Skip to main content
Orchestration sharing controls let administrators decide whether every Orchestration owner can share with teammates or whether sharing requires a role permission. By default, Allow unrestricted orchestration sharing is on. When it is on, Orchestration owners can share their owned Orchestrations. When it is off, owners must also have Share Orchestrations before they can share.
Restricting sharing changes who can add, update, or remove Orchestration collaborators. Confirm which owners should keep sharing access before you save the setting.

How sharing access works

ControlWhat it allows
Allow unrestricted orchestration sharingLets all Orchestration owners share owned Orchestrations.
Share OrchestrationsLets a user share owned Orchestrations when unrestricted sharing is off.
Publish OrchestrationsLets an owner publish an Orchestration to the whole organization.
Publisher roleGrants operational publishing permissions, including Share Orchestrations and Publish Orchestrations.
Sharing and publishing are different actions. Sharing adds named collaborators. Publishing makes the Orchestration visible to everyone in the organization.

Before you start

Confirm you have the right administrator access:
TaskRequired access
View organization settingsPermission to view organization settings.
Turn off unrestricted sharingPermission to edit organization settings.
Create or edit a custom rolePermission to create or edit roles.
Assign Publisher or a custom rolePermission to assign roles to users.
Also decide which Orchestration owners should keep sharing access before you change the setting.

Restrict Orchestration sharing

You need permission to edit organization settings before you can change this control.
1

Open Organization Settings

Go to the administration area and open Organization Settings.
2

Open General

Select General.
3

Find Orchestration Sharing

In Orchestration Sharing, find Allow unrestricted orchestration sharing.
4

Turn off unrestricted sharing

Turn off Allow unrestricted orchestration sharing.
5

Save changes

Click Save Changes.
After this setting is off, Orchestration owners without Share Orchestrations will see sharing controls disabled or blocked. Sofie may show that Orchestration sharing is restricted to users with sharing permission.

Grant sharing access with the Publisher role

Use the Publisher role when a user should be able to share and publish Orchestrations without broad administrator access.
1

Open User Management

Go to Users.
2

Open the user

Select the user who should be allowed to share Orchestrations.
3

Open role assignment

Find the role assignment section.
4

Choose Publisher

Select Publisher.
5

Save the role change

Save the user update and confirm the user can see the expected sharing or publishing controls.
Publisher includes more than Orchestration sharing. It can also include publishing access for other reusable content. Use a custom role if the user should only share Orchestrations.

Create a custom sharing role

Create a custom role when you want narrower access than Publisher.
1

Open Role Management

Go to Users and click Manage Roles.
2

Create a role

Click New Role.
3

Name the role

Use a clear name such as Orchestration sharer.
4

Select Orchestration permissions

Open the Orchestrations permission category and select Share Orchestrations.
5

Add publishing only when needed

Select Publish Orchestrations only if users with this role should publish owned Orchestrations to the whole organization.
6

Save the role

Save the role and assign it to the users who should keep sharing access.

Choose who should get access

Grant Share Orchestrations to users who:
  • Own reusable Orchestrations that other users need to run or edit.
  • Maintain department or project workflows.
  • Need to manage collaborator access after unrestricted sharing is turned off.
Grant Publish Orchestrations more selectively. Published Orchestrations appear to the organization, so the owner should test the workflow, verify inputs, and confirm review points before publishing.

What Orchestration owners can do

An owner with sharing access can:
  • Open Share Orchestration.
  • Add people.
  • Choose Can edit or Can view.
  • Add a note for recipients.
  • Update collaborator access.
  • Remove collaborators.
An owner with publishing access can publish a live Orchestration to the organization. Published Orchestrations can be viewed and run by organization members, while only the owner and editors can modify them.
Test the change with one Orchestration owner before rolling it out broadly. Have that user open an owned Orchestration and confirm whether Share and Publish appear as expected.

Review after rollout

After you restrict sharing:
  • Review who has Publisher or a custom sharing role.
  • Confirm key workflow owners can still share Orchestrations.
  • Confirm users without the permission cannot add collaborators.
  • Check whether any shared Orchestrations should instead be published for organization-wide reuse.
  • Review role assignments when workflow ownership changes.