Access to shared content
Every shared link in ApptiveGrid is reachable by default by anyone who has the link. If you want to restrict access, you have to set that up explicitly.
The most important point first
A share link isn't guessable, but it's unprotected. If it gets forwarded, copied into a chat, or quoted in an email, it keeps working there too.
Treat an unrestricted link like a publication.
Two different models
ApptiveGrid has two separate restriction models. Which one applies depends on what you're sharing. This is the most common source of confusion in this area.
| You're sharing … | Model | Dialog |
|---|---|---|
| Form | Who may access — by account | Set access restrictions |
| View or page/portal | Username and password | Set access permissions |
The two models can't be mixed. A form link doesn't know about a password, and a view link doesn't know about account checks.
Forms: access by account
In a form's share dialog, Set restrictions leads to the Set access restrictions dialog, with the question Define who can access the form via this link.
Three levels:
Anyone
Anyone with this link can access it.
No sign-in required. The default.
Suited for: public sign-ups, contact forms, surveys, feedback from customers.
Any registered user
Only registered users can access it with this link.
The person needs an ApptiveGrid account and must be signed in — but does not need to be a member of your Space.
Suited for: forms where you need a traceable identity, but the people filling it in don't belong to the Space.
This is a low bar
Anyone can create an ApptiveGrid account. This level ensures someone is signed in — not that it's the right person. It's not enough for confidential data.
Anyone in this Space
Only people invited to this Space can access it.
The strictest level. Only people with a role in this Space.
Suited for: internal forms — vacation requests, incident reports, internal data entry.
Any role is enough
Even the Read only role is enough to fill in a form restricted this way. You don't need to give anyone editing rights just so they can submit a form — and doing it this way doesn't consume a seat either.
Views and portals: username and password
When sharing a view, or publishing a page, Set restrictions leads to the Set access permissions dialog, with the text Define who has access.
Two levels:
Everyone
Anyone with the link can access it
The default. No protection beyond the link.
With credentials
Access only with username and password
You set a username/password pair. A sign-in prompt appears when the link is opened:
Welcome!Let us unlock this view. Enter the credentials below.
Username and password are entered there and confirmed with Login. If the details are wrong, you'll see Please check username and password; if they're missing entirely: Username is required or Password is required.
These credentials have nothing to do with ApptiveGrid accounts. It's a standalone pair that only applies to this link. Recipients don't need an account.
Credentials are only visible once
After saving, ApptiveGrid confirms with Permissions updated and explicitly points out:
For security reasons, it's not possible to view the username and password later. However, you can reset them at any time.
Note the credentials down somewhere safe immediately. If they get lost, you'll need to set new ones and send them to all recipients again.
One password per audience
Via Add link, create several links to the same view and give each its own credentials. That way you can revoke access for one group without having to send a new password to everyone else.
What a view's filter does — and doesn't do
When sharing a view, recipients only see what's visible in that view. Filters and hidden columns take effect as well.
Filters are a visual screen, not access control
For genuinely confidential data, don't rely on filters and hidden columns alone. Combine them with an access restriction.
For true separation, the cleanest solution is to not put sensitive data in the same Grid in the first place.
Choosing the right level
| Situation | Recommendation |
|---|---|
| Public sign-up form | Form, Anyone |
| Customer feedback via QR code | Form, Anyone |
| Internal form for the team | Form, Anyone in this Space |
| Status overview for a customer | View, With credentials |
| Public portal | Page, Everyone |
| Portal for partners only | Page, With credentials |
| Personal or confidential data | Don't share via link — invite people to the Space instead |
Check regularly
Shared links get forgotten. The External links at a glance page lists all external access points of a Space in one place: form links, view links, portals, Flow starts, and invitations.
Make it part of your routine
Review this list at regular intervals and remove what's no longer needed — especially after finished projects, ended campaigns, and personnel changes.