Skip to content
kmem

Control who can read a doc

Each doc has a visibility level. The level decides which people and which agents can read the doc. This page explains each level and tells you how to share a doc.

The visibility levels

kmem asks two questions about each doc and each folder:

  1. Which people can open it?
  2. Can connected agents read it?

The Share dialog and the New doc page ask both questions. The answer to the first question is one of these levels:

LevelWhich people can open it
Everyone in AcmeEvery member of the org. The label shows the name of your org.
Same as engineeringThe people who can open the folder above it. The label shows the name of the folder. kmem shows this level for a doc or a folder inside another folder.
Only people you chooseOnly the people and groups that you add. Owners can always open it.
Only ownersOnly the owners of the org.

A box answers the second question. For a doc, the box is Connected agents can read this doc. For a folder, it is Connected agents can read the docs in this folder.

kmem stores the answers in the Markdown of the doc, or in the _folder.md file of the folder. It shows the result as one word in Docs and in the Details panel:

WordWhich people can readWhich agents can read
OpenEvery member, or the people on the listA connection of a person who can open the doc
SealedEvery member, or the people on the listNo agent
PrivateOnly ownersNo agent
EscortedEvery member, or the people on the listNo connection that you can make today. kmem no longer offers this level for new docs, but a doc from an earlier time can have it.

When you clear the agents box, kmem makes the doc Sealed. When you select the box, the doc takes the level of its folder. That level is Open, unless the folder keeps its docs away from agents. Only owners makes the doc Private.

A folder passes its level to the docs in it. A doc can be stricter than its folder, but not less strict. When a doc and its folder disagree, the stricter level applies. The Visibility row in the Details panel tells you when this happens, and what to change.

Choose a level for a new doc

The New doc page asks Who can open this doc before it creates the doc.

  1. Select a level.
  2. If you selected Only people you choose, add people and groups. The next sections explain how.
  3. Select or clear Connected agents can read this doc.
  4. Complete the rest of the page, and select Create doc.

A doc in a folder starts with the level of the folder, for example Same as engineering. The doc then follows the folder when somebody changes the folder.

A new doc from an upload or from an agent follows its folder.

Change the level of a doc

You can change who can open a doc when you can open and edit the doc.

  1. Open the doc.
  2. Select Share at the top of the doc. In a narrow window, select Doc actions, then Share.
  3. Select a new level.
  4. Select or clear Connected agents can read this doc.
  5. Select Save access.

kmem says Access to Deploy process saved. with the title of the doc. You can also open the dialog from the menu of the doc in Docs.

If you have unsaved changes in the editor, kmem asks you to save or discard them first.

If another person changed the doc while the dialog was open, kmem says so. Close the dialog and open it again to see the current settings.

Share a doc with people and groups

  1. Open the Share dialog of the doc.
  2. Select Only people you choose.
  3. Under People and groups, find the people and the groups:
  4. Type a name, an email address or a group name in Find a person or a group.
  5. Select the box beside each person or group that can open the doc.
  6. A group row shows the number of its members, for example Group, 3 members.
  7. Select Save access.

The list shows you and the owners of the org. You keep your access, and owners can always open the doc.

If the org has no groups, kmem says so. Owners and admins create groups in the org settings. Read Create a group.

If the doc is in a restricted folder, the list shows only the people who can open that folder. A doc can narrow the list of its folder. It cannot widen it.

A list can have at most 200 entries. For a larger set of people, share with a group.

After you save, the doc shows a Restricted chip. Select the chip to see who can open the doc.

Rules for the list

  • If a change removes access from members, kmem tells you how many before you save.
  • You cannot remove your own access. kmem stops the change and tells you how to fix it.
  • Only an owner can choose Only owners.
  • An agent can never change who can open a doc.
  • kmem stores the list in the Markdown of the doc. The history of the doc and every export show it.

Share a folder

A folder has the same Share dialog as a doc. The settings apply to every doc in the folder.

  1. In Docs, open the menu of the folder, or open the folder.
  2. Select Share.
  3. Choose the level, the people and groups, and the agents box.
  4. Select Save access.

A doc in the folder can narrow the settings of the folder. It cannot widen them.

Restricted folders

A restricted folder is a folder with Only people you choose. A person who is not on its list sees nothing of the folder: no doc, no count and no name. Restrict a folder explains the rules.

What agents can read

An agent reads your docs through a connection. A connection has these limits:

  • It reads only docs that are Open. It never reads a Sealed, Private or Escorted doc.
  • It follows the access of the person who made it. If that person cannot open a doc, the connection cannot read the doc.
  • It stops when the person who made it leaves the org, or when an owner or an admin removes that person.
  • It never reads docs of another org.

For example, only the Support group can open the support folder. A connection that a person outside the group made cannot read the support folder, even if the folder is Open.

A person who cannot open a doc does not see it in Ask either. Ask reads with the access of the person who asks.

Read Connect agents for the other limits of a connection.

Check who can read a doc

Use one of these ways:

  • Open the Details panel of the doc. Properties shows Visibility, with the level and where it comes from. The row can say set on this doc or inherited from and a folder name. It also shows who can open the doc.
  • Open the Share dialog. It shows the level, the people and groups, and the agents box.
  • In Docs, look for a Restricted chip on a doc, or a lock mark on a folder.
  • Above the list of a folder, kmem shows one line when the folder is not Open. For example, the line can say that agents cannot read the docs in the folder.

Next steps