Sharing is how work leaves the team without leaving the product. One post or one report is opened by somebody outside the team, read-only, on the same screen your team uses. There are two ways to hand that over, and one share uses exactly one of them: you name the people who may open it, or you turn on a link that opens for anybody holding the address. Named people can also approve a post, reject it, ask for changes and leave comments, if you allowed that when you shared it. Somebody arriving on a link only reads. The publishing overview lives on Publishing and Scheduling; this page is the instructions.
Before you start
Every share panel opens on the same question, Who can open it, with two tiles. Specific people stands first and is the one already selected: access is granted to an email address, and anybody who has not been named cannot open the item even with the address of the screen in front of them. Anyone with the link is the second tile: a single address opens the item for whoever holds it, with no account and no sign-in.
The two tiles exclude each other. One share is one of them, and the server refuses a share that carries both a people list and a link. Giving a client a link and naming a reviewer means creating two shares, which is also the only honest way round it, because revoking one of them should not close the other.
Sharing a post for review follows your plan, because collecting a client's sign-off is a paid capability; the pricing page says which plans include it. Sharing a report does not follow it. The report was already paid for with credits, the grant shows the buyer exactly what the buyer already holds, and it collects nothing, so any plan can show one.
Inside the team, sharing is an Owner's or an Editor's act on both kinds of item. An Approver may read the work and decide on it, and may not hand it on to a fourth party.
Share a post for review
Open the post from Posts in the Social section. Its detail page carries a Client review card.
- Press Share. The panel opens on Who can open it, with Specific people already chosen.
- Type the addresses, one per line. Each line becomes one person's access.
- Under What they can do, decide whether they may comment, and whether they may approve or reject. Commenting is on by default and the decision is off by default, so a share is a read unless you say otherwise. The decision option is offered only while the post can still be stopped, which means while it is a draft or scheduled.
- Give the share a label if it helps you recognise it later, and choose when access expires. There is no never here on purpose, because a review is an event with an end. Pick one of the presets or type your own number of days.
- Press Give access.
Turning on the decision blocks publishing until an approval is recorded. The review step reports that as a blocker rather than as a failure, and the post's status card shows what it is waiting for. You can call the whole thing off from the same panel with Cancel review, which makes the post publishable again and stops any existing share from collecting a verdict.
Share a report
Open the report and use the ⋮ menu in its header, then Share. The panel is the same one in a shorter form: the two tiles, then addresses or a link, an optional label and an expiry.
There is no what they can do row here, and that is not an omission. A report has no approval flow and no comment thread, so a report grant is silent by design and the server keeps it that way whatever is sent to it.
Share with a link
Both panels carry the same second tile, Anyone with the link, and it behaves the same way on a post and on a report.
- Press Share and choose Anyone with the link. The address appears straight away, with a Copy button beside it. There is no waiting and no step that reads the link will be ready once you save.
- The share is written down when Create link is pressed, or at the first Copy, whichever comes first. A copied address is therefore never a dead one. Closing the panel without doing either leaves nothing behind, and nothing appears in the list below.
- Also send to (optional) takes email addresses, up to twenty per press, and mails each of them the link. Those addresses are not added to anybody's access list. They receive the same link a forwarded message would carry, which is why the box sits under the link rather than under the people list.
- A label and an expiry work exactly as they do for named people, and the link stops working on the date the expiry names.
The address is shown for copying only in the session that created it. What is stored is a hash of it, never the address itself, so nothing in the product and nothing in a database dump can hand it back. Once the panel is reopened, the share reports Link is on and offers two actions instead of the address: Turn off, which closes the link on the spot, and Make a new link, which mints a fresh address and stops the previous one working. There is no third action that recovers the old one, because it was never kept.
Whoever holds the address gets in. A link that is forwarded passes the access on with it, and there is no password and no code standing in the way. That is the trade this tile makes, and it is why the people list is the one selected by default.
What the client sees
Somebody arriving on a link needs no account and is not asked to sign in. The address opens the same post detail or the same report your team reads, in the same layout, with everything that changes the work taken out of the page and refused by the server as well. The header carries a Read-only marker and a Sign in button, and that is the whole of the chrome: no sidebar, no navigation, no team switcher, no credit balance. They cannot comment and cannot approve or reject, whatever the share was set to allow, because a comment and a verdict are recorded against a person and a link names nobody. They see nothing else belonging to your team, and a second item of yours is not reachable from the one they were given.
Somebody who is already signed in may open a link too. They read it as a link holder like anybody else, unless they hold access to that same item in their own right, in which case they keep it and keep whatever it allows them to do.
A named person is emailed as soon as you give access. Which mail they get is decided by one question and nothing else.
If they already have an account, the mail links straight at the post or the report. They sign in and land on it.
