orgApiKey:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Requires an [Organization API
        Key](/api/authentication#organization-api-keys). Personal Access Tokens
        (PATs) are not supported for this endpoint.


        Include in the `Authorization` header as: `Bearer ORGANIZATION_API_KEY`

````