# Sharing and access

Access is between two people and points one way at a time: someone can reach a machine of
yours, or you can reach a machine of theirs. This page covers how access starts, how to see
who has it, and how to end it.

## What access controls

A machine serves only the people it was shared with and, if its owner joined a group (one an
organization runs or one anyone can join), that group's members. Your requests reach your own
machines, machines someone shared with you, and, if you joined such a group, the machines of
the people in it. There is no other path between a stranger's machine and yours.

Each direction is a separate act by the person whose machine it is. Being given access does
not give access back, and asking someone for access does not offer them yours.

## Accepting an offer

When someone offers you access, they send you an invitation link. See what it offers first,
without answering it:

```bash
saylek sharing preview <invitation>
```

Then accept it:

```bash
saylek sharing accept <invitation>
```

Either form you were sent works: the saylek.com link, or the `<id>:<token>` pair. Treat it
as a secret, because anyone holding it can act on it.

**Accepting is the consent.** Once you have accepted, requests your own machine cannot serve
may run on the other person's GPU by default. Read [Privacy and
egress](/docs/privacy-and-egress) before you accept on a machine that handles sensitive work.

## Offering access to someone

```bash
saylek sharing invite --note "Rana, from the workshop" --email them@example.com
```

That sends the invitation to the address, and it can be accepted once. To get a link you pass
on yourself instead:

```bash
saylek sharing invite --note "Lab, autumn term" --link --uses 5
```

`--note` is required, and only you see it. `--uses` (1 to 100) works only with `--link`;
leave it off for a link that admits one person. An invitation lasts 24 hours unless you pass
`--expires` with a duration such as `7d`, `24h` or `90m`, and 7 days is the longest.
See [Invite flow](/docs/invite-flow) for the whole picture.

## Seeing who has access

```bash
saylek sharing list
```

It shows, separately, the people who may use your machines and the people whose models you
may use. `--direction you-share-with` or `--direction shared-with-me` reads only one. A
direction that could not be read is reported as unknown, never as nobody.

## Ending someone's access

```bash
saylek sharing revoke --person <name>
```

Name them the way `saylek sharing list` shows them. If two people share that name, it
refuses and prints their ids rather than guessing. It ends one direction only: anything of
theirs you use is untouched. You can offer access again later with a new invitation.

An invitation you sent and nobody has accepted yet still works until it expires. There is no
`saylek sharing` command that cancels one, so if a link has spread further than you meant,
let it expire and send shorter-lived ones with `--expires`.

## Giving up access you were given

```bash
saylek sharing stop-using --person <name>
```

It ends one direction only: what you share with them is untouched, and they are not asked to
stop sharing. You can accept a new offer from them later.

Each of these asks before it changes anything. Without a terminal, pass the word it asks
for: `--confirm accept`, `--confirm remove` or `--confirm stop`. `--plan` shows
what would change and changes nothing.

Giving up the **last** one does not stop Saylek routing a request your machine cannot serve:
it can still run on another machine of your own, or in a group you joined (leave one with
`saylek circles leave <id>`; `saylek circles list` shows the id). With neither, it is refused rather than sent somewhere else. To keep
requests on your machine, use local-only mode, covered on
[Privacy and egress](/docs/privacy-and-egress). None of this touches a proxy upstream you
configured yourself.

For pausing or deleting your whole account instead, see
[Common commands](/docs/cli-reference).

## Next steps

- [Privacy and egress](/docs/privacy-and-egress): what the person serving you can see.
- [Invite flow](/docs/invite-flow): emailing an offer to one person.
- [Sharing your models](/docs/share-your-models): letting someone reach the models your machine runs.
