Private · Shared · Public

One scene carries all three audiences

Every workflow becomes a scene — its data, its tools, the agent that runs it, and the history of everything it did. Inside it, everything sits in a layer: what's yours, what's the team's, and what the public page serves.

Where it sits is who sees it.

Cable Line 3
Publicanyone with the link
Delivery scheduleupdated 09:12
Quality reportweek 33
Sharedthe team
12.4%margin, line 3
Order backlog47 open
Shift notesedited by Ana
Privateonly you
$cells.s4_orders → margin by line
rehearsal jobrunning…
Share by moving

Moving a thing is the whole act of sharing

No permissions matrix. Drag the report from Private to Shared and the team has it; on to Public and the share link serves it.

Nothing moves on its own. An asset changes its audience when someone moves it, and the confirmation says exactly what changes.

Private

Quality report

Shared

Quality reportweek 33
Move to Shared? Your team will see this. Its history and, for cells, the formula move with it.
MoveCancel
Jobs · Cable Line 3
Weekly quality digest08:00Public
Margin analysis, line 3yesterdaywas private · moved by Mirko
Reconcile backlog with S/4TueShared
why is margin negative on line 3?TuePrivate · only you
Rehearse in private

Run it three times before anyone watches

A job in your Private layer is a rehearsal: full tools, full trace, visible to nobody. Ask the basic question. Take three attempts at the analysis.

Move the good run to Shared and it enters the team's history at that moment, outputs included. One job list per scene, filtered by what you can see, each row wearing its layer.

A private job reads with your eyes but writes only to your layer, so a job can't hide while its effects show.

Backstage powers the stage

Publish results, keep the substrate

Keep raw tables, credentials, and the data model in a layer the team never wades through. A cell you author there publishes its result into Shared.

The team sees the number, live, and can open the formula that made it. The source stays yours: programs run with their author's access, never the reader's.

Sharedthe team
12.4%margin, line 3 · live
formulareadable by everyone here
Backstageonly admins
$cells.s4_orders → margin by line
s4-orders2.1M rows
S/4 accountcredential

Mirko saves the formula

$cells.q3_model .margin("line-3")
runs with his access → 12.4%

A teammate copies the text

$cells.q3_model .margin("line-3")
runs with their access → q3_model: not found

A reference is a capability: you can only address what you can see.

Authoring is the permission

Programs run with their author's eyes

When you publish a cell that reads your private data, the act of authoring it is the grant. Everyone can read the program; nobody inherits its access.

Build on the published value freely, spreadsheet-style. Copying the formula re-runs it with your own access, and a source you can't see resolves as not found.

Every run traced

Private, shared, or public, each job keeps its full trace. A promoted run brings its history with it.

Gates on consequential actions

A write that touches the real world waits for approval, in every layer, for every author.

Absent, not greyed out

A visitor gets exactly what Public holds. Everything else is missing from the response, not hidden in the page.

Start where every scene starts: a place of your own

Set your first scene