← All guides

3 min read · Updated August 2026

Notion Permissions & Sharing: Control Who Sees What

A clear map of Notion sharing: workspaces, teamspaces, page-level sharing, and guest access, plus the defaults that keep private things private.

Notion sharing is powerful because it works at three levels at once: the workspace, the teamspace, and the page. That flexibility is also why private content leaks when the defaults are wrong. This guide maps each layer and the settings that keep sensitive pages locked down.

Layer 1: The workspace

The workspace is the top level. Members invited to the workspace can see every teamspace that is open. The first decision is who is a member at all. For contractors and short-term collaborators, use guests (page-level shares) rather than workspace members.

Layer 2: Teamspaces

A teamspace is a folder of pages with its own member list. Use teamspaces to segment by function: Operations, Engineering, Finance. Make a teamspace private so only invited members see it, or open so the whole workspace can.

Default to private teamspaces

Create new teamspaces as private by default. It is easier to open access later than to chase down a leak. Sensitive functions (finance, HR) should stay private even in a small company.

Layer 3: Page-level sharing

Any page can be shared independently of its teamspace. This is how you invite a guest: share the specific page by email and pick their role.

The four page roles

  • Full access can edit, share, and delete. Reserve for owners.
  • Can edit can change content but not sharing settings.
  • Can comment can read and leave comments.
  • Can view is read-only.

Give the least power that still lets the person do their job. Most external collaborators need Can view or Can comment.

Public sharing

Toggle Share to web to make a page public without a login. Use it for help docs, public roadmaps, and published content. Never enable it on a page that contains private sub-pages, because public sharing exposes the page and everything under it that is not separately restricted.

The inheritance trap

A page inherits the most permissive setting among itself and its ancestors. If a parent is public, making the child private does not hide it. To truly restrict a page, restrict the chain above it.

Guests vs members

A guest is free on paid plans up to a limit and only sees the pages you share. A member is a billed seat with broader access. The rule of thumb: if someone needs more than a handful of pages, make them a member of a scoped teamspace; if they need one or two pages, share as a guest.

A safe default setup

1. One open teamspace called General for company-wide docs.
2. Private teamspaces for each function that handles sensitive data.
3. Page-level guest shares for external collaborators.
4. Public sharing only on a dedicated Published teamspace.

Audit regularly

Every quarter, open the share menu on your most sensitive pages and confirm the guest list is still current. Offboarding a contractor is not complete until their page shares are revoked.

Templates that ship with sane defaults

The store's templates come with a recommended permissions structure baked in, so a fresh workspace starts private-by-default rather than open-by-accident.

Want this built for your practice, not just read about it?

Book an intro call