A guest account is a limited account for somebody outside your organization. FileRun creates one when a user shares a file or a folder with an e-mail address that has no account yet. The guest can then open what was shared with them, and nothing else.
Compared to regular user accounts, guest users:
Guest role allows editing (possible since FileRun 2026.3.1). After an update from an older version the option is off, so guests stay read-only until an administrator enables it; on a new installation it is on.The permissions above are fixed for the Guest role. The rest is set in the role's permissions, like for any other role: whether guests can download, upload, edit files, use collections, star files, read comments and read tags, ratings and metadata.
When a guest is among the recipients of a share, the sharing window offers only the roles that mean something for a guest, described from the Guest role's permissions: Viewer, Commenter (viewing comments and metadata, when the role allows reading them), Editor (when the role allows editing) and, for folders, Uploader. The roles Distributor, Contributor and Content manager are not offered, because they would give a guest nothing more. A role given to a guest through the API is stored as given, but the guest still cannot do more than the Guest role allows.
Guest accounts are automatically deleted when there are no shares available anymore.
The settings are in the control panel under Users → Settings → Guest access, which only the superuser can open. All three switches are on in a new installation.
The main switch. With it off, guests are refused everywhere: through their sign-in link, on the sign-in page with a username and a password, and even in a session they already have open. Nobody can invite a new guest either.
The guest accounts are not deleted. The users list shows them as inactive, and turning the switch back on gives them their access back.
With this option on, the e-mail that tells a guest about a share contains a link that signs them in without a password. The link belongs to that one guest and opens the shared item directly.
With it off, the e-mail contains the plain address of the item, and the guest signs in with a username and a password, like any other user. A link received earlier no longer works, but a guest who is already signed in stays signed in.
A guest who has no password can set one with Forgot password? on the sign-in page, when that option
is enabled. See Sign-in and passwords.
When an administrator edits a guest account, the sign-in link is shown as Guest access URL, with a
button that copies it. The link is built from the account's username and password, so changing either
of them makes every earlier link invalid.
With this option off, nobody can create a new guest by sharing with an e-mail address, whatever their permissions allow. The guests that already exist keep working, and administrators can still create guest accounts themselves, from the users list.
To invite guests, a user also needs the permission User can add guest users, among the sharing
permissions of the account or of its role.
FileRun deletes a guest account by itself in two cases:
Delete inactive guest user accounts after, in the fieldset
Guest account retention policy, deletes a guest who has not opened FileRun for that number of days.
A guest who never signed in is counted from the day the account was created. The default is 30 days,
and 0 turns this off.Deleting a guest account does not delete any file. The inactivity rule runs once a day, and it keeps running while guest accounts are disabled. In the users list, the expiration date of a guest shows the day it will be deleted.
See also Data retention.