Administration

Directory sharing

Give a person access to one branch of the tree.

A share hands one person access to a single branch of your tree, separate from their role. Reach for it when someone needs to work in one part of the structure without changing what they can reach anywhere else.

Sharing from policy

Administrators manage shares from the Policy area. Open Policy from Setup, select the Access tab, and keep the Directory list in view.

The Policy area with the Access tab open, showing the Directory list and a prompt to select part of the directory to manage who can access it.The Policy area with the Access tab open, showing the Directory list and a prompt to select part of the directory to manage who can access it.
  1. In the Directory list, find the branch you want to share. Use the "Search the directory" box when the tree is large.
  2. Select it. Until you do, the panel prompts you to select part of the directory to manage who can access it.
  3. Choose the person you want to give access to.
  4. Choose what they can do on that branch — see it, add entries, edit entries, or remove them.

Seeing is the floor of every share. You build adding, editing, and removing on top of it, and you cannot grant someone editing without also letting them see what they are working on.

To share, you need permission to manage access there. You can pass on only the actions you can perform on that branch yourself, so a share never grants more than you already hold. The Access tab also carries a Pages list, for sharing a page with a person in the same way.

Access flows downward

A share is never limited to the single place you pick. It covers everything beneath it — the whole branch, down to the bottom. The Access tab states this plainly: "Sharing always includes everything below it."

Entries follow the same rule. Because every entry is filed somewhere in the directory, a share opens the entries filed anywhere beneath the place you pick. Share high in the directory to open a wide slice of your data at once, or lower down to keep the view narrow.

The cascade is built in and cannot be switched off. There is no setting to share one place on its own — see Access and sharing for how roles and shares combine to decide what a person can reach.

Removing access

To take back a share, return to the Access tab and select the same place. Find the person in the list of who can access it, and remove their access to that branch.

Removing a share also removes their access to everything beneath it, because that access was the whole branch and not the single spot. Their role stays untouched. If the person can still reach it afterwards, the access is coming from their role or from a share higher up the directory.

When you are not sure where someone's access comes from, look it up rather than work it out by hand. The access explorer shows, for any person, which branches they can reach and where each grant originates. Every share and removal is recorded, so you can review the change under the Activity tab.

Related

Need a hand? support@techly.au

Pyron Documentation