Show the numbers without handing over the list

Every growing team runs into the same week. An intern starts on Monday and should read the queue before touching it, a sales lead needs customer names because working her accounts is the job, the agency spending your ad budget wants to see which campaigns actually earned revenue, and an investor has asked for the monthly funnel by Friday. Four requests, four different answers, and one thing in common: none of them is a reason to hand somebody your customer list. Viably answers all four with five roles, a short list of permissions you can grant one person at a time, and guest access that expires on the date you chose when you sent the invitation.
Trigger
Members
Lands in
The Members page
Setup
2 min
Needs
Admin access to the workspace

Three ways in, and only one of them needs an account

Your colleagues sign in with the accounts they already have, and the people who work with you from outside do not need one at all. This is usually where sharing an operational dashboard stops being possible, because the outsider has no company login and nobody wants to create one for them.

Slack

Anyone in your connected Slack workspace can sign in, and what they arrive as is a setting you control rather than a default you inherit.

Google Workspace

Claim your company domain once and every colleague on it lands in the right workspace, with no invitation to chase.

An emailed link

For guests, who by definition have neither of the above. Viably emails a single-use link each time they want in, so there is no password anywhere and nothing to reset.

What new arrivals become is your decision, not ours

Everyone in a connected Slack workspace can reach a sign-in, so a workspace can say what the next person through the door starts as. Set it to limited and the intern who joins on Monday reads the queue without being able to change it, until somebody decides otherwise.

Five roles, each one written for a real job

Roles are named after the work rather than after the permission, because the question an admin is actually answering is what somebody has been hired to do. Every role is available to an invitation, so you can bring in a colleague at the right level on the first day instead of promoting them on the second.

The sales lead who works by name

Someone carrying a book of customers needs to see who those customers are, which used to mean handing over the whole workspace. Manager gives them the full CRM record and keeps billing, Powers, and member access out of it.

The support partner you outsource to

An outsourced service team can work the queue, reply to customers, and be measured on response time while remaining unable to download a single row of it. Working the list and taking the list are separate permissions here.

The agency running your campaigns

Give the people spending your budget a live view of what each source and campaign actually earned, with every customer name redacted. They optimise against real revenue instead of a monthly screenshot, and they never hold your leads.

The investor or auditor with a deadline

Thirty days of read access, granted in the time it takes to type an address, ending on its own afterwards. Nobody has to diarise a revocation, and nobody has to build a deck of numbers that already exist.

Slack owners and admins keep their standing

If Slack says somebody owns or administers your workspace, Viably agrees, so the two never drift apart and nobody can be locked out of their own Powers by a change made here.

Trust one person with one thing

Some requests are not a job description. A limited member needs payment amounts for one reconciliation, or an analyst needs to download a file without ever seeing a customer name. Rather than promoting somebody and hoping to remember to undo it, grant the single permission on their own row and leave their role where it is.

See contact names and addresses

The analyst who has to reconcile two records genuinely needs the address for an afternoon. Grant it on their row and leave the rest of the workspace as it was.

Download contacts and logs as a file

Kept separate from working the queue on purpose, because taking a copy of the pipeline out of the building is a different act from answering the person at the top of it.

See payment amounts and customers

A bookkeeper closing the month reads the money on a payment event without being given the CRM. A single grant covers the reconciliation and nothing else.

Grants only ever add

A grant can turn a no into a yes and never the other way around, so nothing here can quietly take a capability away from somebody who has it. The three permissions above are the only grantable ones: billing, Powers, and member management are how a workspace governs itself, and they stay with the admin role where they can be seen.

Bring somebody in from outside, for as long as it takes

A guest is somebody who was never meant to stay: the investor doing diligence, the auditor with a checklist, the agency reporting on last quarter, the fractional CFO who is here on Tuesdays. They read what a limited member reads, they change nothing, and their access ends on a date you set before you sent the invitation.

Step 1Invite them by email address

Open Members, choose Guest, and pick how long they need: a week, a month, or a quarter. Add a line in your own words saying why, and the invitation carries it.

Step 2They open the link and they are in

No account to create, no password to choose, and nothing for anybody's IT team to approve. The link works once, and Viably emails another whenever they come back after their session has lapsed.

Step 3Forget about it

Access ends on the day you chose, whether or not anybody remembers. Extending it is one control on their row, and so is ending it early.

No account, no password, no provisioning

Guest sign-in is a link Viably emails on request. It works once, it expires in minutes rather than days, and it can only ever admit somebody whose row in your workspace still says guest, so promoting them, ending their access, or removing them stops the link working in the same moment.

One guest, several workspaces

Somebody who advises two companies that both run Viably holds one identity and switches between the workspaces that invited them. An emailed link only ever opens the ones where they are a guest, and never a workspace where they happen to be a colleague.

The list stays yours, whoever is looking at it

This is the part that decides whether outside access is safe enough to offer at all. Redaction hides the person and keeps the analysis, so a queue can go on a projector, into a board meeting, or in front of an agency without the customer list going with it.

