Sistava

Control Access & Share Resources

Resource Access controls who can open a supported Drive file or document, CRM contact, Content item, task, Project, Sprint, calendar meeting, or employee mailbox email. Sharing is one way to change that access. It is separate from social-media sharing.

Need to decide whether to invite someone, change their role, or share one item? Read Collaborate Across Workspaces first.

Access controls at a glance

Every workspace resource is private from the public web. Choose the access level that fits the item:

Access level Who can open it When to use it
Workspace default Every accepted collaborator in the source workspace Normal internal work. This is the default for existing supported resources.
Restricted The policy owner, workspace admins, and people you add Sensitive work that should not be visible to every collaborator.
External direct share One existing, signed-in Sistava account in another workspace Give a client, partner, or another account read-only access without adding them to your workspace.
Public link Nobody, not available Public, anonymous links are intentionally not enabled yet.

Changing an item from workspace default to Restricted does not make it public. It narrows access. Adding an external account does not make them a collaborator and never gives them access to your other work.

What is shared by default

A workspace is one isolated operating environment. A person who has accepted an invitation to that workspace can already open its workspace-visible resources. A separate Sistava account receives nothing unless you explicitly share an item.

Resource source Default access Can use Resource Access now?
Employee-written Drive work files, including Markdown and private-path documents All accepted collaborators in the source workspace Yes
Employee-created exports, such as PDF, DOCX, XLSX, images, videos, and screenshots All accepted collaborators in the source workspace Yes
CRM contacts All accepted collaborators in the source workspace Yes
Content items, tasks, Projects, and Sprints All accepted collaborators in the source workspace Yes
Calendar meetings your employees are booked to attend All accepted collaborators in the source workspace Yes
Employee mailbox emails, including their text and private discussion All accepted collaborators in the source workspace Yes
Files uploaded in Chat All accepted collaborators in the source workspace Not per file yet
Files uploaded for Training, including spreadsheets All accepted collaborators in the source workspace Not per file yet
Work journal entries All accepted collaborators in the source workspace Not per item yet
Private employee notebooks Only the person whose conversation created the notes, unless that person approves a read request Request-only, read-only

That workspace-wide default preserves access to existing work. It is not public. No anonymous visitor and no collaborator in another workspace can open it.

How to share one resource

  1. Open the resource in Drive, Company → CRM, Content, the Tasks drawer, Manage projects, Sprints, a meeting card in Calendar, or an email in an employee Inbox. You can also use the Share icon on a tracked file preview in Chat.
  2. Click Share in the resource's action row or drawer.
  3. Choose an accepted workspace collaborator, or enter the email address of an existing Sistava account in another workspace.
  4. Select their role and click Share. A direct share makes the resource Restricted, so other source-workspace collaborators no longer retain the old default unless you choose General access again.
  5. The recipient receives an in-app notification. An external recipient opens a protected, read-only shared-resource page; they never become a collaborator in your workspace.

Import a Private Copy into Another Workspace

If you run more than one workspace, share a compatible selected file, document, or CRM contact to your own Sistava account. Open the shared-resource notification while the destination workspace is active, then click Add private copy. The system creates a new file or CRM contact owned by that destination workspace.

Nothing appears in the destination workspace until its recipient accepts the offer. The imported copy is private by default and independent of the source: revoking the original share stops future imports but does not delete a copy the recipient already accepted. This is also how you safely share a selected item with a partner, friend, or client without giving them your whole workspace.

Content items, tasks, Projects, Sprints, and calendar meetings are read-only shared views today. They do not offer Add private copy.

To share several CRM contacts, select the rows in Company → CRM, choose Share selected, enter the recipient's Sistava account email, and choose a role. Each contact keeps its own access rule, so you can remove one later without affecting the others.

Choose the right access

Role What they can do
Viewer Open and read the file.
Commenter Open, read, and comment.
Editor Open, comment where the resource has comments, and edit its supported human workflow.

Use General access when you want every signed-in collaborator in your workspace with the internal link to open the resource. Use Restricted when only the people you add should have access. You can remove a person's direct access at any time. Direct recipients outside your workspace always get a protected, read-only view even if you choose Editor.

Projects have no comment thread yet. Their Share control offers Read-only or Can edit & archive; Project access never automatically shares the tasks or Drive files grouped under that Project.

Calendar meetings have no comment thread either. Their Share control offers Read-only or Can edit, move & cancel. A Viewer can see the appointment's safe details, but never its meeting link or organizer. An Editor can use the meeting link and manage a scheduled meeting booked in Sistava. A meeting that came from Google Calendar, Outlook, or another calendar stays owned there, so move or cancel it in its source calendar.

Mailbox email sharing controls the human Inbox record: Read-only opens the email text, Can view & comment also allows the internal discussion, and Can add private notes allows notes for the employee. If an email contains a snapshot of a restricted Drive file, its source-file permission still applies. An external recipient sees only a protected, read-only text view: no attachment bytes, notes, comments, native Inbox access, or import.

Copy internal link gives you a convenient workspace link to send through email or chat. It is not a public link: the recipient must sign in and still pass the resource's access policy. Forwarding it does not grant anyone access.

When you restrict a supported resource or remove a direct share, a previously copied internal link stops opening it for people who no longer have access.

Public links are not available in this release. Making a resource public would need a separate revocable link, expiry, audit trail, and an explicit decision about exposing its data. Resource Access never makes a supported resource public by accident.

Private employee notebooks

An employee's Private notebook can appear in Drive as a locked item. A locked item deliberately reveals no notes, title, timestamp, source path, or the person who owns the notes. Select it and choose Request access to ask that person for a human read-only view.

Only the person whose conversation created that notebook can approve the request. Approval creates a normal, revocable Viewer grant for the Drive view; it does not let the employee use, merge, or repeat those private notes in someone else's conversation. Workspace Owners and Admins do not get an automatic read bypass for private notebooks.

Who can change access

The person who first manages a resource's Resource Access, or a workspace administrator, can add people, change general access, or remove grants. AI employees can tell you that a file is shareable, but they cannot change its permissions themselves.