Show the numbers without handing over the list
- Trigger
- Members
- Lands in
- The Members page
- Setup
- 2 min
- Needs
- Admin access to the workspace
Three ways in, and only one of them needs an account
Your colleagues sign in with the accounts they already have, and the people who work with you from outside do not need one at all. This is usually where sharing an operational dashboard stops being possible, because the outsider has no company login and nobody wants to create one for them.
Anyone in your connected Slack workspace can sign in, and what they arrive as is a setting you control rather than a default you inherit.
Claim your company domain once and every colleague on it lands in the right workspace, with no invitation to chase.
For guests, who by definition have neither of the above. Viably emails a single-use link each time they want in, so there is no password anywhere and nothing to reset.
Everyone in a connected Slack workspace can reach a sign-in, so a workspace can say what the next person through the door starts as. Set it to limited and the intern who joins on Monday reads the queue without being able to change it, until somebody decides otherwise.
Five roles, each one written for a real job
Roles are named after the work rather than after the permission, because the question an admin is actually answering is what somebody has been hired to do. Every role is available to an invitation, so you can bring in a colleague at the right level on the first day instead of promoting them on the second.
Someone carrying a book of customers needs to see who those customers are, which used to mean handing over the whole workspace. Manager gives them the full CRM record and keeps billing, Powers, and member access out of it.
An outsourced service team can work the queue, reply to customers, and be measured on response time while remaining unable to download a single row of it. Working the list and taking the list are separate permissions here.
Give the people spending your budget a live view of what each source and campaign actually earned, with every customer name redacted. They optimise against real revenue instead of a monthly screenshot, and they never hold your leads.
Thirty days of read access, granted in the time it takes to type an address, ending on its own afterwards. Nobody has to diarise a revocation, and nobody has to build a deck of numbers that already exist.
If Slack says somebody owns or administers your workspace, Viably agrees, so the two never drift apart and nobody can be locked out of their own Powers by a change made here.
Trust one person with one thing
Some requests are not a job description. A limited member needs payment amounts for one reconciliation, or an analyst needs to download a file without ever seeing a customer name. Rather than promoting somebody and hoping to remember to undo it, grant the single permission on their own row and leave their role where it is.
The analyst who has to reconcile two records genuinely needs the address for an afternoon. Grant it on their row and leave the rest of the workspace as it was.
Kept separate from working the queue on purpose, because taking a copy of the pipeline out of the building is a different act from answering the person at the top of it.
A bookkeeper closing the month reads the money on a payment event without being given the CRM. A single grant covers the reconciliation and nothing else.
A grant can turn a no into a yes and never the other way around, so nothing here can quietly take a capability away from somebody who has it. The three permissions above are the only grantable ones: billing, Powers, and member management are how a workspace governs itself, and they stay with the admin role where they can be seen.
Bring somebody in from outside, for as long as it takes
A guest is somebody who was never meant to stay: the investor doing diligence, the auditor with a checklist, the agency reporting on last quarter, the fractional CFO who is here on Tuesdays. They read what a limited member reads, they change nothing, and their access ends on a date you set before you sent the invitation.
Open Members, choose Guest, and pick how long they need: a week, a month, or a quarter. Add a line in your own words saying why, and the invitation carries it.
No account to create, no password to choose, and nothing for anybody's IT team to approve. The link works once, and Viably emails another whenever they come back after their session has lapsed.
Access ends on the day you chose, whether or not anybody remembers. Extending it is one control on their row, and so is ending it early.
Guest sign-in is a link Viably emails on request. It works once, it expires in minutes rather than days, and it can only ever admit somebody whose row in your workspace still says guest, so promoting them, ending their access, or removing them stops the link working in the same moment.
Somebody who advises two companies that both run Viably holds one identity and switches between the workspaces that invited them. An emailed link only ever opens the ones where they are a guest, and never a workspace where they happen to be a colleague.
The list stays yours, whoever is looking at it
This is the part that decides whether outside access is safe enough to offer at all. Redaction hides the person and keeps the analysis, so a queue can go on a projector, into a board meeting, or in front of an agency without the customer list going with it.
The real address is never sent to a browser that should not have it, so the protection is not a blur somebody can lift with developer tools. What arrives is already redacted.
