Records & sharing links
Everything a record can become once it may leave the account: a board you drag, a status a submitter tracks, a report page anyone can open, an approval decided from an inbox, a portal, a template. Every outward link follows one discipline — an unguessable, revocable token carrying a curated projection, never the data behind it.
Views: table, board, calendar, cards
A form's submissions page renders the same result set four ways. The board's columns are the workflow's own states; dragging a card takes exactly the move the record page offers, through the same endpoint, with every server-side guard intact — privilege, conditions, required fields. A drop the rules withhold explains itself in the column while the card hovers, and a move into a final state asks first. Records that predate the workflow gather in a leading No status column. The calendar places records by created, updated, or any date field; cards are the table as a grid. The chosen view rides the URL, so a colleague can be sent the board itself.
Status links: “track your request”
Any record can carry a public status page. Mint the link from the record's header (it needs the same privilege as publishing a public link — exposing a record's state is the same class of decision), and whoever holds it sees the record's current stage in your workflow, its reference number, and when it last moved. Never the answers, never who is working on it, never the rules. One link per record, stable across edits; replace retires the old URL everywhere at once.
To send one automatically, write {{status_link}} into a notification
template. The link is minted lazily, on the first send whose template actually references
it — writing the marker into the template is the decision to expose the record's
status.
Approvals by email
A workflow's Request an approval action mails each named approver their
own approve/decline link — the person who signs off on requests rarely wants another
account, and now they never need one. You delegate exactly one move per verdict when you
author the action, and choose which fields the approver's page shows; nothing else from
the record ever reaches it. The decision lands with a name, a comment and a timestamp on
the record's Approvals tab, a later move can require
`approval_status` = "approved", and with several approvers the move waits for
every yes while any no reads declined. See workflows for the
authoring details.
Shared reports, embeds, badges and digests
A saved grouped report — counts, sums, averages per category — can be shared four ways: a live read-only page at a tokenized URL, an iframe embed of the same page for your own site, a live badge — a one-number SVG image for READMEs, wikis and docs, served off the same token and available when the report's first count or sum can be honestly totalled — and a daily or weekly email digest to up to twenty addresses whose owners never need an account. A report that lists individual records is refused at sharing time, and a shared report later edited into a listing goes dark rather than serving rows: aggregates travel, records never do. The digest letter itself carries the numbers and a link to the live page when one exists.
The submitter portal
The portal lets the people who filled your forms in track all their records with nothing but their email address. It is off until you switch it on, per form, by choosing which EMAIL field identifies the submitter — in the form's settings strip, under the submissions table. Only that field ever matches: an address that merely appears somewhere inside a record (a reference, a cc) never unlocks it.
Once enabled, the public form page grows a “track my submissions” affordance. A visitor types their address; if any records match, a link is mailed to that address — possession of the mailbox is the credential — and the page answers identically whether anything matched, so the request itself confirms nothing. The mailed link lasts 24 hours and lists each record's status, exactly what its status page would show.
Publishing a form as a template
Share as template, in the form's menu, publishes the form's design at a public link anyone can clone from. What travels is the design: fields, calculations, show/hide rules, outcomes, and the workflow's states and moves. What never travels is anything org-local — records, dataset bindings, linked-record fields, notification templates, integrations, recipients. The stripping happens when you publish, not when someone reads, so the published copy never held anything private. Publishing again refreshes the template from your live form at the same link; rotate or remove it any time.
Two ways to put a published template in front of people. The same dialog has a community gallery switch: asking lists your template — after a quick review — on faldaro.com's templates page, attributed to your organization by name, and turning the switch off delists it immediately, approval or not. And a public form link's own dialog can offer visitors cloning: with the per-link switch on and a template published, the form page itself carries a quiet "clone this design" line — every public form becomes a doorway to making one like it.
Counters, QR codes and link previews
A public form link's dialog also has a response counter switch: on, the
public page shows the form's response count as social proof — a number counted
server-side, never a window into the records behind it, and off by default like every
disclosure here. Every share dialog offers the link as a downloadable QR
code (PNG for print, SVG for design tools) — rotating the link orphans every
printed code, which is exactly what rotation means. And a pasted /f/,
/t/ or /v/ link unfurls in chat and social apps as a real
preview card — the form's name and description, the template's shape, the report's title;
never numbers, and never anything from a status, portal, claim or signing link, whose
pages must stay out of preview caches entirely.
Mentions and linked records
Typing @ in a record's comments offers your organization's members; a mention
sends the comment by email with a link to the record and surfaces a “Mentioned you” card on
the recipient's dashboard. Every mentioned id is re-checked against membership on the
server, mentions are capped per comment, and the write is audited like any other. A
linked record field holds a reference to a record of another form —
validated on every write to exist, be live, and belong to exactly the declared form — and
is deliberately absent from public forms: a picker over your records has no business in
front of an anonymous visitor.
What every link here has in common
A 256-bit token that is the whole of the URL's authority; revocation by rotating it, which kills the old URL everywhere at once; a payload that is a curated projection of exactly what the surface needs; and uniform refusals, so probing a link never reveals whether it existed. On the Free plan these pages — and the notification emails your forms send — carry a small “Powered by Faldaro” line; paid plans remove it. The features themselves ship on every plan — sharing must never hit a paywall.