Help · Link security

Share OpenWiki capability links safely

An OpenWiki link can carry more than location. Some capability URLs grant feedback or decision authority, so choosing the correct link is part of the security boundary.

Updated August 3, 2026Product documentation

Read-only links

Use the canonical reading URL for a living publication and an immutable version permalink for a fixed citation or approval record.

Authority-bearing links

  1. Feedback capability: lets the holder submit governed feedback.
  2. Review capability: lets the holder approve, request changes, or reject a candidate.
  3. Edit or management capability: grants a control action and must not be treated as a public reading URL.

Avoid accidental disclosure

  1. Do not paste capability URLs into public issues, screenshots, analytics, or indexed pages.
  2. Send the narrowest capability to the intended person.
  3. Revoke a share link when it was sent to the wrong place.
  4. Use a version permalink when the recipient only needs evidence.

Search indexing remains separate

Capability pages, candidates, Private publications, and Unlisted publications remain noindex. A Public canonical publication still needs the separate indexing choice and quality gates.

FAQ

Frequently asked questions

Is a long capability URL safe just because it is hard to guess?

It should still be handled as a secret. Anyone who obtains the URL may receive the authority encoded by that capability.

Which link should I put in release notes?

Use a canonical reading URL for a living document or an immutable version permalink when the release note must identify an exact revision.

Use the real workflow

Publish what your agent creates.

Give every report, document, or plan its own reader-ready page. Comments, review decisions, and formal revisions can flow back from there.