How to Set SharePoint Document Library Permissions for Power Automate Approvals
Question details
The user needs to configure SharePoint permissions so employees can see document metadata (like names and Project IDs) but cannot open, edit, or download the files until a Power Automate flow approves access.

- Product
- SharePoint and Power Automate
- Device & OS
- not provided
- Scenario
- Setting up a document approval workflow where file visibility must be separated from actual file access.
- Observed behavior
- Currently, granting read access allows users to open and download files prematurely. Removing read access completely hides the files from search results and filtered views, breaking the workflow.
Ensure you have Site Owner or Full Control permissions in your SharePoint site to manage library settings and create custom lists, as well as access to Power Automate to build approval flows.
Use a Dual-List Strategy with Item-Level Permissions
The safest method is to separate the file storage from the metadata visibility to avoid SharePoint search and view errors.
SharePoint search and list views can behave unreliably when users have visibility of file names but lack the permission to read the actual file contents.
To avoid missing files in filtered views, keep the private documents in a highly restricted library and display their metadata in a separate public list.
Navigate to Site Contents and create a new Document Library. Go to Library Settings > Permissions for this document library, stop inheriting permissions, and remove all access except for Site Owners.
Create a separate SharePoint List to store public metadata such as Project IDs, document names, and approval status. Grant standard users 'Read' or 'Contribute' access to this list so they can request approvals.
Build a flow in Power Automate triggered by an approval action. Use the 'Grant access to an item or a folder' SharePoint action to dynamically assign Read or Edit permissions to the specific user in the restricted library once the flow is approved.

Create a Custom Read-Only Permission Level
Modify SharePoint permission levels to allow viewing item metadata without permitting users to open or download the source files.
Enhance Your Document Workflow with WPS Office
While SharePoint and Power Automate handle complex access controls and approvals, managing and editing the actual documents requires a powerful office suite. WPS Office is a free, lightweight, and user-friendly alternative to Microsoft Office, ensuring seamless collaboration on Word, Excel, and PowerPoint files once access is granted.
- 1. Download WPS Office: Visit the official WPS Office website and download the free desktop application for your operating system.
- 2. Open Approved Documents: Once your Power Automate flow grants access to a SharePoint document, download it and open it seamlessly in WPS Office.
- 3. Edit and Save: Edit your documents with full formatting retention and save them back in their native formats (e.g., .docx, .xlsx) to maintain compatibility.

Frequently Asked Questions
Why can't users see files in SharePoint search if they only have view metadata permissions?
SharePoint search utilizes security trimming based on user permissions. If a user lacks the permission to read the actual content of a file, SharePoint's indexing engine may completely hide the item from search results and filtered views to prevent data leakage.
Can Power Automate change permissions on a specific file dynamically?
Yes, Power Automate includes specific SharePoint connector actions such as 'Grant access to an item or a folder' and 'Stop sharing an item or a file'. These allow you to programmatically adjust item-level permissions during or after an approval flow.
What happens if a user tries to open a file without read permissions?
If a user attempts to access a file via a direct link but does not have the required read permissions, SharePoint will display an 'Access Denied' error or a 'Request Access' message, preventing them from viewing or downloading the content.




