Спільний доступ до conversations і variants
Sharing API надає доступ view або edit до conversation/variant. Targets можуть бути individual user, group, organization, unit або team.
Лише conversation owner може create, change, list або remove shares.
Межа permissions
| Permission | Current conversation behavior |
|---|---|
view | Read shared conversation/variant і associated visible build metadata. |
edit | Includes shared conversation edits і rebuild-related access, реалізований conversation routes. |
Ці labels не автоматично grant кожну downstream action. Artifact download, VM launch, deployment, billing, secrets і organization administration можуть мати окремі owner і entitlement checks. Перевірте кожну required action сесією recipient.
Якщо та сама conversation доходить до user через кілька shares, accessible-list response обирає вище з view і edit.
Target rules
- Direct user shares resolve against organization membership.
- Groups, units і teams мають belong to relevant organization.
- Organization shares reach current organization members.
- Membership changes можуть змінити effective access без edit share.
Не використовуйте broad organization share, коли достатньо user або team share.
Безпечний workflow sharing
- Підтвердіть conversation ID і owner.
- Підтвердіть recipient target і current membership.
- Почніть з
view, якщо editing не required. - Create one share і inspect returned target і permission.
- Sign in as recipient і test allowed і denied operations.
- Remove або reduce access, коли task ends.
- Refresh recipient session і repeat denied-path test.
Не припускайте, що email або in-app notification sent. Communicate через approved channel без tokens або private artifact URLs.
Collaboration behavior
edit , authorization, не conflict resolution. Перед тим як двоє змінюють ту саму conversation, домовтеся, хто owns next recipe revision, і compare normalized output з full chat. Rebuild має бути tied to specific reviewed recipe, а не до edit, що прийшов останнім.
Review і offboarding
Periodically inventory:
- direct shares;
- broad group, unit, team і organization shares;
- stale memberships, що still confer access;
- resources, whose original owner left; and
- recipient access to old builds, downloads і VMs.
Removing share не necessarily delete copy, already downloaded recipient. Handle exported artifacts через data-classification і retention policy.