Roles decide which objects a member can read or edit. Record-level sharing goes one step further: a single company, deal or other record can be restricted so that only chosen people see it. Record-level sharing is turned on per organization. Ask support to enable it for your workspace.

In the app

Open a record, then Share in the command menu (or the side panel):
  • Restrict: only the record’s creator, whoever restricted it, and people you share it with can see it.
  • Share with a member or a role, with Read, Read and write or Full access. Full access also lets them manage sharing.
  • Everyone can view: everyone can read it, editing needs a grant.
  • Back to default: the record follows its object’s normal access again.
The creator always keeps access to a record they created. Ownership can be transferred. Vault items are always private and use the same sharing panel. See Vault.

Through the API

Sharing is managed on the metadata endpoint (/metadata, GraphQL) with setRecordShare:
target is { objectMetadataId, recordId }. principal is one of everyone, workspaceMemberId or roleId. Use enabled: false to remove a member’s or role’s share, and principal: { everyone: true }, enabled: true, accessLevel: READ_WRITE to return a record to its default. Read the current state with the recordSharing(target:) query. Requests run as the caller: an API key or member can only see and share records they can already open.