Using Gridline
Sharing and access
Admins and employees, company-wide and restricted files, how to share, and why a hidden file looks like it does not exist.
Gridline answers two questions about every file: who are you? and may you see it? This guide explains both, how to share a file with particular people, and one rule that surprises people: a file you may not see looks like it does not exist.
Two roles
A company has admins and employees. The person who registers the company is its first admin. Admins invite everyone else.
| Admin | Employee | |
|---|---|---|
| Upload files, read the ones they may see | Yes | Yes |
| See every file in the company | Yes | No: company-wide files, and ones shared with them |
| Change or delete a file | Any file | Only their own |
| Invite and remove people | Yes | No |
| Create, edit and delete quality rules | Yes | No (read only) |
| Plans, billing, analytics and the audit log | Yes | No |
| Webhooks | Yes | No |
| Their own API keys | Yes | Yes (fewer scopes) |
Your role is checked on every request, not remembered from when you signed in. When an admin changes your role or removes you, it takes effect on your very next click.
Who can see a file
Every file has one of two visibilities:
| Visibility | Who sees it |
|---|---|
| Whole company | Everyone in the company. This is the default. |
| Restricted | The person who uploaded it, every admin, and the colleagues it is shared with. Nobody else. |
This is one rule, applied the same way everywhere: the file list, a single file, its report and preview, its download, its comments, live updates and AI agents. There is no side door.
Share a file with particular people
Open the file
Only its uploader and admins see the Sharing button.
Choose Sharing
A box opens: Who can see this file.
Choose Only people I choose
A list of your colleagues appears.
Tick the people
Each person you tick can see the file. The list replaces who had access before, so untick someone to take their access away.
Save
It takes effect on the next thing anyone does. Each person newly added is told a file was shared with them; you are not.
To open a file back up, choose Everyone in the company and save. That clears the list.
- People you pick must be active members of your company.
- Only the uploader and admins can see who a file is shared with.
- Sharing a file never gives anyone any other file, and mentioning someone in a comment never gives them access.
Versions
A new version starts with the same access as the file it joins, plus the person who uploaded it. After that, each version's access is its own.
Hidden means not found
If you open a file you may not see, Gridline shows the same not found page as for a file that does not exist. That is deliberate: even saying “you are not allowed” would tell you that a file with that address exists.
You only get a “not allowed” message when you can see a file but are not allowed to change it, because you are neither its uploader nor an admin. In practice you do not see the buttons at all.
From code
Sharing is available over HTTP too: see Files, versions and reports. What an API key may do is covered in API keys and scopes: a key never has more power than the person who made it.