Remove a colleague's access
Remove a colleague’s access to one record, or to a folder’s key domain. Removal takes effect at once.
Who can do this: a domain owner, or a person with the Owner role.
The samples use the allowed helper from Access decisions.
1. Find who has access
domains.members lists the people and groups that hold the key domain. A record’s own recipients are on its entry, in recipients.
const membership = await client.domains.members(root);let membership = try await client.domains.members(root)val membership = client.domains.members(root)2. Remove access
// one recordawait allowed(await client.domains.unshareRecord(locator, colleague));
// a folder's key domainawait allowed(await client.domains.unshare(root, { person: colleague }));// one record_ = try await allowed(client.domains.unshareRecord(locator, from: colleague))
// a folder's key domain_ = try await allowed(client.domains.unshare(root, from: .person(colleague)))// one recordallowed(client.domains.unshareRecord(locator, from = colleague))
// a folder's key domainallowed(client.domains.unshare(root, from = ShareTarget.ToPerson(colleague)))What the colleague keeps after unshare
| Saved | Colleague can open it |
|---|---|
| Before the removal | Yes, on a device that already had access |
| After the removal | No |
unshare starts a new epoch. Versions saved after it use keys the colleague never receives.
Next
- Share for
Membershipand group shares. - People, devices and roles to remove a person from the whole tenant.