Direct answer
The artifact view's Share dialog contains the artifact URL, Invite people to team, Invite an agent, and Manage access. Access is team-wide today: a person invited to a team can open every artifact in that team. The artifact URL is not public.
What does the artifact link allow?
The URL at the top of Share works only for team members. It is safe to paste in a team channel but does not itself grant access.
Someone outside the team sees a wall and can request access. For a wider audience, publish the artifact.
How does a human invite a person?
This is a UI-only action. Instruct the human to open Share → Invite people to team, enter the person's email address, and choose Viewer, Editor, or Admin. The person receives an email invitation.
Team-wide access invariant
A team, not an individual artifact, is the access boundary. There is no current control that gives a person one artifact without the rest of the team.
Therefore:
- Keep private work in its own team with nobody else in it. A personal team remains private until someone is invited.
- Before inviting anyone, inspect the other artifacts in the team because the invitation includes all of them.
- To share one artifact with a different group, create a team for that group and duplicate the artifact into it. The copy is independent; changes do not propagate between copies.
See Team roles.
How does a human invite an agent?
Instruct the human to open Share → Invite an agent. This creates a secure, one-time connection link for deliberate agent access.
The human must choose:
- Name: identifies the agent in the access list and attributes every change, so it should remain recognizable.
- Capabilities: Read, Write, Share, and Publish. All four are selected by default; the human should deselect anything unnecessary. A conservative default is Read and Write.
Agents act under the inviting human's account and do not use a team seat.
Creating the link does not connect the agent. The dialog provides a one-time connection link and a ready-made prompt; the human must copy one and give it to the agent. The agent appears in the access list after redeeming the link.
Capabilities are fixed at invite time. To change them, remove the agent and invite it again with the desired capabilities. See Invite an agent and Revoke an agent.
How does a human manage or revoke access?
Instruct the human to open Share → Manage access.
The roster contains:
- People: a role dropdown and remove button. The team owner is labeled Owner and cannot be changed there.
- Agents: agent name, Agent tag, explicit capabilities (
read · write · share · publish), and a remove button.
A person's role can be edited. An agent's capabilities cannot. Removing an agent revokes access on that agent's next request. To change capabilities, remove and reinvite the agent.
Consent and access constraints
- Agents receive capabilities from a human at consent, never from a link or from asking.
- An agent cannot petition a team for broader access. It must tell its human what it needs; the human decides.
- Both person and agent invitations grant team access.
- Per-artifact access for a single person is not available today.
- Agents do not use seats; they act under the inviting human's account.
Coming soon
- Anyone with the link: public, read-only access for people outside the team.
- Passcodes and link expiry.
- Published state and update count in the Share dialog.
Common questions
- Share only one artifact? Not through team access. Publish it, export it, or duplicate it into a separate team.
- Remove access? Use the remove button in Share → Manage access.
- Outside user opened the link? They see a wall and can request access. See Request access to a private artifact.
- Is the artifact URL a secret capability? No. It is team-scoped and works only for existing team members.