Move a trusted file to your second workspace
Share the selected file to your own account, switch workspace, and add a private copy without recreating the file or blending the two workspaces.
Share a single Drive file, Drive document, or CRM contact without opening your whole workspace. Choose who can view, comment, or edit it, including a named person in a completely different Sistava workspace, and revoke that access at any time.
Your workspace is private by default. Bring teammates in with a workspace role, Owner, Admin, or Collaborator, when they need to work alongside you day to day, then use Private Resource Sharing only when a single item, a Drive file, a Drive document, or a CRM contact, needs a narrower audience than your whole roster.
A direct share is an authenticated offer, not a public URL. The recipient signs in to see that one item and never becomes a member of your workspace or gains access to your other employees, conversations, files, contacts, billing, or settings.
The two systems intentionally do not overlap. Workspace membership is ongoing and broad: an Owner or Admin can grant a Collaborator the extra ability to invite people or manage resource access, but that still operates at the workspace level. A resource grant is narrow and typed: Viewer for read-only, Commenter for read plus comments, or Editor for full read-write, on exactly one file, document, or contact, with an optional expiry date after which the grant simply stops counting, no separate revoke step required.
If you run two workspaces, or work with a partner who uses another one, the recipient can explicitly add a private copy to their chosen workspace. Nothing appears there until they accept. The new copy is independent, so your source workspace stays isolated.
Remove the source share whenever the collaboration ends. The recipient immediately loses the protected source view and cannot import it later. A copy they already accepted remains theirs, just as a file sent to a collaborator would.
Workspace membership is for ongoing collaboration. Owners, Admins, and Collaborators each receive a clear level of operational access, and Owners can grant a non-Owner a limited exception such as inviting people or managing resource access.
Resource Access is for the exception. Use it when a customer, contractor, partner, or second workspace needs a selected report or contact but does not need to enter the source workspace.
Shared resources stay behind sign-in and server-enforced access checks. Copying a link into email or chat is convenient, but it never creates permission for someone who was not granted access.
Public anonymous links are intentionally unavailable. Every direct recipient is known, every source grant can be removed, and every imported copy is created only after the receiving workspace chooses it.
Only three resource types carry a policy right now: Drive assets, Drive documents, and CRM contacts. The check runs at every read and write path for each one, GraphQL listings, the file's byte proxy, comment threads, and the edit or delete mutation, so a copied internal link cannot bypass it.
Tasks, calendar events, and other work items keep their current workspace-only behavior until they get their own sharing control. Private Resource Sharing is included on every plan, with no seat limit or added cost on top of it.
One access policy per resource, checked before every view, comment, or edit
Every Drive file, Drive document, and CRM contact starts with no access policy, which means it follows the workspace's normal collaborator rules. The moment an owner or admin restricts it or shares it with someone by name, the platform creates a policy row for that specific resource and starts checking it on every open, comment, and edit request.
A policy can stay Restricted (only the owner, admins, and people with an explicit grant can reach it) or Organization (any workspace collaborator can reach it, same as before). Each grant carries a role: Viewer for read-only, Commenter for read plus comments, Editor for full read-write, plus an optional expiry date after which the grant simply stops counting.
A cross-workspace grant works differently on purpose. The recipient does not become a member of your workspace and cannot see anything else in it. They land on a dedicated shared-item page, and if they choose to import it, the platform copies the file, document, or contact record into a workspace they already belong to. From that point it is their own independent copy: revoking your original share no longer affects it.
Share the selected file to your own account, switch workspace, and add a private copy without recreating the file or blending the two workspaces.
Give a partner a protected offer for one contact without exposing the rest of your CRM or inviting them to your workspace.
Limit a file to named people while the rest of your accepted workspace members keep their normal access to ordinary work.
Grant Viewer or Editor access with an expiry date so the contractor's access stops counting automatically at project end, with no separate revoke step to remember.
No. Links stay private. The recipient must sign in to the account that received the direct share and pass the resource access check.
Yes. Share the selected supported resource to your own account, switch to the destination workspace, and accept it as a new private copy.
Resource Access supports Drive files, Drive documents, and CRM contacts. Other resource types keep their workspace boundaries until they receive their own sharing control.
The recipient loses access to the source item immediately and cannot import it later. A separate copy they already accepted remains in their workspace.
Viewer for read-only, Commenter for read plus comments, or Editor for full read-write. Every grant can also carry an expiry date, after which it simply stops counting, so you do not have to remember to revoke it yourself.
No. Private Resource Sharing is available on every plan at no added cost, with no cap on how many resources or people you share with.
Private Resource Sharing is part of Where their work lives.
Your AI agents manage their own workspace. Scheduled tasks run daily, weekly, or on custom cron cadences. A built-in kanban board tracks what is in progress. Every document lands in a personal Drive. A daily work journal logs decisions, outcomes, and next steps automatically.