Skip to content

Remove a colleague's access

Remove a colleague’s access to one record, or to a folder’s key domain. Removal takes effect at once.

Who can do this: a domain owner, or a person with the Owner role.

The samples use the allowed helper from Access decisions.

1. Find who has access

domains.members lists the people and groups that hold the key domain. A record’s own recipients are on its entry, in recipients.

const membership = await client.domains.members(root);

2. Remove access

// one record
await allowed(await client.domains.unshareRecord(locator, colleague));
// a folder's key domain
await allowed(await client.domains.unshare(root, { person: colleague }));

What the colleague keeps after unshare

SavedColleague can open it
Before the removalYes, on a device that already had access
After the removalNo

unshare starts a new epoch. Versions saved after it use keys the colleague never receives.

Next