Docs
Admin guide
For workspace owners, admins and studio IT: who can do what, keeping the workspace secure, and deploying ReachFS.
Last updated October 3, 2026
Roles
Every workspace member has one of four roles. The person who creates the workspace is its owner. Admin pages live in the desktop app's main window, not the website, because approving a device means handling keys that only an approved computer holds.
| Can | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| Open and search files | Yes | Yes | Yes | Yes |
| Save, rename, delete; lock files for editing; make snapshots | Yes | Yes | Yes | No |
| Invite and remove members, change roles | Yes | Yes, except owners | No | No |
| Approve and revoke other people's devices | Yes | Yes | Own devices only | Own devices only |
| Require two-step sign-in; stop uploads at the plan; rename the workspace | Yes | Yes | No | No |
| See billing and the audit log; delete snapshots; empty the recycle bin | Yes | Yes | No | No |
| Archive and restore folders | Yes | Yes | No | No |
| Make or remove another owner | Yes | No | No | No |
| Choose the workspace's own storage bucket | Yes | No | No | No |
A workspace always keeps at least one owner.
Members and invites
Inviting. In Members, enter an email and a role. ReachFS emails an invite link; if sending fails, choose Copy the invite link and send it yourself. Pending invites are listed until accepted, and can be withdrawn. The person installs ReachFS, signs in, and then approves their first computer, or you do (see Devices).
Changing a role. Pick a new role beside the member. Only an owner can make or unmake another owner, and the last owner cannot step down until someone else is one.
Removing someone. Choose Remove beside the member. ReachFS then:
- Releases any files they had locked.
- Revokes the storage credentials their computers held.
- Starts a new workspace key. Your computer does this right away; if you are not on an approved computer, the next approved computer to connect does it. Until then, Members shows the person as rotation pending.
Once the key has changed, the removed person cannot read anything written after their removal. They could already read older files, and may have copies, so removal cannot take those back. To make the stored copies of old files unreadable to their old key too, re-encrypt them (see Security settings).
Devices
Each computer is a separate device with its own key. Devices lists every one with its owner and when it was last seen.
- Approving. A new computer waits until an approved computer lets it in, and approving is what hands it the workspace key. Anyone can approve their own new computer; an owner or admin can approve anyone's. Approve only computers you recognise.
- Revoking. Choose Revoke for a lost or retired computer. The next time it connects, it unmounts the drive and deletes everything ReachFS kept on it: the file list, unsent changes, offline copies and its key. Revoking also starts a new workspace key, as removing a member does.
- Remove and wipe. The same, for another member's computer, when you need it gone now. ReachFS refuses this for a computer that is also in another workspace, whose admins did not ask.
A revoked computer cannot be approved again; it has to join afresh with a new key.
The limit to know: a computer that never reconnects keeps whatever it already had on its disk. Revocation reaches it only when it comes online.
Security settings
Require two-step sign-in. In the workspace's Settings, turn this on and ReachFS refuses anyone who signed in without a second step: an authenticator app code, a backup code, or a passkey. Members without one are asked to set it up on their account page.
The recovery phrase. Whoever creates a workspace sees its 24-word phrase once. It is the only way back in if every approved computer is lost: ReachFS holds no key that opens your files. Store it like the master key it is, for example printed in the office safe. The phrase keeps working after members are removed and keys change.
Re-encrypting old files after a removal. A new workspace key protects everything written from then on. Files written before stay readable to the old key until you re-encrypt them, which rewrites each file under the current key. It is slow, because every old file is downloaded and uploaded again, and it can be stopped and run again safely. Run it from an approved computer:
- Unmount the workspace's drive in the app.
- Open a terminal in the ReachFS install folder.
- See what is left:
reachfs.exe --session rewrap --dry-run --state "%LOCALAPPDATA%\ReachFS\workspaces\<folder>" - Run it without
--dry-run. Add--max-upload-mbps 200to keep the office line usable.
A file someone has open for editing is skipped and picked up on the next run. Old copies held by snapshots, the recycle bin or version history stay readable to the old key until those expire or are deleted. Folder and file names are not re-encrypted.
Storage and billing
Each plan includes an amount of storage; storage past it is billed by the month as overage. Plans and prices are on the pricing page. Plan & billing in the app opens Paddle, our reseller, in your browser to upgrade, change your card or see invoices, and shows this month's estimate.
Usage shows storage used against the plan, a 30-day trend, downloads (included, not metered), duplicate files, and storage by person. The by-person figure is worked out on your computer, because who created each file is encrypted and ReachFS's servers cannot see it.
Identical content is stored once per workspace: a copied clip costs no extra storage.
Stop uploads at the plan's storage. Off by default, so storage past the plan is billed as overage. Turn it on in the workspace's Settings to cap spending instead. When the workspace reaches its plan, new uploads stop; deleting, renaming and copying inside the workspace keep working. Changes made meanwhile wait safely on each computer, the tray says the workspace is full, and the uploads go through as soon as space is freed, the plan is upgraded or the switch is turned off.
