Per-process access, separate from app-scoped permissions. Lets a run be opened to people who could not otherwise see it.
UI: ProcessSharingPanel.tsx in the process runner.
API: /api/process/{id}/sharing.
App grants answer "may this person use processes at all." Sharing answers "may this
person see this run." A user with only processes:read sees their own runs; sharing is
how a specific run reaches someone else without granting them processes:read_all.
defaultVisibilityWhat a declared app member with the URL can do.
| Value | Effect |
|---|---|
none | Default. Link alone grants nothing. |
viewer | An authenticated app member with the link may read. |
contributor | An authenticated app member with the link may read and act, subject to step/field gates. |
Neither link visibility nor an assignment bypasses the required application membership boundary. Anonymous/nonmember access is denied by the deployment host even if middleware admits an optional-auth request to the handler. This is an intentional cutover access difference, not automatic preservation of old public links. See application access.
| Field | |
|---|---|
userId | Auth0 sub |
role | viewer or editor |
displayName, email | Captured at assignment time for display |
Members come from /api/org/members, which resolves declared collaborators across affiliations.
Three role words are in play and two are near-synonyms:
defaultVisibility: none │ viewer │ contributor assignment role: │ viewer │ editor
contributor (link) and editor (assignment) both mean "may act," but the words differ
by mechanism. viewer means the same thing in both. They are separate types —
ProcessSharingDefaultVisibility and ProcessSharingRole — not one shared enum.
Every process starts closed:
sharing: { defaultVisibility: "none", assignments: [] }
Set in startProcess. Nothing is shared unless someone shares it.
Sharing is checked in lib/require-process-read.ts and
lib/require-process-write.ts, which resolve access from four sources:
triggeredBy)processes:read_all)defaultVisibility — inside verified app membershipSharing widens access. It never narrows it: an admin with processes:read_all sees
every run in that app regardless of its sharing settings.
ProcessSharingVisibility ("private" | "public") is deprecated. Old documents are
migrated on read in getProcessSharing. Do not write these values.
Contributor links widen access for authenticated principals; they do not permit anonymous writes. Sharing is process-specific, not organization-level isolation. There is no general expiry or retention policy attached to a link; revocation changes the sharing configuration. Treat public links and assignment changes as explicit access decisions, and test direct requests as well as UI.