# Sharing with clients

> Invite external contacts to view a project in Connect, and control what they can see.

**Connect** is the GIMLabs client portal - a read-only view of a project for
external contacts. You set up and control that access here in Manage, from a
project's **Connect** area, which appears when your company uses Connect.

## Invite a contact

Choose **Invite contact**, enter their **name** and **email**, and set what they
can see and do. They receive an email to set up a Connect account, then sign in and
view the project. See the [Connect platform page](https://www.gimlabs.io/platform/connect)
for the contact's side.

## What you can grant

Each contact's access is controlled by a set of per-contact permissions:

| Permission | What it allows |
| --- | --- |
| **Export data** | Download project data in the available formats. |
| **Geology overlay** | Show geological descriptions alongside the data. |
| **Hole status** | Show each location's status. |
| **Empty tables** | Show tables that contain no data. |
| **Complete locations only** | Hide locations still in progress. |
| **Locations only** | Restrict the view to location data. |
| **View media** | Show project photos and documents. |
| **Create chain of custody** | Let the contact raise chain of custody records. |
| **Create testing schedules** | Let the contact create testing schedules. |

### Which labs a contact can see

When you grant **Create testing schedules** or **Create chain of custody**, you
also choose **which laboratories** that contact can schedule against, from a
checklist in the invite (and edit-permissions) dialog. This is an
**allow-list**: the contact only sees the labs you tick, and every test under
the labs you leave unticked stays hidden. Tick nothing and they see no labs or
tests at all - so they can view existing testing but can't build a new schedule.
Your lab list and test catalogue are your service offering, so nothing reaches a
client you didn't deliberately share.

## Manage access over time

- **Access expiry** - every contact's access has an expiry date; extend it with
  the **+30d** / **+90d** buttons or pick a date.
- **Permissions** - edit a contact's permissions at any time.
- **Revoke / Restore** - revoke access to remove it, and restore it later if
  needed.
- **Activity** - see each contact's activity: when they **logged in**, **viewed** a
  table, and **exported** data.

<Callout type="note" title="Roles control who can manage access">
  Inviting, editing and revoking each need the matching Connect permission on your
  role. Connect access does not depend on your plan - it is available wherever your
  company has Connect enabled.
</Callout>
