Skip to main content
All postsProduct

Who can see the file, and who can change it

Owner, editor, viewer. A link for your company, or for anyone who holds it. Access requests that grant nothing until someone says yes. How sharing works on the canvas, and the one rule under all of it.

1 min readThe Lindi team

Sharing a design file is easy to get wrong in both directions: too tight, and the people who need to comment cannot; too loose, and a link in a chat log grants edit rights to whoever finds it. This is how access works on the canvas, written down, because it had shipped without being written down.

Three roles, and the highest wins

Every file resolves one effective role for a person: owner, editor or viewer. The owner is whoever created it. Editors and viewers come from three places — a share to them by name, a link set to your company, or a link set to anyone who holds it — and the highest grant that applies is the one you get. A viewer can read and comment; an editor can change; only the owner can change who else can.

  • A share by name grants as soon as it is accepted, or immediately if the owner sent it
  • A company link grants everyone in your company the level you set
  • An anyone link grants only when the request carries the link’s own secret
  • A request for access is a pending row that grants nothing until it is approved
Three people in the file at once, each with the cursor and the level the owner gave them.

The rule under all of it

Nothing grants by accident. Asking for access looks, in the data, almost exactly like being invited — and the one field that tells them apart is checked every time, so that a request never behaves like an invitation until a person has said yes. Notifications ride on the same events, so the owner hears about the request, and the requester hears the answer.

The person who owns the product decides who touches it. That was true before Lindi and it is true inside it.

Reading about it is one thing. Lindi is open by request, and free for early users.

Request access