Share a record or folder with a colleague
Give a colleague access to one record, or to every record in a folder’s key domain.
Who can do this: a domain owner of the record’s or folder’s key domain.
The samples use the allowed helper from Access decisions.
1. Choose what to share
| To share | Call | Target |
|---|---|---|
| One record | domains.shareRecord | The record’s locator |
| A folder | domains.share | The key domain’s root locator |
You share a folder as its key domain. The colleague gets every record in the key domain, now and in the future. A folder that is not a key domain root cannot be shared alone. See Owners and sub-domains.
2. Share
// one recordconst shared = await allowed(await client.domains.shareRecord(locator, colleague));
// a folder's key domainconst sharedDomain = await allowed(await client.domains.share(root, { person: colleague }));// one recordlet shared = try await allowed(client.domains.shareRecord(locator, to: colleague))
// a folder's key domainlet sharedDomain = try await allowed(client.domains.share(root, to: .person(colleague)))// one recordval shared = allowed(client.domains.shareRecord(locator, to = colleague))
// a folder's key domainval sharedDomain = allowed(client.domains.share(root, to = ShareTarget.ToPerson(colleague)))3. Handle the decision
| Outcome | When | What to do |
|---|---|---|
allow | The colleague has access on every device they hold. | Nothing more. |
deny | The caller is not a domain owner, or the policies refuse the share. | Show text. |
challenge | The policies require a fresh multi-factor sign-in. | Call stepUp(), or use the allowed helper. |
Next
- Share for group shares and what each call returns.
- Remove a colleague’s access.