Docs menu

Workspaces and sharing

Every app lives in a workspace. Your workspace is decided by your email address the first time you sign in, and nobody in it sees your apps until you share them.


Your workspace

A workspace holds your apps and pages. Its name is part of every app's address:

https://expense-notes.yourcompany-com.spryloom.app
        ^ the app     ^ the workspace

Each app name is used once per workspace, because it is part of the address.

spry whoami says which workspace you are in.


Company or personal

There is nothing to set up. Spryloom looks at where your email domain's mail is delivered, once, when the workspace is made.

Your email Your workspace
A work address whose mail runs on Google Workspace, Microsoft 365, Zoho Mail, Amazon WorkMail, Rackspace, GoDaddy, IONOS, Titan, Namecheap Private Email or Hostinger Your company's. The first person from acme.com to sign in creates the acme-com workspace, and everyone from acme.com who signs in after them joins it.
A personal address, such as Gmail, Outlook, Yahoo or GMX Your own. People at the same mail provider never share one.
A work address whose mail runs elsewhere, such as Fastmail, Proton, iCloud or the company's own servers Your own.

The two work the same. The only difference is visibility: company, which means "everyone at our domain", so it needs a company workspace. In a personal workspace, share apps with people by name instead.


Who sees which apps

Being in the same workspace shows nobody your apps. An app appears in someone's dashboard, and in spry apps, only once it is shared with them, the same way a document is private until you share it.

access.visibility in spryloom.yaml decides who:

visibility Who can open it Who sees it listed
private You and the app's admins You and the app's admins
invited You, the admins, and the people you invite The same people
company Everyone at your workspace's domain Everyone at your workspace's domain
link Anyone with the address, once they have signed in You and the app's admins only

A new app is private.

Someone an app isn't shared with is told there is no app by that name, and is never told whose it is. If they try to publish an app with the same name, they are told the name is already used in the workspace, and nothing more.

What people see once it is shared

People it is shared with You and the app's admins
Open the app ✓ ✓
Its name, what it does, who looks after it, what it stores ✓ ✓
Who else has access ✓
Versions, history and logs ✓
Secret names, and changing anything ✓

Sharing an app

With a few people

  1. Set the visibility and publish:

    access:
      visibility: invited
    
    spry publish .
    
  2. Invite them:

    spry invite expense-notes --email ryan@yourcompany.com --email sam@yourcompany.com
    

    Or use Invite a coworker on the app's page in the dashboard, or ask your agent. Each person gets an email saying who invited them and what the app does.

Invitations can go to people outside your company too: anyone with an email address can be invited to an invited app.

With everyone at your company

In a company workspace:

access:
  visibility: company
  domain: yourcompany.com

domain must be your workspace's own domain. Publish, and everyone at that domain can open it and sees it in their dashboard, without being invited.

Taking access away

spry uninvite expense-notes --email ryan@yourcompany.com

Their next click or refresh is refused, even if they are still signed in. This also cancels an invitation they haven't used yet.

To stop sharing with everyone, change visibility and publish again; it takes effect straight away.


Admins

You are the admin of every app you publish. To let someone else look after an app, add them to access.admins and publish:

access:
  visibility: invited
  admins: [priya@yourcompany.com]

Admins see everything about the app that you do, and can invite and uninvite people. Removing someone from access.admins and publishing takes the role away; uninvite doesn't.

Inside your app, admins arrive with the admin role and everyone else with user. See security and access for how your app reads them.


Something not working?

See workspaces and sharing on the troubleshooting page.