Report Sharing Permissions
Share a report with specific people without opening the data behind it.
What it adds
Per-report access control inside the app, distinguishing what each recipient may do with the report.
What your agent is told to do
5
What your agent is told to do
5-
1
Give each saved report its own access list, separate from the workspace-wide role. Reports combine data that not everyone should see together.
-
2
Model four distinct grants: view, edit, duplicate, and reshare. Being able to read a report is not permission to hand it to someone else.
-
3
Enforce the underlying data permissions on every render. A share grants access to the report definition, never a bypass of row-level security on the source.
-
4
Show the current access list on the report, so an owner can see who can open it without digging through settings.
-
5
Do NOT build account-less public links here — tokenized external sharing is owned by Signed Share Links. Role definitions are owned by User Roles; read from them rather than defining new roles.
Edge cases it handles
6
Edge cases it handles
6- A recipient without access to a source must see that widget explained, not a blank panel or a raw permission error.
- Removing someone from the workspace must revoke their report shares immediately, not leave an orphaned grant.
- A duplicated report must not inherit the original's access list by default — the copy starts with the duplicator.
- Downgrading a user's workspace role must narrow their report access too; the more restrictive of the two wins.
- An owner leaving must not strand a report with no one able to manage it. Reassign ownership or block the departure.
- Aggregate figures can leak restricted rows. If a recipient cannot see the underlying rows, do not show them the total derived from those rows.
Definition of done
8
Definition of done
8- Each saved report has its own access list independent of workspace roles.
- View, edit, duplicate, and reshare are separately grantable.
- Row-level security on source data is enforced for every viewer, sharer or not.
- Losing workspace membership revokes report access with no delay.
- Widgets a recipient cannot see are explained rather than silently blank or broken.
- A duplicated report does not carry the original's shares.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Segment Event Forwarding
Segment Event Forwarding
Send one clean stream of product events to Segment and let it fan out downstream.
What it does
A documented event schema and a single forwarding path emitting track, identify, group, and page calls with consistent identity.
How it works
- 1 Write the event schema before writing any code: the exact set of event names, the properties each carries with their types, and the traits attached to a user and to an account. Every downstream tool inherits this schema, so a name chosen carelessly is expensive to change later.
- 2 Establish one identity model and apply it everywhere. Use a stable internal user identifier that never changes, associate the anonymous identifier from the first visit with it at signup, and attach the account or workspace so downstream tools can roll events up by customer.
- 3 Route every event through one internal emitter rather than calling the provider from feature code. That emitter validates the event against the schema, drops or flags anything unrecognised, and is the single place where identity and default properties are attached.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/segment-event-forwarding
UI Event Naming Schema
UI Event Naming Schema
Give every tracked interaction a name that still means the same thing in a year.
What it does
A documented vocabulary and structure for event names and properties, applied across the app's existing tracking.
How it works
- 1 Audit the events the app already sends and list them. The duplicates, the near-synonyms, and the ones nobody can explain are the reason the schema is needed, and they are also the migration list.
- 2 Fix a structure of object, action, and context: what was acted on, what happened to it, and where. Fix a closed set of actions — viewed, clicked, opened, submitted, selected, failed — and require every new event to reuse one of them.
- 3 Keep variable detail in properties, never in the name. A record identifier, a plan name, or a workspace slug baked into an event name produces thousands of unaggregatable one-off events.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/ui-event-naming-schema
Component Analytics Hook
Component Analytics Hook
Instrument shared components once instead of hand-writing events on every screen.
What it does
Interaction tracking attached to the app's shared components, emitting named events carrying the context of where they were used.
How it works
- 1 Identify the shared components that account for most interaction — buttons, links, menus, dialogs, tabs, table rows, form submits — and attach tracking inside them rather than at each of the hundreds of call sites.
- 2 Have each component emit its own identity and the context it was rendered in: the screen, the surface, and a stable identifier supplied by the caller. Position on the page and visible label are not identity.
- 3 Emit exactly one event per user action. A menu item inside a card inside a table row must not produce three overlapping records of the same click.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/component-analytics-hook
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.