If they do not, the mail invites them to create one. The invitation is valid for a week, the address is filled in for them and cannot be changed, and the account is born already verified, because receiving that mail is the proof. It works even while public sign-up is switched off, since the agency addressed them by name. The invitation is good for one account. Once it has been used, a later click sends them to the sign-in screen instead of the form.
Once they are in, they see your screen, not a stripped-down copy of it: the same post detail or the same report, with a Read-only badge in the header naming the team that shared it. Everything that changes the work is absent, and the server refuses it as well, so nothing about the page is decoration. They see nothing else belonging to your team. Not your other posts, not your other reports, not your accounts, not your credits.
Everything shared with them collects on Shared with me in their sidebar, which appears only for somebody who actually holds a share. A client whose account exists for nothing else lands there when they sign in.
Reading the results
Results come from named people, since a link collects nothing. On a post, the client's panel sits under the work itself. They press Approve, Request changes or Reject, and a note is required for the last two. Comments are a thread on the same screen, visible to them and to the team.
Each decision and each comment emails one person on your side, the post's author, or the team owner if the author's account is gone. It is never the whole team, because a twelve-person agency taking twelve mails from one comment mutes the channel and there is no other one. The same activity is listed on the post's Client review card, so nothing depends on the mail arriving.
The client's list is bounded so a stuck browser cannot flood your inbox. On one share, one person may leave five comments a minute and cast ten verdicts a minute; past that the action is refused and nothing is written.
Manage who has access
The Who can see this list sits under the share panel on both screens and shows, for every address, whether that person has Joined or is still Invited, which is read off whether an account with a confirmed mailbox holds the address.
A share made with a link takes its own row there, labelled Anyone with the link unless you gave it a label of your own. The row names no people, because there are none to name, and carries Turn off and Make a new link rather than an address. Only saved shares are listed, so a link that was minted in the panel and never confirmed is not in it.
Resend mails the invitation again, and it always sends something that works rather than a copy of a mail that may have lapsed. One re-send per address every ten minutes, a few per address per day, and a ceiling per team per hour.
Editing the address list is the whole of access management. Adding an address grants access, removing one takes it away, and both take effect in the same check that lets everybody else in. Revoke shuts a share completely, and an expiry does it on a date. On a link share the same three controls are Turn off, Revoke and the expiry. All of them are immediate; there is nothing cached and nothing for the reader to be halfway through, including a reader who is sitting on the page when it happens.
One case surprises people, so it is worth stating. Access follows the address, so a client who changes the email on their account loses access, because you addressed a person at an address rather than whoever holds an account. Re-inviting the new address is the repair.
What this does not do
- One share is one way in. Named people or a link, never both on the same share. Two audiences need two shares.
- A link collects nothing. Whoever opens one reads it. Approval, rejection and comments stay with named people, because each of those is recorded against somebody.
- A link cannot be looked up again. The address is shown once, and only its hash is kept. Make a new link is the only way back to a working address, and it retires the old one.
- There is no password and no access code on a link. Holding the address is the whole of the permission.
- Reports collect nothing. No approval, no comments. A report share shows the numbers and stops there.
- The calendar cannot be shared. Grants point at one post or one report.
- There are no in-app alerts. Mail is the only push channel in this product, on both sides of a share.
- A client is not a team member. They take no seat, they spend none of your credits and they see no balance.
- Changing the address on a client's account does not move their access. It ends it.
When something looks wrong
The client says the item will not open. Check the address in the list against the address on their account, character for character, and check that the share is neither revoked nor past its expiry. Those are the only ways access ends. An address that reads as Invited means they have signed up but have not confirmed their mailbox yet.
The invitation has expired. Use Resend rather than re-adding the address. It mints a fresh invitation for the same access instead of a second one.
The decision buttons are gone but the post still opens. That is deliberate, and it happens when the review was cancelled, when the post has moved past scheduled, or when the plan that paid for sign-off no longer covers it. The work stays visible and the client is told the share is no longer collecting decisions, without being told anything about your billing. Comments are untouched.
They received two emails about the same item. Saving the same address list again mails nobody, so two mails mean the address was added twice across two separate shares. Revoke the one you do not need.
The link opens nothing. A link stops working for four reasons and no others: it was turned off, the share was revoked, the expiry passed, or Make a new link replaced it. Mint a fresh one and send that address. An address that was never confirmed with Create link or Copy was never saved either, so it opens nothing from the moment the panel closed.
The link has been lost. It cannot be read back, not from the panel and not from support, because only its hash was ever stored. Make a new link is the repair, and the old address stops working as soon as the new one exists.
The person on the link cannot comment or approve. That is deliberate and no setting changes it. Add them to a share by email address instead, and decide there whether they may comment and whether they may approve or reject.
Something else. Contact support with the address of the screen and the client's email address.