> ## Documentation Index
> Fetch the complete documentation index at: https://docs.runlayer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Share and control access

> Share artifacts within your organization and understand direct and inherited permissions.

Artifact links require authentication to your Runlayer organization. Recipients
also need permission to view the artifact; copying a link does not grant access.

## Share an artifact

1. Open the artifact and select **Share**.
2. Add people, groups, teams, or roles from your organization.
3. Choose the appropriate permission, then copy the link from the sharing panel.

| Permission   | What it allows                                                   |
| ------------ | ---------------------------------------------------------------- |
| **Can use**  | View and download the artifact.                                  |
| **Can edit** | Manage artifact access, edit tags, and restore earlier versions. |

Replacing or editing file content through Runlayer MCP still requires ownership
of the standalone artifact. See [Create and update](/artifacts/create).

Under **General access**, owners and admins can choose **Everyone at
\[organization name]** to share with the organization, or **Only people invited**
to limit direct access to invited recipients. Organization-wide access still
requires sign-in.

## Access inherited from an agent

For agent-created artifacts, the originating agent's **Artifact sharing** setting
also grants access. Open **Artifact sharing settings** on the agent's detail page
to review it.

| Agent setting                          | Access granted through the agent                                                                 |
| -------------------------------------- | ------------------------------------------------------------------------------------------------ |
| **Only me**                            | The agent owner has access; other viewers receive no access through this setting.                |
| **Everyone with the link**             | Members of the same organization can open the artifact link. This is the default for new agents. |
| **Everyone with access to this agent** | Access follows the agent's own sharing permissions.                                              |

The artifact creator retains ownership, and administrators with **Manage Agents**
can manage artifacts. Direct artifact shares can grant access in addition to the
agent's setting.

<Note>
  Access is cumulative. Removing a direct invitation does not revoke access
  someone still has through a group, team, role, organization-wide share, or the
  originating agent. Review those sources when restricting an artifact.
</Note>

An artifact created through Runlayer MCP has no originating agent, so its access
does not inherit an agent's sharing setting.

## Sharing outside your organization

Artifact sharing currently supports authenticated members of your Runlayer
organization. It does not provide anonymous public links or access for external
stakeholders simply by sending them a URL.

## If a recipient cannot open the link

* Check that they are signed in to the correct Runlayer organization.
* Review the artifact's **Share** panel and, for an agent artifact, the originating
  agent's sharing settings.
* Ask an administrator to check that the recipient has **Use Agents** or
  **Manage Agents** access.
* Confirm the artifact has not been deleted.

See [Roles & Permissions](/platform-roles) for workspace permissions.
