Skip to main content

Board Permissions You Can Actually Read, Password-Protected Share Links & Message Search

· 17 min read
Copera Team
Copera Team
Product Team

Board permissions stop being guesswork. Roles are listed and explained instead of hidden behind dead controls, Members tells you why each person has access, row visibility is something you can see the impact of before you save, and See board as lets you look at the board through anyone's eyes. Alongside it: a password on any public artifact link, real message search across your channels, and a weekly AI limit that says what it is and how to get more.

New Features

Boards — Permissions You Can Read, and Change with Confidence

Board permissions used to be guesswork: read-only cells looked editable, clicking a built-in role opened a "create role" box with nothing enabled, and nothing told you who could see what or why. The whole surface is rebuilt (#3649).

  • Roles, listed and explained — every role has a page. Built-in roles are the same on every board and openly read-only: they read as statements about what the role can do, not as controls that quietly refuse you.
  • Duplicate instead of fighting a built-in role — copy any role in one step and change whatever you want. A custom role is a plain set of capabilities with no ceiling, and you can see how many of the 50 per board you have used before you hit the limit.
  • Admin, split into three — Manage members, Manage settings and Manage tables are separate now, so you can hand someone the run of the board without giving them control over who is on it.
  • Deleting a role asks who takes over — pick a replacement and everything the old role granted (tables, columns, labels) moves across rather than disappearing.
  • Members says why each person has access — board owner, added directly, through a team, workspace admin, or an older grant. The owner's row is locked and reads "Created this board", and it tells you what role new people join as.
  • Tables and columns, in plain terms — who can open a table, edit its rows and manage it, and per column who can see it, edit it or is locked out. A "Result by role" column shows what each role actually ends up with.
  • Row visibility you can see before you commit — restrict rows with labels, give each label its grantees, set a default, and let rules assign labels automatically. Saving shows the impact first ("this hides them from 4 people — see who"), and a label you set by hand is never overwritten by a rule.
  • See board as — preview the board exactly as a person, a team or a role sees it, with the reason for every difference and a link to fix it. The preview is a real sandbox: nothing you touch while it is on gets saved.
  • Permission history — who changed what and when, each entry linking to the thing it changed, including which role a copy was made from.
  • Rules that now hold everywhere — Viewers and Clients can view but not comment; commenting is its own permission. External guests can never be given management rights, directly or through a team, and cannot be the role new people join as.
  • Two admins editing at once no longer overwrite each other — table access, role edits and row labels are saved against the version you started from, so the second save is refused instead of silently winning.

A public artifact link can now be protected with a password, so you can share something outside Copera without it being open to anyone who gets the address (#3647).

  • Set it when you publish, or later — add an optional password in the publish flow, or set, change and remove one at any time from the share panel.
  • The address does not change — changing the password keeps the same link, and previously handed-out access stops working immediately.
  • Repeated wrong guesses get shut out — a visitor who keeps guessing is locked out, and one person hammering a link can no longer use up the protection everyone else depends on.
  • It survives a link rotation — rotating the address keeps the password; unpublishing or revoking clears it.
  • Visitors get a proper prompt — a clean password page in all six languages, showing nothing about the artifact until the password is right.

Workspace — A New Invite Flow, with Pending Invites and Teams

"Invite people" used to close itself the moment you clicked it, and one duplicate address could fail the whole batch. The invite dialog is rebuilt (#3646).

  • It stays open — the invite and members dialogs are owned by the header now, so opening one from the workspace menu no longer takes it down with the menu.
  • One row per person, checked before you send — each address becomes a row with its own teams and its own edit and delete. Addresses that are already invited offer Resend, ones that are already members are skipped, and invalid ones can be fixed inline — all before anything goes out.
  • Teams at invite time — assign teams per person, or use "Add a team to everyone" to apply one across the batch. A caption names the workspace's main team so it is clear everyone joins it whichever other teams you pick (#3651).
  • A Pending tab — search your outstanding invites, filter the expired ones, resend, copy the link or revoke.
  • A result screen that tells the truth — exactly who was sent an invite and who was skipped, and why.
  • Paste a list and it just works — commas, semicolons, spaces and line breaks all split correctly, and a name followed by an address in angle brackets becomes the address.
  • The same dialog everywhere — the workspace menu, Settings → Members, chat and Growth all open the same flow. Members and guests who cannot invite now get an explanation instead of a button that fails for them.
  • Guests who come back come back clean — a returning guest no longer inherits the channels, boards and teams from their previous stint, and a guest promoted to member no longer gets deactivated later on their old guest expiry date.

Chat — Search Your Messages

Chat gets real search: find a message inside the channel you are reading, or across every channel and thread you have access to.

  • In-channel and workspace-wide — search the current conversation from its header, or widen out to everything you can see.
  • Sort by relevance or by most recent — whichever matches how you are looking.
  • Only what you can already see — results are limited to the channels and threads you have access to, and deleted messages drop out of search rather than lingering in results.
  • On your phone too — the same search is available in the mobile app.

