Who Has Access to This
The first question anybody asks after an incident, and until recently one the platform could not answer at all: who can see this document, and how?
Where to find it
On a document, the Sharing panel. Below the grants it lists every route to the document.
What it shows
- The creator, named exactly.
- Grants, named exactly, with their level and expiry.
- Live share links, with what is left of them.
- Each linked record, and the teams holding Read on that record’s datastore, by name.
- The classification, reported separately as a cap rather than as a route.
Routes, not a list of people
It deliberately does not enumerate the members of every team. A named list of everybody who could open a document is a different and more sensitive artefact than a list of the doors, it is out of date the moment somebody changes team, and it invites the reader to believe it is complete.
The doors are the thing you can actually change.
The classification is a cap, not a door
Shown apart from the routes because it does not grant anything. It only ever narrows what the routes allow, which is why it reads as a separate line.
Use it before sharing, not only after
The panel is most useful before attaching a document to another case: it shows what access already exists, so you can see what you are about to add to.
Worked example
A manager is asked how a valuation reached a contractor. The Sharing panel shows one grant to a named person that expired last month, one live link with one use left, and two linked records — one of which is a case the contractor’s team can read. The answer is the second record, and it took one screen rather than a week.
Recommendations
- Check it before attaching a sensitive document to an additional record.
- Treat a long route list as a finding. A document reachable six ways is usually attached to something it should not be.
- Revoke what the incident found from the same panel.