External Guest Access
Invite someone outside your workspace to view a single source or folder, with optional expiry, without making them a workspace member.
External guest access lets you share exactly one source or folder with someone outside your workspace — a consultant, vendor, auditor, or short-term reviewer — as a Viewer, optionally until a date you choose. They get to the shared item through a minimal "shared with me" experience, and nothing else: no workspace sidebar, no other sources, no workspace settings.
An external guest is not a workspace member. Inviting someone as a workspace Viewer would let them see every workspace-visible source and the broader workspace. An external guest sees only what you explicitly share with them.
When to use it
| Situation | Use |
|---|---|
| Someone outside the company needs to view one source or folder | External guest access |
| Someone outside the company needs to edit source or artefact content | Invite them as a workspace member, then add restricted source/folder access if needed |
| A teammate should join the workspace and see workspace-visible content | Invite them as a workspace member |
| An existing workspace member needs a restricted source or folder | Add them through restricted access members, not a guest invite |
External guests get Viewer access only. Access can carry an optional expiry; workspace membership does not.
Invite an external guest
- Open the source or folder's Settings.
- Go to the External access tab.
- Click Invite external guest.
- Enter the person's email address.
- Optionally set an access expiry date and add a short message.
- Send the invitation.
The guest receives an email with an accept link bound to that email address — it only works for the address you invited. Accepting creates their access; it never adds them to Members.
Folder invites cover the folder and its contents. When you invite someone to a folder, they get access to that folder and everything inside it — sub-folders and sources. Items outside the folder stay private to the workspace. There is no hidden inheritance: the invite, the email, and the shared view all say "folder and its contents" explicitly.
Integrity checks eligibility before sending, so you can't accidentally create duplicate or conflicting access:
- Already a workspace member — you'll be pointed to the Members tab to manage their access there instead. Workspace members don't receive guest invites.
- Already has access, or already invited — Integrity surfaces the existing grant or pending invitation rather than creating a duplicate.
- Already covered by a folder grant — if the person already has access through a parent folder, a redundant source invite is blocked.
Set or change expiry
Expiry is optional. A guest with an expiry keeps access through the end of the chosen day, then loses it automatically — you don't have to do anything when the date passes.
From the External access tab you can:
- Extend an expiry by 7 or 30 days.
- Clear the expiry to make access permanent.
Expiry is enforced the moment it passes, independent of any background job. An expired guest is denied access immediately; the expired grant is kept in the logs for audit history, not deleted.
Revoke access
Revoking removes the guest's access immediately. Their next page load shows an access-ended state. You can re-invite the same person later if you need to — revoking doesn't block a future invitation.
Manage external guests
The External access tab is a current-state view. It lists:
- Active external guests, and
- Pending invitations that haven't been accepted yet.
Expired and revoked access isn't shown as a dead row here — that history lives in the Logs tab, which records every invite, acceptance, expiry change, and revocation.
What the guest sees
An external guest signs in and lands on a minimal shared experience — just the source or folder you shared, as a Viewer. The workspace sidebar, settings, members, and every unrelated source stay hidden. For a shared source they get the artefact table and available read-only table controls; for a folder, the folder and its contents.
Everything shared with a person is gathered under Shared with me, so a guest with access to several scopes can find them in one place.
When access ends — revoked or expired — the guest sees a clear access-ended message that does not reveal the name or contents of what was shared.
FAQ
Does an external guest become a workspace member? No. They never appear in the workspace Members list and never gain workspace-visible content. Their access is limited to the single source or folder you shared.
Can a guest see other sources in the workspace? No — only the source or folder you shared (and, for a folder, its contents).
What happens when access expires? Access ends automatically at the end of the expiry day. The grant is retained in the logs for audit history.
How is this different from a restricted source member? Restricted-source membership assumes the person is already a workspace member, and it has no expiry. External guest access is for people outside the workspace and supports optional expiry.
Can I re-invite someone after revoking? Yes. Revoked history doesn't block a new invitation for the same person.