Copera AI — A Weekly Limit That Explains Itself, and a Way to Ask for More

Slow mode is retired. When a workspace's weekly AI allowance runs out with no extra credit, AI now simply pauses until the week resets — the same on every plan, paid or free — and the whole experience around that moment is rebuilt (#3643).

  • The workspace menu is the explainer — AI used this week as a share, the percentage, an actual reset date and a link to the page that explains what counts as AI usage. No more animated demo bars that looked like real numbers.
  • A quiet line at 80% — a short status under the composer, with an upgrade link for admins. It shortens itself to fit a narrow drawer instead of wrapping into a ragged block, and it shows your real percentage rather than a fixed one (#3645).
  • When you hit the limit, you get an action, not a wall — admins see Add extra credit and Upgrade plan; members get Request more AI, which notifies every workspace admin in the app and by email; guests are told to ask an admin. Extra credit is shown as a share of a week, never as a money figure.
  • One request, and it actually arrives — a member can request once per week and the button then reads Requested. If a notification fails to reach the admins, the next attempt re-sends it rather than leaving the member waiting on a message nobody got.
  • Your own budget is respected — if your personal weekly budget is spent, you keep the control that unblocks you even while the workspace is running on extra credit.
  • One line under your first AI answer — shown once, ever. No usage indicator anywhere else.

Templates — See What Goes In, and What You Are Getting

Saving a board as a template used to quietly lose most of the board. Templates are rebuilt end to end (#3641).

  • Creating a template shows what will be included — live counts of what goes in, and a plain statement of what a template never carries.
  • A template says what is inside it — its page reports its contents, and owners can edit its details or delete it.
  • Using one asks first — you give the new board a name and pick your options instead of a board appearing immediately.
  • Templates now carry the whole board — automations, dashboards, row templates, forms, views, row descriptions and status workflows all come across, with references pointing at the new board rather than the old one.
  • Docs get a real entry point — "New from template" in the create flow and on the empty state.
  • Duplicate board — copy a board directly, instead of being pushed through the template wizard or a backup file to do it.
  • Row templates behave — they only offer columns that can actually be templated, can be overwritten from an existing row, show a preview of the values they will fill in, and work the same way from every picker.
  • A gallery you can search — filter by type and search by name.

Boards — Browse and Search Linked Records from the Row Dialog

Link and lookup widgets in the row dialog used to stop at a dead "+N" once there were more records than fit (#3640).

  • "+N more" actually opens something — a read-only browse view of every linked record, with search focused and ready.
  • Search from the widget header — find a specific linked record without scrolling the list.
  • Lookup chips open instantly — clicking one goes straight to the record it points at, with none of the delay or the swallowed first click the old path had.
  • Stacked, not squeezed — several linked records in a row-dialog lookup now render one per line instead of being crushed onto a single truncated row (#3628).

Copera AI — The Pill Does What It Says

A run of work on the contextual AI pill, aimed at one thing: when it tells you it did something, it did (#3642, #3633, #3635, #3630, #3631).

  • It never claims an action it did not take — a check now verifies each claim against what actually happened, gives the assistant one chance to correct itself, and otherwise appends a plain "No changes were made" line. It works in all six languages, so a French or German claim is caught the same way an English one is.
  • Filter by column name — "show me only rows created by mike" now works. You do not have to know a column's internal identity, option labels and people's names are resolved for you, and a column that does not exist comes back named, with the table's real columns listed, instead of a silent failure.
  • Filters that apply, and stay applied — a filter issued just before a turn finishes is no longer dropped, and touching a filter by hand no longer strands every later AI filter.
  • New conversation — start over from the composer instead of dragging a growing session behind you. The assistant also stops opening every answer by restating what earlier turns did.
  • It stops refusing you after a run ends — a finished run being re-announced used to lock the composer for good, refusing every later instruction silently until you switched conversation.
  • Rows and columns the AI creates appear immediately — rows created by AI now show up on the board for everyone with their real values, and a labels column it creates is usable without a refresh.
  • Navigation counts as an answer — "take me to my Moonbase board" takes you there and is treated as done, instead of being reported as an unexpected error after it visibly worked.
  • Clearer failures — a send that fails before the assistant even starts now tells you what happened rather than showing a generic error, and your text stays in the composer.
  • The pill is bound to where you opened it — it knows which board, table and view it is sitting on, so it stops asking you which board to act on while it is already on one.

