Blog · Teams

Search that respects who can see what

On a team server, Duct only shows people the files they could open at the source. How we map sharing to search, and why we fail closed.

A shared search engine has one job before any other: never show someone a document they shouldn't see. A search box over a company's Google Drive that ignores sharing is a leak with a nice interface.

When Duct runs as a team server with sign-in, results from Google Drive and Microsoft 365 follow each file's sharing at the source. If you couldn't open it in Drive, you won't find it in Duct.

Three people search for "payroll". Ada in HR sees the budget, the salary review, the handbook and the board minutes; Chidi in finance sees the budget but not the salary review; Bola in sales sees only the handbook and the minutes
One server, one search, three people. The salary review is shared with HR; the budget with Ada and Chidi. Everyone sees the handbook and the board minutes.

Principals

Each document can carry an access list of principals:

  • user:ada@okafor.ng, one person
  • domain:okafor.ng, everyone signed in with that company's email
  • anyone, everyone who can use the server

When you sign in as ada@okafor.ng, you match user:ada@okafor.ng, domain:okafor.ng and anyone. A document is visible to you if its list contains one of those. Documents without a list, such as folders the admin chose to share with everyone, are visible to everyone on the server.

Google Drive lets you share a file with "anyone with the link". That's how most files get overshared: a link pasted into one email is technically readable by anyone. If Duct treated that as "anyone", every such file would become searchable by the whole company.

So it doesn't. Drive tells us whether a domain or public share is discoverable (allowFileDiscovery). Only discoverable shares count. Link-only sharing is ignored.

Failing closed

Every time Duct isn't sure, it hides rather than shows:

  • If a file's sharing can't be read, the file is visible only to the person who connected the source.
  • If Microsoft or Google returns an error for a file's permissions, the same.
  • Files shared only through a group (a Google group, or a Microsoft 365 group) are hidden from that group's members for now, because Duct doesn't read group membership yet. Hiding them is wrong in a way people notice and tell us about; showing them would be wrong in a way nobody notices.

The access check sits in one place, the query filter every search goes through, and the same rule is applied to everything that touches a document: opening it, the documents list, exports, "Ask", the deadlines radar, the suggestions on the home screen, and notebooks. A notebook shared with you never shows quotes from documents you can't open, even if the person who shared it can.

Anything that addresses a document by its path is checked before it reaches the handler, so a new feature can't forget. And the tests sign in as different people and check what each one can find.

Notebooks, too

Notebooks are where people collect quotes from documents and share them with colleagues. Sharing a notebook can't be a back door: Ada's notebook includes a quote from the salary review, and when she shares it with Chidi, he sees every note except that one.

Chidi's view of Ada's shared notebook: the quotes from the Acme contract and the board minutes, with who added each, and no quote from the salary review
Chidi's view of a notebook Ada shared with him. Her quote from the salary review isn't there, and he can't tell it ever was.

The parts that are still yours to decide

Admins can set each source to follow its sharing, to be visible to everyone, or to be visible to chosen people and domains. Following sharing is the default whenever sign-in is on. The full details are in the deployment guide.