Skip to main content
Share link management and revocation work in every workspace, and workspace-wide share policy comes with the Enterprise plan. To choose the share scope for an individual note, see the Sharing guide. This page collects the controls an admin uses to govern sharing. These work on the web today and roll out to the desktop and mobile apps over time.

What can you do?

Keep the convenience of sharing notes by link, while an admin keeps the contents from leaking outside the company.
  • Manage and revoke share links: An admin reviews every link shared in the workspace from one place and revokes any of them right away.
  • Enforce a share scope cap : An admin sets the widest share scope people can pick for the links they create, blocking anything broader than the cap. To see how people choose a share scope per note, see the Sharing guide.
  • Workspace share policy : An admin sets the share scope cap, the maximum expiry, and the allowed company domains.
A note link shared with the [People at my company] scope, received over a Slack DM or email, opens right away once you sign in with your company account. You do not need to sign up for Tiro separately.
  1. Click the link and the “Sign in with your company account” screen appears. If you are already signed in with your company account, the note opens right away.
  2. Click [Sign in with company account] and sign in with your company Google account.
  3. After you sign in, you return to the note automatically and can read it.
The Sign in with your company account screen, with a lock icon and a Sign in with company account button.
You can only open the note by signing in with an allowed company domain account. By default that is the company domain of whoever shared the note, and on the Enterprise plan an admin manages the allowed domain list directly. You can open the link as long as you authenticate with that domain account, even without a Tiro account, and the note stays hidden if you sign in with a different domain account. It works the same whether you click the link from a Slack DM, an email, or any other path. A workspace admin reviews every active link in one place and revokes any of them right away. Under [Settings][Workspace], the “Shared links” section lists the currently shared links, along with each note’s title, share scope, and share date.
The Shared links list, showing note titles, share scope, and share date, with a Revoke button on each row and a Revoke all button at the top.
  • To pull back one link, click the [Revoke] button on its row.
  • To pull back several links at once, select them with the checkboxes and revoke them.
  • To pull back every link at once, click the [Revoke all] button at the top.
A revoked link stops opening immediately, and the note returns to private. To share the note again, create a new share link from the note.
Revoking cannot be undone. The same link cannot be restored, and sharing again creates a new link.

Manage workspace share policy

This setting shows only to workspace admins. As an admin, you set the share scope, expiry, and allowed company domains for the links your team creates, at the workspace level. Under [Settings][Workspace], set the three policies in the “Share policy” section.
The Share policy section, with the workspace share scope cap set to People at my company and the maximum link expiry set to 90 days.
The [Workspace share scope cap] option enforces the widest share scope people can pick for the links they create. You set the cap to one of three levels: [Anyone with link], [People at my company], or [Private (no link sharing)]. The strictest level, [Private (no link sharing)], blocks link sharing across the whole workspace. The cap applies retroactively to existing shared notes right away. For example, if you set the cap to [People at my company], a link already shared as [Anyone with link] also becomes viewable only by people at your company from that point on, with no need to recreate the link. When someone shares a new note and picks a scope wider than the cap, it adjusts down to the cap automatically. The [Maximum link expiry] option sets the longest number of days before a new share link expires. Leave the value empty to keep links indefinitely with no expiry. The maximum expiry applies to share links created after you set it, and existing links created before never expire from it. In the allowed company domains setting, you manage the list of company domains that can open [People at my company] links. Anyone who authenticates with a registered domain account can open the link, even without a Tiro account.

Frequently asked questions

They are protected by the share scope cap automatically, with nothing for you to touch. When the cap is set to [People at my company], a note you shared earlier as [Anyone with link] becomes viewable only by people at your company from that point on. The policy applies at the moment someone opens the note, so there is no need to recreate the link, and the address stays the same. The maximum link expiry behaves differently. Expiry applies to share links created after you set the policy, and links created before never expire from it.

How do I show a note to someone outside the company (an external partner)?

Invite them to the note directly. A share link only opens for allowed company domain accounts under the workspace policy, but if you type that person’s Tiro account email into the invite field in the “Share note” popup, you invite them by name and they can view the note. There is no way to use anonymous link sharing to get around the workspace visibility cap. Only named invites, where it is clear who is viewing, are allowed. Yes, they can, even if they have never signed up for Tiro. Opening a link shared as [People at my company] brings up the “Sign in with your company account” screen, and clicking [Sign in with company account] to sign in with a company Google account takes them straight to the note. The email domain of the account they sign in with has to match an allowed company domain for the note to open. It is usually one of these three causes. Check them in order.
  1. Check the signed-in account: If you are signed in with a personal account instead of a company account, the note shows as missing for security. Sign in again with your company domain email account.
  2. Check link expiry: If the workspace has a maximum link expiry set, an expired link is blocked with the same screen.
  3. Check for revocation: An admin may have revoked the link.
You cannot view a note through an expired or revoked link, so ask the note owner for a new share link. Yes. When a workspace admin clicks the [Revoke] button for the note in the “Shared links” list in workspace settings, the link is invalidated immediately. In a hurry, ask your admin to revoke it along with the note title.

Why don’t I see the sharing settings in the mobile app?

The sharing security and management options work on the web today. They roll out to the desktop and mobile apps over time. Until then, open Tiro in a web browser to manage the sharing settings.
Related pages: Sharing · Integrations · Folders · Privacy and security