> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://katalyz.crisp.help/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Choosing the right access setting

Every time you share a room, you pick one of three access settings. Each trades off friction for verification. Pick the one that fits the sensitivity of the content.

![](https://storage.crisp.chat/users/helpdesk/website/-/5/5/4/8/554891f22af0b400/katalyz-sharing-modes_knx6d7.png =591xauto)

## The three modes at a glance

| Mode | How buyers verify | Friction | Best for |
|---|---|:---:|---|
| **Anyone with the link** | None | ⭐ Lowest | Public content, generic demos |
| **Authorized emails only** | Email on allow-list | ⭐⭐ Medium | Most sales conversations |
| **Magic code verification** | Email + 6-digit code | ⭐⭐⭐ Highest | Pricing, contracts, signatures |

> **Personal magic link bypasses the mode.** Whichever access setting you pick, an invited participant who clicks **their own personal magic link** (the one Katalyz emailed them) lands directly in the room — no email prompt, no code, no allow-list check. The access setting only kicks in when someone arrives via the **plain room URL** instead.

## 1. Anyone with the link

Open access — no allow-list, no code. Behavior depends on **how** the visitor opens the room:

- **Via the personal magic link** (the one Katalyz sends to invited participants by email) → they're logged in directly, no prompt. Activity is attributed to their identity.
- **Via the plain room URL** (e.g. someone forwarded it, or pasted it) → the visitor is asked for an **email** before continuing. The email is **not validated against an allow-list** — anyone can type anything — but it gives some attribution and tracking.

So it's not "zero friction in all cases" — there's still an email prompt for raw URL visitors. What it doesn't do: verify that the typed email belongs to the visitor, or restrict who can claim to be whom.

**Use for:**
- Publicly shareable content (case studies, generic demos, marketing material)
- Early-stage prospecting where friction kills interest

**Don't use for:**
- Pricing, contracts, confidential business info
- Content you don't want forwarded or indexed

## 2. Authorized emails only

You list specific emails. When someone opens the link, they enter their email — if the typed string **matches** one in your allow-list, they get in.

> **It's a string match, not real email verification.** No code is sent, no link is clicked to prove ownership. If a visitor knows (or guesses) an authorized address, they pass through claiming to be that person. So this mode raises the bar on "who can wander in" but doesn't prove identity. For that, use **Magic code verification**.

Authorized users do get sent their own personal magic link by email when you invite them — so legitimate participants don't need to re-type anything.

**Use for:**
- Active sales conversations where you know who should see the room
- Internal collaboration with named team members
- Content sensitive enough to warrant gating, but not critical

**Strengths:** tracks activity per person (accurate analytics for participants who arrived via their own magic link), keeps random forwarded opens out, low friction.

## 3. Magic code verification

Buyers enter their email → receive a 6-digit code → enter the code to access.

**Use for:**
- Pricing, contracts, legal documents
- Signature workflows
- Compliance-sensitive content
- Deals where you want highest-assurance identity verification

**Strengths:** prevents link-sharing attacks, establishes email ownership at time of access.

**Tradeoff:** adds a step. Buyers sometimes don't receive the code (spam filters, corporate gateways) — see [Magic code isn't arriving](https://katalyz.crisp.help/en/article/the-magic-code-isnt-arriving-1i9xg2y/).

## How to change the mode later

You can change a room's access setting anytime. Existing authorized users keep access unless you revoke manually.

1. Open the room.
2. Click **Share** (top right).
3. Change the access setting.
4. Save.

## Example reasoning (illustrative only)

Just as one possible way to think about it — the right choice depends on your own context, policies, and risk tolerance:

- *Public content (case study, generic demo)?* Some teams pick **Anyone with the link**.
- *Active sales conversation with a known buyer?* Some pick **Authorized emails only**.
- *Pricing, contracts, signatures, compliance-critical content?* Many lean on **Magic code verification**.

Your team should establish its own guidelines based on the sensitivity of the content and the regulatory environment you operate in.

## Related articles
- [How magic links work](https://katalyz.crisp.help/en/article/how-magic-links-work-1o0pj80/)
- [Inviting buyers](→ 02-rooms/08-sharing-access/04-inviting-buyers)
