> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dispoiq.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Workspace access and deal sharing

> Manage team access, share deal links and verify actual withdrawal effects.

Last updated: October 8, 2026.

Give a teammate workspace access when they need to work with your deals and buyers. Send a buyer a deal link when they need to review a property. Those are different kinds of access: a buyer-facing link does not make its recipient a member of your team.

This guide is for activated business workspaces and the controls available to them. Availability depends on your workspace, plan and role. It explains how to make sharing decisions; it does not change your accepted subscription agreement, grant additional data rights or obtain a recipient's consent.

## 1. Choose the right kind of access

| What you want to do | Use | What to consider |
| - | - | - |
| Have someone work inside your business's workspace | A team invitation and their own sign-in | Their role, occupied seats and whether they should see workspace records |
| Let buyers review a property | A buyer-facing deal link | The information displayed on the page and the possibility of forwarding |
| Follow a particular buyer's apparent interest | A personalized deal link | Activity can be associated with that buyer even if someone else uses the link |
| Give someone a photograph or document | The relevant file or resource link, if you are entitled to share it | File access can differ from workspace or deal-page access; downloaded copies can remain with recipients |

A deal page can be viewed without a teammate's sign-in. Do not treat a personalized URL as a password-protected document room or proof that only the named buyer can view the property. Keep access instructions, lockbox codes, identity documents, private contracts and unnecessary personal information out of broadly shareable materials.

## 2. Add and manage teammates

Give each authorized teammate an individual account. Choose the least access they need and review it when their work changes. Protect the email account they use to sign in, and avoid sharing passwords or invitation emails.

The role choices are **Owner**, **Admin** and **Viewer**. Owner is the role for subscription decisions and member-access management. Admin is intended for day-to-day deal, buyer and messaging work within the available features. Viewer is intended for read-only work. A role does not purchase a feature or create a separate confidential area within the workspace.

For an owner with the controls enabled:

1. Open **Settings → Team & Seats** and review active members and pending invitations.
2. Choose **Invite member**, enter the intended teammate's name and email, and select their role. Check the address before sending.
3. Have the teammate accept the account invitation. A pending invitation is different from an active member.
4. Review the result in the team list. If the invitation fails or access is still pending, use the available resend or cancel control, or contact support. An error is not confirmation that the invitation succeeded.

Use the available owner controls to change roles or disable access when someone leaves. Keep another appropriately authorized active owner before changing or removing the only active owner. Confirm that the requested change succeeded; removing a team member does not recall files or information they already received, revoke separate buyer links, or erase the business's records.

A change in the team list does not by itself confirm that every existing session or authentication-provider membership has been revoked. Contact support if access still appears possible.

Use only the member actions actually available to your authorized role and workspace. The Team & Seats screen offers its invitation control to owners; an Admin role does not mean the screen offers the same owner controls. If an invitation, acceptance, role change or removal fails, remains pending or conflicts with the access you observe, contact **[support@dispoiq.app](mailto:support@dispoiq.app)** with the member reference and result. Support will record the issue, verify the workspace and your authority, and coordinate authorized technical review of the invitation, membership and access outcome. Do not assume a repeated invitation fixes an uncertain result or that a changed roster revokes every separate account, session or shared link. If access appears broader than intended, stop further sharing of affected information until the required access restriction is confirmed. A seat-capacity or feature denial does not authorize an additional purchase.

## 3. Keep seats separate from billing changes

Active members and pending invitations occupy seat capacity. Disabled members do not. Check outstanding invitations as well as active people when you cannot add a teammate.

Disabling or removing someone does not automatically lower your purchased seat quantity or recurring charges. Request a billing change separately at **[support@dispoiq.app](mailto:support@dispoiq.app)**. Requested added seats take effect when processed and confirmed, with incremental charges prorated by actual days; requested seat reductions take effect at the next renewal without an ordinary mid-term refund. Do not assume that sending the request has changed your subscription or that lowering capacity automatically removes people.

The [Plans, Features & Seats guide](https://docs.dispoiq.app/help/plans-seats) explains the plan and capacity details. Your accepted subscription terms and confirmed purchase arrangement govern the charge and effective date.

## 4. Prepare a deal for sharing

Before sending a link, review the buyer-facing information, not just your internal notes. Check the property address, asking price, what that price includes, estimated ARV and repairs, occupancy, access arrangements and next steps. Label estimates accurately and remove information you do not intend the audience to receive.

Confirm that you have authority to market the deal and share the photographs, documents and other materials. A software control does not establish ownership of the property, permission to advertise it, assignability of your contract or authority to arrange entry. Keep the transaction documents and permissions needed for your actual deal.

Sharing your own deal is different from redistributing another provider's buyers list or source-restricted information. Saving a discovered contact or paying for enrichment does not create unrestricted sharing or export rights. Check the [Buyer Data & Permitted Use Policy](https://docs.dispoiq.app/policies/buyer-data) and the permissions that apply to the source before sharing provider-derived information outside your business.

Photos and documents may have resource URLs that work separately from the page where you found them. Do not assume an upload is private because the upload control sits inside your signed-in workspace. Share only materials appropriate for that exposure; use a method with access controls you've verified for confidential documents.