Company, source, campaign, stage, status, revenue, and dates all remain legible. That is what makes a redacted queue genuinely useful to somebody analysing it rather than a screen of asterisks.
The table, the detail view, and the CSV route all read through the same redaction, so there is no export that quietly contains what the page was hiding.
Who took a file, which surface it came from, the filters it was cut from, how many rows it held, and whether the names in it were redacted. Revoking access afterwards becomes an answerable question rather than a hope.
A guest looking at your contacts can see that a lead came from a paid campaign in March, sits in your Working stage, belongs to a company in your best-performing segment, and has paid you twice. What they cannot see is who to email about it. That is exactly the shape of information an outside analyst needs and exactly the shape a competitor would want, which is why the two are separated by a permission rather than by trust.
Access that ends without anybody remembering
Most access problems are not decisions, they are follow-ups nobody got round to. The contractor who finished in April, the agency whose retainer ended, the auditor who signed off in June. Viably treats the end of access as part of granting it.
An expiry is compared against the server's own time on every request, so access ends on the day it was supposed to whether or not a scheduled job ran and whether or not anybody logged in.
Expiry is not something that waits for the next sign-in. A guest reading a page when their window closes is asked to sign in again, and no new link can be issued.
Offboarding somebody surrenders their permissions and their grants while leaving their name on the contacts they claimed and the replies they sent, so your history stays readable after the person has gone.
An engagement that runs two weeks longer takes one change on their row. Ending it early is the same control in the other direction.
The record builds itself from your forms, your inbox, and your payments, the queue orders itself by who is still waiting, and the access to all of it expires on schedule. Read Lightweight CRM for the capture side, and the customer lifetime view for what one contact record holds by the time an outsider looks at it.
Yes, and it is the default for the two narrowest roles. Customer names, email addresses, and phone numbers arrive at the browser already redacted for anyone without the identity permission, while the company, the source, the stage, the status, the revenue, and every date stay perfectly legible. Somebody can therefore read the whole funnel, see which campaign earned the money, and tell you how fast enquiries are being answered, without ever holding an address they could mail.
No, and that is the point of the guest role. An outside investor, an auditor, or a fractional CFO signs in with a link Viably emails them, so there is no account to create, no password to choose, and nothing for your IT team to provision. Everyone who does belong to your company keeps signing in with Slack or Google as usual.
It stops, on the date you picked when you invited them, without anybody having to remember. The next page they open sends them to the sign-in screen, and a fresh link cannot be issued because the workspace no longer recognises them as a guest. Their name stays on the roster and on anything they touched, so the history of the engagement survives the access to it.
Yes. Downloading is its own permission, separate from working the queue, so a member who claims and replies to contacts all day can be prevented from ever taking a copy of them out of the building. Guests and limited members cannot download anything at all, and every file that does leave is recorded with who took it, which filters it was cut from, how many rows it contained, and whether the names in it were redacted.
Make them a manager. It is the rung between member and admin, built for the person running a book of customers: the full CRM including names, addresses, and what each customer has paid, with none of the billing, Powers configuration, or member management that admin carries. If it is narrower than that, a single grant on their own row will do it instead.
No. Viably is priced flat for the whole workspace, so putting a tenth colleague, a support partner, or a board member in front of the numbers costs nothing extra. Roles exist to answer who should see what, and never to meter how many people are allowed to.
No. A guest reads, and that is the entire list. They cannot claim a contact, send a reply, edit a stage, add a tag, configure a Power, or touch billing, and the restriction is enforced in the queries themselves rather than by hiding buttons in the interface.
Invite somebody today
The quickest way to see how this feels is to invite yourself at a personal address as a guest, with a window of seven days. You get the emailed link, the redacted queue, and the expiry, in about two minutes.
Open Members in the dashboard to set what new arrivals become, invite a colleague at the role that fits, or hand an outsider a window that closes by itself. Every plan includes all five roles, because access is not a feature to be sold back to you.
Add Viably to SlackPoint your forms and your support inbox at Viably with the Inbound Email and Webhook Relay guides, attach revenue with Payment Webhooks, and the funnel your guest reads will be built from the work your team was already doing. A workspace with one POST and one mail forward already has something worth showing.