# Control Access & Share Workspace Resources Resource Access controls who can open a Drive file or CRM contact. Sharing is one way to change that access. It is separate from social-media sharing. ## Access controls at a glance Every workspace resource is private from the public web. Choose the access level that fits the item: | Access level | Who can open it | When to use it | | ------------------------- | --------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- | | **Organisation default** | Every accepted member of the source organisation | Normal internal work. This is the default for existing Drive files and CRM contacts. | | **Restricted** | The policy owner, organisation admins, and people you add | Sensitive files or contacts that should not be visible to every teammate. | | **External direct share** | One existing, signed-in Sistava account in another organisation | Give a client, partner, or another account read-only access without adding them to your organisation. | | **Public link** | Nobody — not available | Public, anonymous links are intentionally not enabled yet. | Changing an item from organisation default to **Restricted** does not make it public. It narrows access. Adding an external account does not make them a member of your organisation and never gives them access to your other work. ## What is shared by default An organisation means one workspace tenant. A person who has accepted an invitation to that organisation can already open its organisation-visible resources. A separate Sistava account belongs to a different organisation and receives nothing unless you explicitly share it. | Resource source | Default access | Can use Resource Access now? | | ------------------------------------------------------------------------------- | ----------------------------------------------- | ---------------------------- | | Agent-written Drive work files, including Markdown and private-path documents | All accepted members of the source organisation | Yes | | Agent-created exports, such as PDF, DOCX, XLSX, images, videos, and screenshots | All accepted members of the source organisation | Yes | | CRM contacts | All accepted members of the source organisation | Yes | | Files uploaded in Chat | All accepted members of the source organisation | Not per file yet | | Files uploaded for Training, including spreadsheets | All accepted members of the source organisation | Not per file yet | | Work journal entries and the employee notebook | All accepted members of the source organisation | Not per item yet | That organisation-wide default preserves access to existing work. It is not public. No anonymous visitor and no member of another organisation can open it. ## How to share one file or contact 1. Open the file in **Drive** or use the Share icon on a tracked file preview in **Chat**. For contacts, open **Company → CRM**. 2. Click **Share** in the file viewer or contact drawer. 3. Choose an accepted organisation member, or enter the email address of an existing Sistava account in another organisation. 4. Select their role and click **Share**. A direct share makes the resource **Restricted**, so other source-organisation members no longer retain the old default unless you choose General access again. 5. The recipient receives an in-app notification. An external recipient opens a protected, read-only shared-resource page; they never become a member of your organisation. To share several CRM contacts, select the rows in **Company → CRM**, choose **Share selected**, enter the recipient's Sistava account email, and choose a role. Each contact keeps its own access rule, so you can remove one later without affecting the others. ## Choose the right access | Role | What they can do | | ------------- | -------------------------------------------------- | | **Viewer** | Open and read the file. | | **Commenter** | Open, read, and comment. | | **Editor** | Open, comment, and edit supported Drive documents. | Use **General access** when you want every signed-in member of your organisation with the internal link to open the resource. Use **Restricted** when only the people you add should have access. You can remove a person's direct access at any time. Direct recipients outside your organisation always get a protected, read-only view even if you choose Editor. ## Links stay private **Copy internal link** gives you a convenient workspace link to send through email or chat. It is not a public link: the recipient must sign in and still pass the resource's access policy. Forwarding it does not grant anyone access. Public links are not available in this release. Making a resource public would need a separate revocable link, expiry, audit trail, and an explicit decision about exposing contact data. Resource Access never makes a file or CRM contact public by accident. ## Who can change access The person who first manages a resource's Resource Access, or an organisation administrator, can add people, change general access, or remove grants. AI employees can tell you that a file is shareable, but they cannot change its permissions themselves.