Minimize the artifact before access control
- Remove secrets, tokens, private paths, and unrelated conversation context.
- Inspect images for visible credentials or personal data.
- Import media through the metadata-stripping workflow.
- Include only evidence the recipient is authorized to see.
Choose visibility independently from capability
- Private for authorized account or capability access.
- Unlisted for intentional link sharing without public promotion.
- Public only for deliberately tokenless reading.
- Search-indexable only for maintained Public work.
Send the narrowest link
A view link is for reading. A feedback link grants comment authority. A review link grants decision authority. An owner or management capability must never be used as a public reading URL.
Respond to accidental exposure
- Revoke the exposed capability.
- Issue a replacement only if access is still needed.
- Inspect access and publication state.
- Remove or revise the artifact if its content itself disclosed sensitive data.
FAQ
Frequently asked questions
Is an unlisted link safe to post publicly?
No. Unlisted reduces discovery but anyone who receives a capability may exercise its authority until it expires or is revoked.
Does metadata stripping remove secrets visible in a screenshot?
No. It removes metadata, not visible pixels. Inspect the image content separately.
Use the real workflow
Publish what your agent creates.
Give every report, document, or plan its own reader-ready page. Comments, review decisions, and formal revisions can flow back from there.