A Giraffe workspace holds everything your organization is working on: live deals, feasibility studies, client-specific site plans, and the layer libraries behind them. Governance is what decides who can open, edit, or even see that content. Get it right, and a consultant only ever sees the sites they are assigned to. Get it wrong, and one client's numbers turn up in front of another client's team.
Access is closed by default
Giraffe always defaults to the highest level of control. When you create a project, space, layer, template, content pack, app, or credential, it is private to you. No one else in your workspace can see it, not even people on your own team, until you or an administrator shares it with them.
This holds the same way across every type of content: Projects, Spaces, Layers, Templates, Content Packs, Apps, and Credentials all start closed, and stay closed until someone with permission opens them up.
For the exact steps to share each type of content, see Sharing in Giraffe.
The permission levels
Content in Giraffe shares a common vocabulary for permission levels, though not every level applies to every type.
Admin can create, edit, share, and delete the content. Available for everything you can share. See Admin Permissions.
Edit can create and edit content, and cannot share or delete it. Available for Projects, Spaces, and Layers. Other content types skip straight from View to Admin when shared with an individual. See Edit Permissions.
View can open the content and see the data, and cannot change anything. Available for everything you can share. See View Permissions.
Guest can see limited project metadata through a Space, without opening the project or space itself. Available for Projects and Spaces only. See Guest Permissions.
The person who creates a project, space, layer, or other object is its Admin by default. Only an Admin, or a workspace administrator, can grant access to anyone else.
Guest access is an add-on for Enterprise accounts. Reach out to sales to inquire about upgrading.
See Project Permissions and Space Permissions for the full breakdown of what each level can do.
Workspace membership and content sharing are separate
Every workspace member has a baseline permission level for the whole workspace, set when they are invited: Admin, Edit, View, or Guest. See Member Permissions for what each workspace-wide level allows. This baseline only applies to members of your own workspace.
Sharing a specific project, space, or other piece of content is a separate mechanism, and it reaches further than your own workspace. You can share directly with anyone who has a Giraffe account, whether they belong to your workspace or are licensed in a different one entirely. Someone outside your workspace has no baseline permission with you at all: their access comes only from the level you grant when you share with them.
For members of your own workspace, the two combine. A specific project can grant a member more than their workspace baseline for that one item. A member with View access workspace-wide can still be made an Edit or Admin on a single project, if someone shares that project with them at that level.
Getting the right people access
Sharing is what turns closed-by-default into the right people having what they need. Content in Giraffe is shared one of three ways.
With an individual, by email. This is the only way to reach someone outside your workspace, as long as they have a Giraffe account somewhere.
With a Team: a group of workspace members who typically work together, like an office or a project team. See What are Teams?
With your entire workspace, always at View access. Only a workspace administrator can grant it.
When you are not sure what level to grant someone, start with View. You can raise it to Edit or Admin later if they need to make changes.
See Sharing in Giraffe for the exact sharing steps for each type of content.
When someone needs to see everything
Workspace administrators are the one exception to closed-by-default. On an Enterprise account, a workspace administrator can turn on audit mode to see, edit, share, or delete any project or space in the workspace, whether or not it has been shared with them. See How to see all projects in a workspace.
Audit mode exists for oversight: cleaning up stale permissions, checking who has access to what, or stepping in on someone else's project. A workspace administrator turns it on deliberately. Outside audit mode, an administrator sees the same closed-by-default workspace as everyone else.
Sharing outside your workspace
Everything above assumes the other person has a Giraffe account, in your workspace or another one. To let anyone view a project without an account, publish it instead of sharing it. See Publish Projects.
🚨 Warning: A published project gets a public URL. Anyone with the link can view it without an account, and without going through workspace governance. Only publish content you are comfortable making public.
What your account tier changes
Some of what is described above depends on your account tier: Core, Team, or Enterprise. Guest access, Team-based and workspace-wide sharing, and audit mode are not available on every tier. See Sharing by Tier.