Portablemind
Portablemind
Docs
Open Portablemind
Collaboration

Workspace Sharing

Give users from other organizations access to your workspace.

Workspace sharing lets users from one Portablemind organization work with another organization's content — with real, role-controlled permissions. Two companies collaborating on a project can grant each other's people exactly the access they need, while each organization's data stays isolated and under its own control.

This is the right model when your collaborators already have their own Portablemind organization — partners, service providers, agencies. If you're bringing in someone who's new to the platform entirely, start with Guest Users instead; that page also has a side-by-side comparison of the two models.

What workspace sharing gives you

  • A formal request/accept flow — sharing between organizations is established deliberately, by mutual agreement, never unilaterally.
  • Resource-level access — you share the specific things the collaboration needs — a conversation, a project, a folder — not your whole workspace.
  • Role-based permissions — everything a visiting user can see or do is controlled by the access levels on each share and the security roles and capabilities the host grants.
  • Work from your own workspace — content shared with you appears inside your own workspace; you don't log out or move somewhere else to reach it.

Core concepts

Sharing relationships

A sharing relationship is a formal link between two organizations. It moves through a small set of statuses:

StatusMeaning
PendingRequested, awaiting the other organization's acceptance
ActiveAccepted and functional
SuspendedTemporarily paused
RevokedPermanently ended — the access it granted is removed

Tip: Revoking is permanent — it's a hard unshare, and re-establishing access afterwards requires a brand-new invitation.

Hosts and guests

In any relationship there are two sides:

  • The host organization is the one granting access to its content.
  • The guest users are the people from the other organization who receive that access.

Host users only ever see their own workspace — they provide access, they don't receive it. Guest users work from their own workspace, where the content shared with them appears alongside their own.

Roles and shares control everything

A relationship on its own is not enough to see a host's content. What a visiting user can actually reach is determined by what the host shares and the permissions attached — each share carries an access level, and the host's security roles and capabilities govern everything beyond it, using the same permission system that governs the host's own members.

The sharing workflow

Establishing a partnership between two organizations works like this:

  1. Invite — from the Partners page (Administration → Partners), an administrator clicks Invite Organization and enters the email address of a contact at the other organization. There's no directory to browse — invitations always go to a specific email address.
  2. Accept — the other organization sees the incoming request in the Pending section of its own Partners page and accepts (or declines) it. The relationship becomes active.
  3. Share and grant — access to actual content is granted by sharing specific resources — conversations, projects, files — with the partner, and by the roles and capabilities the host assigns. Until something is shared, there's nothing for the partner to see.
  4. Access — the partner's users now see the shared content from inside their own workspace, within whatever their access levels allow.
Request and accept a workspace share

For API-level details, see the API guide.

Where shared content appears

Your top bar always shows which workspace you're working in, with an Owner or Guest badge indicating your role there. Content shared with you from another organization doesn't require moving anywhere: it appears directly inside your own workspace, filtered by the permissions you hold on each shared resource. The workspace menu also links to Workspace Sharing, which opens the Partners administration page.

If someone shares content with a person who doesn't have a Portablemind account yet, the share invitation email walks them through creating their own workspace — and the pending shares activate as part of signup.

Accept a workspace share

Ending a share

Relationships don't have to be forever. From the Partners page, opening a partnership's Manage dialog offers Revoke — a permanent, hard unshare: the access granted through the relationship is removed in one step. If the organizations want to collaborate again later, they start over with a new invitation.

Security model

Workspace sharing is designed so that collaboration never weakens isolation:

  • Deliberate grants required — no user can touch another organization's data unless that organization explicitly shared it with them.
  • Role-gated access — every action a visiting user takes is checked against the access levels, security roles, and capabilities the host granted. There is no implicit access.
  • Resource-level granularity — access is granted share by share, role by role — never wholesale to an entire workspace.
  • Audit trail — every relationship change and access grant is logged.
  • Clean revocation — revoking a relationship removes the access it granted in one step, so nothing lingers.
  • Guest Users — invite brand-new users into your workspace with scoped access, and see how guests compare to workspace sharing.
  • Tickets and Partners — partner onboarding and cross-organization ticket management built on top of workspace sharing.
Guest UsersCommunications Hub