Data protection
Three layers protect against mistakes. Restoring from any of them is instant and uploads nothing, because ReachFS points at the content already stored.
| Layer | What it keeps | How long | Who restores |
|---|---|---|---|
| Recycle bin | Deleted files and folders | 30 days | Any member; emptying it is owner or admin |
| Version history | Earlier saves of each file | 30 days | Any member, from Show history |
| Snapshots | The whole workspace at a moment | Until deleted, or the schedule's keep period | Any member restores; owners and admins delete |
Scheduled snapshots. In Snapshots, an owner or admin sets one every so many hours and how many days to keep them. Members can also take one by hand before a risky change.
The activity log. Each file's history shows who added, changed, moved or deleted it. The workspace Audit page records membership, device and security events, such as invites, removals, approvals, revocations and settings changes.
Archiving finished projects
Where archiving is enabled, archive a finished project to move its files to cheaper cold storage. Archived files stay listed and searchable, but cannot be opened until the folder is restored.
- In Files, right-click the folder and choose Archive folder. The folder shows an Archived badge with progress while its files move.
- To bring it back, choose Restore from archive. Files open again once the restore finishes.
What to know:
- Content that other, live files also use stays in regular storage, so archiving never slows down work elsewhere.
- Earlier versions and recycle-bin copies stay in regular storage until they expire.
- Someone opening an archived file sees Windows' the file is offline message; the app tells them to ask for a restore.
- Archived storage is counted separately from regular storage.
- The archive option appears only where archive storage is enabled, and not for a workspace on its own bucket. For those, use your provider's own lifecycle rules.
Bring your own bucket
A workspace can keep its files in a storage bucket your organisation owns and pays for, on Backblaze B2 or any S3-compatible provider. Files are encrypted on members' computers either way: your provider stores only data it cannot read.
Setting it up. Only the owner can do this, and only while the workspace is still empty, because files cannot move between buckets once stored.
- Create a bucket at your provider, and a key for it.
- In the app, open Settings › General › Storage and enter the provider, endpoint, region, bucket, key ID and secret.
- ReachFS checks the key by writing, reading and deleting a test file, and tells you what to fix if any step fails.
The secret is stored encrypted on ReachFS's servers and is never shown again; settings show only the last four characters of the key ID.
B2 or another provider?
| Backblaze B2 | Other S3-compatible | |
|---|---|---|
| Your key needs | Write keys and delete keys on the bucket | Read, write and delete on the bucket |
| What computers get | Short-lived keys ReachFS makes from yours: one workspace only, no delete, expire in 2 hours | Your key itself, after you confirm it reaches only this bucket |
| When a member or computer is removed | Their keys are revoked at once | Keeps working until you rotate the key at your provider |
For generic S3, give ReachFS a key limited to this one bucket, and rotate it after removing someone.
Billing. Talk to us about pricing for workspaces on their own bucket.
Studio IT
Installing. ReachFS-Setup.exe needs administrator rights once. It installs WinFsp (left in place on uninstall, since other software may use it), the ReachFS app and engine, and the Explorer status icons for all users. It is a standard WiX bootstrapper, so /quiet and /norestart work for scripted rollouts. Each person then signs in and approves their own computer. The app updates itself, checking once a day.
Where data lives on each computer. Under %LOCALAPPDATA%\ReachFS, per Windows user. Offline copies are stored encrypted. Two things are not, so that search is instant and saves are fast: the workspace's file list (names and media details), and changes not yet uploaded. Both are protected by Windows account permissions and wiped if the computer is revoked. Turn on BitLocker (or equivalent full-disk encryption) on every computer that runs ReachFS; it is what protects those against a stolen laptop. Device keys and the sign-in session are kept in Windows Credential Manager.
Network. Everything goes out over HTTPS on port 443:
| Destination | Used for |
|---|---|
api.reachfs.app |
Sign-in, sync, locks, keys |
reachfs.app |
Browser sign-in, invites, updates |
Your storage endpoint (s3.us-east-005.backblazeb2.com for ReachFS-managed storage, or your own bucket's) |
File content |
| A team cache on your LAN, if you run one | TCP 7447, found by broadcast on UDP 7448 |
Bandwidth. Per-computer upload and download limits, with a separate quiet-hours schedule, are in Preferences. A saturated line slows ReachFS down but never fails it: transfers give up only after a minute with no bytes moving.
A team cache box. For a studio where many editors read the same rushes, run one always-on machine as a LAN cache, so each block comes over the internet once instead of once per editor. It stores only encrypted blocks and holds no keys: a stolen cache box reveals file sizes and access patterns, not content.
reachfs team-cache --session --server https://api.reachfs.app --user <box's user> --listen 0.0.0.0:7447 --size-gb 2048 --dir D:\teamcache
Sign the box in as a user who is a member of each workspace it should serve. Editors' computers find it automatically, or take its address in Preferences › Team cache. Its /stats page shows blocks served from the cache against blocks fetched from storage.
Audit. The workspace Audit page lists membership, device and security events, with who did each and when.