> Documentation index: https://rift.sh/llms.txt

# Sharing

Share a folder with a key, choose a role and remove access when you need to.

## Share a folder

Sharing takes a path, a key and a role. The other machine starts syncing that folder immediately, and nothing else on your machine is visible to it.

Bob can edit team. The agent can read it. Neither sees Alice's private folder.

```
$ rift share team bob
✓ shared team with bob · write
$ rift share team agent --read
✓ shared team with agent · read
$ rift members team
alice    admin   you
bob      write
agent    read
```

`bob` and `agent` are aliases Alice saved with `rift peer add`. Aliases exist only on her machine. A full public key works in place of an alias.

## Roles

| Role | List and read | Add, edit, move, delete | Share and remove access |
| --- | --- | --- | --- |
| read | yes | no | no |
| write | yes | yes | no |
| admin | yes | yes | yes |

`write` is the default. Every machine rejects an edit signed by a `read` key.

## Share a subfolder

Share `team/docs` with Carol, a contractor, and her machine syncs that subfolder only. Nothing else in `team` reaches her machine, including file names.

Bob has the whole folder. Carol has one subfolder of it.

```
$ rift share team/docs carol
✓ shared team/docs with carol · write
$ rift members team/docs
alice    admin   you
bob      write   from team
carol    write
```

Everyone with access to `team` keeps access to `team/docs`. A subfolder share only adds members.

## Restrict a path

`--exclusive` limits a path to the keys you name. Members of the parent folder lose access to it. Here Alice shares `.env` with her agent, and Bob can no longer read it. Bob keeps any copy his machine already downloaded, so replace the secrets in it.

Bob sees that .env exists. New versions are encrypted with a key he was never sent.

```
$ rift share project-a/.env agent --read --exclusive
✓ shared project-a/.env with agent · read
! bob no longer has access to project-a/.env

# bob
$ rift cat project-a/.env
✗ permission denied
  project-a/.env is restricted to 2 keys
```

## Remove access

Bob stops receiving changes. Files he already downloaded stay on his disk.

```
$ rift unshare team bob
✓ removed bob from team · new key
$ rift members team
alice    admin   you
agent    read
```

After `rift unshare`, Bob cannot read anything new in `team`, and the other machines reject any change he sends. The folder gets a new key, and the remaining members receive it.

Removing access does not delete files Bob already downloaded. If one held a secret, replace that secret.

Moving a file to a folder with different members changes who can read it. See [Move](https://rift.sh/docs/files.md#move).
