A person's role sets what they can reach across the whole of Pyron; sharing is the more targeted layer on top. It hands one person access to a single part of the tree, without changing anyone else's role.
Sharing part of the directory
If you can manage access to part of the directory, you can share it with a specific person. Sharing is a direct grant: you choose the place, the person, and what they are allowed to do there. It stands apart from roles, so it changes what that one person can reach and nothing else.
When you share, you decide how far the person's access goes:
- See it and the entries filed against it.
- Add new entries.
- Edit what is already there.
- Remove entries.
Seeing is the floor. Every share includes the ability to view, and you build any adding, editing or removing on top of that — you cannot grant someone editing without also letting them see what they are working on.
You can only share access you hold yourself. To share you need permission to manage that item's access, and you can pass on only the actions you are allowed to perform there. That keeps a share from ever handing someone more than the person sharing it already has.
Sharing can start from the directory itself, or from the central access controls an administrator uses; either way you pick the person and the actions. For the exact steps, see directory sharing.
Access flows down the tree
A share is never limited to the single place you pick. Access includes everything beneath it — the whole branch, down to the bottom. Share a region and the person reaches every site and area under it; share one site and they reach only that site and its contents.
The same holds for entries. Because every entry is filed somewhere in the directory (see Entries), sharing also opens the entries filed anywhere beneath the place you share. Grant access high in the directory to open a wide slice of your data at once, or lower down to keep the view narrow.
Because of this, share at the level that matches what the person is responsible for. Pick the smallest branch that still covers everything they need, and the rest of the tree stays out of their view.
Checking who has access
Access reaches a person from two places: their role, and anything shared directly with them. When both layers stack up, the surest way to know what someone can reach is to look it up rather than work it out by hand.
Administrators can do this from the access explorer under administration. It answers the question both ways round:
- For a person, it shows which parts of the tree they can reach and what they can do there.
- For part of the directory, it shows who can reach it and where that access comes from.
This is the place to confirm a share landed the way you meant it to, or to check why someone can or cannot see a branch. For the full walkthrough, see the access explorer guide.