Ask for access to a record
Ask the owners of a record’s key domain for access after an open is denied. A domain owner answers the request with a share or a refusal.
The samples use the allowed helper from Access decisions.
Ask for access
Who can do this: any person of the tenant, for themselves. Guests and AI agents cannot ask.
1. Check the deny reason
You can ask only after a deny with reason not-a-member. Any other deny reason cannot be requested.
const opened = await client.objects.open({ locator });const canAsk = opened.outcome === 'deny' && opened.reason === 'not-a-member';let opened = try await client.objects.open(ObjectRef(locator: locator))var canAsk = falseif case .deny(let denied) = opened, denied.reason == .notAMember { canAsk = true }val opened = client.objects.open(ObjectRef(locator))val canAsk = opened is Decided.Deny && opened.reason == DenyReason.NOT_A_MEMBER2. Send the request
Pass the action, a reason code, and your own case or ticket id as an optional reference.
await allowed(await client.requests.ask(locator, 'view', reason, 'CASE-2291'));_ = try await allowed(client.requests.ask(locator, action: .view, reason: reason, reference: "CASE-2291"))allowed(client.requests.ask(locator, action = OpenAction.VIEW, reason = reason, reference = "CASE-2291"))The answer is requested whether or not the record exists. It never names an owner. A new request for the same record replaces the last one. A request lapses after seven days by default.
3. Wait for the answer
requests.mine() returns the person’s requests and their state: requested, approved, refused, lapsed or replaced. Once the state is approved, open the record again.
Answer an access request
Who can do this: a domain owner of the record’s key domain. The Owner and Admin roles do not see requests.
1. List the requests
const pending = await client.requests.toAnswer();let pending = try await client.requests.toAnswer()val pending = client.requests.toAnswer()2. Approve or refuse
Approve with a share that names the request in answering. The default is the record alone. An optional expiresAt ends the access at that time.
const r = pending[0];if (approved) await allowed(await client.domains.shareRecord(r.locator, r.person, { answering: r.accessRequestId, expiresAt }));else await allowed(await client.requests.refuse(r.accessRequestId));let r = pending[0]if approved { _ = try await allowed(client.domains.shareRecord(r.locator, to: r.person, answering: r.accessRequestId, expiresAt: expiresAt)) }else { _ = try await allowed(client.requests.refuse(r.accessRequestId)) }val r = pending[0]if (approved) allowed(client.domains.shareRecord(r.locator, to = r.person, answering = r.accessRequestId, expiresAt = expiresAt))else allowed(client.requests.refuse(r.accessRequestId))3. Handle the decision
An approval is an ordinary share, so the policies can deny it. A denied approval leaves the request open.
Next
- Share a record or folder with a colleague for the share calls.