Widening access needs an explicit confirm
Aliases: make public confirm · expand audience · share upsell
What it is
Sharing scope can narrow or widen. Widening grows the audience: only-me to named people, named people to link, team to the internet. That direction must not take effect on releasing a slider; it needs a confirm that names the new audience. Narrowing can apply at once, because risk falls. This is not how current scope is displayed. It is whether growing the set is seen and acknowledged. That links are harder to contain than named people, and that revoke cannot recall a download, are later consequences; confirm copy may mention them, but those mechanisms live on their own entries.
Why it happens
Widening is irreversible spread: once a new audience opens the object, it enters their downloads, caches, and forwards. UI often uses one dropdown for both directions; picking Anyone and Only you are the same gesture with opposite cost. Without confirm, a mis-tap, or picking the largest item so “the link will open,” completes a publish. Confirm writes the asymmetry into the act: growing pauses, shrinking does not. The confirm has to name the new class and approximate size (“about 4,000 people in the org can open this”), or it is another habitual OK. If shrinking uses the same dialog, people dismiss every share dialog and widening confirm dies.
Studying it
Run “show this to one colleague” and “accidentally set scope to maximum.” Compare: dropdown applies immediately, confirm only on widen, confirm on every change.
Independent variables: confirm only when growing, whether copy names class and size, whether narrowing also interrupts. Dependent variables: accidental publishes, extra steps on a legitimate share, confirms clicked unread.
A lab that says “please do not make this public” makes people unusually careful. Hide widening inside something that looks like Copy link, closer to the accident. Split intentional publish from “I thought I was copying a link.” Count of dialogs shown is not quality—shown and unread equals none.
Where it stops holding
Adding one named person from only-me is small and reversible; a light confirm or an undo toast can beat a make-public dialog. If admin policy already forbids public, the control should be unavailable, not fail after confirm. Bulk-widening many files needs the file count in the confirm, or confirming one by one and mis-widening hundreds look the same. A timed widen (thirty-minute demo) still confirms, with an end time in the copy.
Applying it
- Any choice that grows the audience shows one sentence naming the new scope and requires an explicit confirm. Narrowing applies immediately and can undo.
- Confirm names class and known size, not a hollow “are you sure.”
- If Copy link would lift scope from named people to anyone-with-the-link, run widening confirm before the copy.
- Verify: set a task “only Jia can see this.” Watch for org-wide or internet-open without confirm. Then publish something that should be public, and ask people to restate the new audience from the confirm. If they cannot, the confirm was an empty box.
Related
- Within the group: H8.08.1 Current sharing scope must sit beside the content · H8.08.3 Permission inheritance must be understandable · H8.08.4 View, comment, and edit roles follow least privilege · H8.08.5 Link sharing spreads farther than named people · H8.08.6 Revoking access cannot recall copies already taken · H8.08.7 Org defaults vs personal share need a stated winner
- Adjacent: H8.04 Copy, Share, and Export · H3.05 Confirmation Dialog Abuse
- Search terms:
share widening·make public·audience confirm
Cards in the same group
- H8.08.1Current sharing scope must sit beside the content
- H8.08.3Permission inheritance must be understandable
- H8.08.4View, comment, and edit roles follow least privilege
- H8.08.5Link sharing spreads farther than named people
- H8.08.6Revoking access cannot recall copies already taken
- H8.08.7Org defaults vs personal share need a stated winner