Bug Fixes

  • Recordings on Mac playing back as a frozen image — macOS needs Screen Recording permission for screen and window capture; without it the system hands over a wallpaper-only stream and nothing complains. Spark now checks that permission, explains it with a button that opens System Settings, and refuses to start without it. Capturing a window that is minimized (or a display that goes to sleep) also records a frozen frame — you now get a warning while it lasts (#3638).
  • A Spark download link that opened to nothing — the link was minted when the page loaded and expired minutes later. It is renewed at the moment you click, and a click during a renewal already in flight now waits for it instead of reporting a failure (#3638).
  • A "public" Spark link that still asked for a Copera login — a public Spark with no share token silently handed out the internal, login-walled link and could not be repaired. The link is re-minted on any save, and the share sheet now says plainly who the copied link works for (#3638).
  • The Spark toolbar stuck on screen after logging out — logging out mid-recording left the always-on-top recording toolbar floating with dead buttons until you quit and reopened Copera. The recording is now closed down properly, and a take caught mid-upload is kept locally so you can recover it after signing back in (#3638).
  • Dialogs stretching edge to edge — every dialog was being rendered at full window width instead of its intended size, including board Members settings and the call "Add people" modal (#3638).
  • Emailed calendar invites vanishing from Tempo — an invite that arrived by email could disappear for good: opening its inbox thread replayed the attachments and a cancellation buried in the thread deleted the meeting, again on every read. Thread reads no longer cancel anything, a cancelled meeting cannot be brought back by reopening an old thread, and an invite whose calendar copy has gone missing now renders from what was saved with it (#3637).
  • The Contacts drawer crashing — any workspace with at least one duplicate contact pair failed to open the drawer at all. The duplicates cards also get their avatars, titles and timestamps back (#3634).
  • The row dialog failing to open on records with lookup widgets — opening such a record threw an error instead of showing the record (#3644).
  • One broken field taking the whole row dialog down — a single misbehaving field widget now fails on its own and the rest of the record stays usable.
  • Contact cells rendering blank on boards — contact columns now show their chips and open the editor, and Email, Location, Paragraph and Tracker columns render properly in board views.
  • The automation run history drawer opening behind the builder — it slid in, flashed for a frame and vanished behind the fullscreen builder, and every later open landed behind it too. Its retry confirmation was also unreachable. Automations also stopped announcing recoverable problems as a bare "Invalid data" message (#3639).
  • An automation condition left blank never matching — a "changed from / to" condition that looked empty in the inspector was actually comparing against a literal blank value and failing every run. Blank now means "any value", as it reads (#3628).
  • All-day meetings shown at the wrong time — the channel meetings list printed all-day events as a time range, off by hours for anyone west of UTC. They show as a day now (#3628).
  • Drawers running past the bottom of the window — chat, channels, contacts and todos drawers all overshot the window with the contextual AI workspace on, cutting off composers and letting lists scroll past their end (#3645).
  • The emoji picker crashing in Safari — along with two other crashes in shared components, in drafts and in popovers. Board colours named in lowercase now resolve to the right colour instead of falling through.
  • The invite dialog crowding itself — the "Add people" and guest access fields are less cramped, and "+ Add a personal note" no longer draws over the guest box on a short window (#3651).
  • An unusable Members table on boards — the table sized itself to its widest cell, so the role column never truncated and the table ran clean off its card with no way to scroll to the rest. Columns now get real widths, the role control truncates with a tooltip carrying the full name, and the card scrolls sideways instead of clipping what it cannot fit (#3651).
  • Music flashing on screen when you join a voice channel — the mini player appeared for a moment before the room's actual music state arrived.
  • Reconnecting WhatsApp failing when the session was already disconnected — relinking now carries on instead of stopping at an error that only meant "already done".
  • WhatsApp images and stickers that could not be downloaded — inbound media with no filename now gets a sensible one based on its type.
  • Support notifications on your phone opening the wrong screen — a new omnichannel message now opens the conversation itself rather than the general chat screen.
  • "This and following" dropping a meeting's guests — editing part of a recurring series now carries the guests forward correctly, and the scope dialog no longer hangs behind Tempo's overlays.
  • The Growth card crashing the dashboard — a card that appeared or disappeared between renders could take the page down with it, and on phones the Growth header's dialogs died the moment the overflow menu closed (#3646).
  • Old sessions coming back to life after a rejoin — removing someone and re-adding them could revive the sign-ins they had before the removal. Removal now invalidates them for good, and a rejoin only ever validates the fresh sign-in (#3646).
  • A half-finished invite that could never be retried — if something failed while a member was being reactivated, the account was left half set up and the invite could not be used again. A failed attempt now rolls itself back cleanly, and retrying works (#3646).

Improvements

  • Big tables load and scroll noticeably faster — tables up to a million rows stay on the fast path, the first rows paint sooner, and "load all" pulls in a much larger batch per click. Scrolling no longer hitches while more rows stream in behind you, and heavy description bodies are skipped from the load entirely.
  • My Work keeps itself current — sources and stats refresh on their own every minute and silently catch up when you come back to the tab, without wiping what is on screen. The manual refresh moved from the stats header into the toolbar, where it sits with the rest of the controls.
  • Your email signature is applied to messages sent through the public API — sending, creating a draft and updating a draft all pick up the right signature, inserted above quoted content and never doubled up if one is already there.
  • Chat loads your conversations faster — the lookup behind your thread list is scoped to your workspace instead of scanning everything you have ever written.
  • Permission history names the role a copy came from — a duplicate now reads "created the QA role from Admin" rather than naming the copy twice (#3649).
  • A board's owner can never be demoted — the owner is always an administrator of their own board, and leaving or demoting another admin is no longer refused with a false "no administrator left" (#3649).