Sharing, invitations, and publishing
Keep private participation, workspace membership, and public snapshots as distinct access decisions.
Atoi separates three actions that are easy to conflate:
| Action | Effect | Audience |
|---|---|---|
| Invite to conversation | Grants participation in one private conversation | Named or link-invited people |
| Invite to workspace | Grants workspace membership according to the selected role | Workspace members |
| Publish | Creates an explicitly public, view-only representation of selected content | Anyone allowed by the publication setting |
[!WARNING] This access model is still rolling out across clients. Read the confirmation shown by the current product as authority; do not assume every preview control is available on every surface.
#Invite to a conversation
A conversation invitation scopes access to that conversation. It does not reveal the host’s Library, other conversations, connections, projects, or account settings by default.
Before inviting, review the visible history: participants can read the conversation they join. If people are allowed to steer Atoi in that conversation, the host controls the grant and the product discloses whose connection funds the resulting model use.
Revoking an invite link prevents new joins. Removing a participant ends that person’s access without erasing messages they already contributed.
#Invite to a workspace
Workspace membership is for persistent collaboration. Roles govern workspace-level administration; projects do not create a second membership system. A pending invite is not an active member.
Promotion from conversation participant to workspace member requires consent. Never infer workspace access from an email match or a public share.
#Publish a snapshot
Publishing is an outward-facing action. Review the selected content, title, visibility, redaction receipt, and optional expiry before confirming. A public snapshot is view-only and does not make its visitor a project member.
The Shared links and permissions checklist provides the practical pre-publish review.
#Revoke the correct thing
Remove a participant to end their private access. Revoke an invitation link to close that door. Unpublish or revoke a public share to end publication. These are separate objects and should have separate confirmations.
Verification sources
- docs/decisions/2026-08-23-share-invite.md
- docs/decisions/2026-08-23-organizing-model.md
- packages/contracts/fixtures/atoi-client-capabilities.v1.json
Was this useful?