Redacted before it leaves the server

The real address is never sent to a browser that should not have it, so the protection is not a blur somebody can lift with developer tools. What arrives is already redacted.

Everything that is not a person stays readable

Company, source, campaign, stage, status, revenue, and dates all remain legible. That is what makes a redacted queue genuinely useful to somebody analysing it rather than a screen of asterisks.

A masked screen cannot produce an unmasked file

The table, the detail view, and the CSV route all read through the same redaction, so there is no export that quietly contains what the page was hiding.

Every download is on the record

Who took a file, which surface it came from, the filters it was cut from, how many rows it held, and whether the names in it were redacted. Revoking access afterwards becomes an answerable question rather than a hope.

What a redacted row still tells you

A guest looking at your contacts can see that a lead came from a paid campaign in March, sits in your Working stage, belongs to a company in your best-performing segment, and has paid you twice. What they cannot see is who to email about it. That is exactly the shape of information an outside analyst needs and exactly the shape a competitor would want, which is why the two are separated by a permission rather than by trust.

Access that ends without anybody remembering

Most access problems are not decisions, they are follow-ups nobody got round to. The contractor who finished in April, the agency whose retainer ended, the auditor who signed off in June. Viably treats the end of access as part of granting it.

The clock is the database's

An expiry is compared against the server's own time on every request, so access ends on the day it was supposed to whether or not a scheduled job ran and whether or not anybody logged in.

A live session dies with the access

Expiry is not something that waits for the next sign-in. A guest reading a page when their window closes is asked to sign in again, and no new link can be issued.

Leaving keeps the work and drops the keys

Offboarding somebody surrenders their permissions and their grants while leaving their name on the contacts they claimed and the replies they sent, so your history stays readable after the person has gone.

Extending is one control, not a re-invitation

An engagement that runs two weeks longer takes one change on their row. Ending it early is the same control in the other direction.

It pairs with the rest of the automation

The record builds itself from your forms, your inbox, and your payments, the queue orders itself by who is still waiting, and the access to all of it expires on schedule. Read Lightweight CRM for the capture side, and the customer lifetime view for what one contact record holds by the time an outsider looks at it.

Common questions

What teams ask before they let somebody outside the company near the pipeline.

Can I give somebody access without giving them our customer list?

Yes, and it is the default for the two narrowest roles. Customer names, email addresses, and phone numbers arrive at the browser already redacted for anyone without the identity permission, while the company, the source, the stage, the status, the revenue, and every date stay perfectly legible. Somebody can therefore read the whole funnel, see which campaign earned the money, and tell you how fast enquiries are being answered, without ever holding an address they could mail.

Does a guest need a Slack account or a Google Workspace account?

No, and that is the point of the guest role. An outside investor, an auditor, or a fractional CFO signs in with a link Viably emails them, so there is no account to create, no password to choose, and nothing for your IT team to provision. Everyone who does belong to your company keeps signing in with Slack or Google as usual.

What happens when a guest's access runs out?

It stops, on the date you picked when you invited them, without anybody having to remember. The next page they open sends them to the sign-in screen, and a fresh link cannot be issued because the workspace no longer recognises them as a guest. Their name stays on the roster and on anything they touched, so the history of the engagement survives the access to it.

Can I stop people downloading a CSV?

Yes. Downloading is its own permission, separate from working the queue, so a member who claims and replies to contacts all day can be prevented from ever taking a copy of them out of the building. Guests and limited members cannot download anything at all, and every file that does leave is recorded with who took it, which filters it was cut from, how many rows it contained, and whether the names in it were redacted.

How do I give one salesperson customer names without making them an admin?

Make them a manager. It is the rung between member and admin, built for the person running a book of customers: the full CRM including names, addresses, and what each customer has paid, with none of the billing, Powers configuration, or member management that admin carries. If it is narrower than that, a single grant on their own row will do it instead.

Do you charge per seat for any of this?

No. Viably is priced flat for the whole workspace, so putting a tenth colleague, a support partner, or a board member in front of the numbers costs nothing extra. Roles exist to answer who should see what, and never to meter how many people are allowed to.

Can a guest change anything?

No. A guest reads, and that is the entire list. They cannot claim a contact, send a reply, edit a stage, add a tag, configure a Power, or touch billing, and the restriction is enforced in the queries themselves rather than by hiding buttons in the interface.

Invite somebody today

The quickest way to see how this feels is to invite yourself at a personal address as a guest, with a window of seven days. You get the emailed link, the redacted queue, and the expiry, in about two minutes.

Open Members in the dashboard to set what new arrivals become, invite a colleague at the role that fits, or hand an outsider a window that closes by itself. Every plan includes all five roles, because access is not a feature to be sold back to you.

Add Viably to Slack
Then decide what they are looking at

Point your forms and your support inbox at Viably with the Inbound Email and Webhook Relay guides, attach revenue with Payment Webhooks, and the funnel your guest reads will be built from the work your team was already doing. A workspace with one POST and one mail forward already has something worth showing.