## 5. Use buyer links with care

Where **Invite to deal** is available on the relevant buyer or contact record, choose the correct deal, generate the link and copy the resulting URL. Check the selected buyer and property before sending it. Generating or copying a link is different from sending a message, and a separate link does not necessarily create a new audience restriction or replace an earlier link.

Send a personalized link to its intended recipient rather than posting it in a group or using it for everyone on your buyers list. If it is forwarded, another person's visit can appear under the original buyer. A copied link, a buyer identifier, or the label “invite” does not verify the visitor's identity or keep the page confidential.

Opening a deal can record visits and interactions, such as time on the page, scrolling and photo activity. These records help you decide whom to follow up with, but they do not prove funding, purchasing intent or that the named buyer performed the interaction. Browser settings, blocked requests and forwarded links can affect the record. Confirm important facts in a conversation with the buyer.

A generated link, page view, offer or reply does not itself establish permission for marketing messages. Follow the applicable recipient-permission and opt-out requirements before contacting someone. Do not send a fresh message just to check whether access was removed.

See the [Cookie & Analytics Notice](https://docs.dispoiq.app/policies/cookies-analytics) for the different visitor and app technologies. Visitor collection notices and choices must match what is actually collected; this guide does not supply consent or replace a collection notice.

## 6. Understand what removal changes

| Action | What to keep separate |
| - | - |
| Disable or remove a teammate | Workspace access, purchased seats, buyer-facing links and copies already received are different matters |
| Remove a buyer from a deal's buyer list | That list entry is separate from the buyer's master record, existing personalized links and recorded activity |
| Mark a deal closed or terminated | Finishing the transaction does not itself revoke existing deal-page links or stop engagement collection |
| Use Unpublish or change a deal's status | Do not rely on the status label alone to restrict viewing; confirm the actual effect before treating the page as withdrawn |
| Delete a deal or attachment | Removal of application records and cleanup of stored files are separate steps; recipient copies, external files, caches and retained records can need different handling |

To withdraw a deal or restrict its audience, do not rely on **Unpublish**, closing the deal or changing a status to block every existing URL. Stop distributing the affected links and pause affected scheduled sharing where available; if you cannot safely stop that distribution, contact **[support@dispoiq.app](mailto:support@dispoiq.app)** promptly for authorized handling. Ask support to review the actual deal page, existing personalized or earlier URLs, and separately accessible photographs or documents. Support records the issue, verifies your authority and coordinates authorized restriction or removal work, then explains what has been confirmed and what remains unresolved. Keep affected sharing paused until the restriction you need is confirmed.

Use only an access, expiry or withdrawal control actually available and confirmed for the affected resource. This guide promises no single-link revocation, automatic expiry, token rotation or confidential file access. A failed or blocked deletion is not a completed withdrawal; existing scheduled work and stored-file cleanup can require separate handling. Removing a page does not by itself establish that a separate file URL, cache or recipient copy is gone. Before further sharing, remove material unsuitable for a shareable page or use a method whose required access restrictions have been verified.

If a link or document reached the wrong audience, contact **[support@dispoiq.app](mailto:support@dispoiq.app)** promptly. Give the workspace, affected deal and a short description. Use a general page path in the first message rather than a complete private link or access token. Ask how to provide further evidence if needed. Do not assume changing a slug, removing a buyer or deleting a page recalls a link, stops every pending communication or removes every copy.

## 7. Privacy requests and keeping records

An individual can ask about their information without being a workspace member or paying for a subscription. Use the [Privacy Requests & Security Reporting](https://docs.dispoiq.app/policies/privacy-requests) for the contact route. Correcting an incorrect buyer association, honoring a messaging opt-out, removing workspace access and deleting personal information are different actions.

Before collecting visitor information or sharing personal or source-derived records, establish the notices, permissions, source rights and privacy choices required for that activity. Use the [Privacy Policy](https://docs.dispoiq.app/policies/privacy) and the applicable source conditions; a record's public origin or availability in your workspace does not settle those requirements. If the required basis, notice or control is unresolved, stop the affected sharing or collection and ask **[support@dispoiq.app](mailto:support@dispoiq.app)** to coordinate authorized review. A general tracking-preferences panel is not currently provided, and support email is not an automatic browser opt-out signal handler. Required technical choices must be in place for the activity they cover.

For an incorrect buyer association, identify the affected deal, approximate visit and apparent mismatch without forwarding private access tokens in ordinary email. Support records the request, checks identity or workspace authority proportionately, reviews the relevant records and coordinates authorized correction, export, deletion or restricted retention as appropriate. A forwarded personalized link or browser identifier is not proof of the visitor's identity; do not treat its activity as verified consent or erase unrelated evidence to change a buyer's apparent interest. Eligible fulfillment uses an appropriate secure method and respects source restrictions and applicable individual rights. This process does not guarantee that every recorded visit can be attributed or corrected automatically, or that every retained record must be erased.

Keep authorized copies of business-critical records before removing content or ending access. The [Data Retention, Export & Deletion Policy](https://docs.dispoiq.app/policies/data-retention) explains commercial account-closure windows and the protection for timely pending export requests. Those windows do not delay applicable individual privacy rights, extend ordinary paid application access or grant broader source-data rights.

For a suspected access problem, follow the reporting instructions above or the [Security Overview](https://docs.dispoiq.app/policies/security). This guide establishes no guaranteed response time, universal erasure promise or additional security-testing authorization.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.