# Push documents from your own systems
Source: https://nordvec.com/sk/docs/guides/how-to/push-documents#choose-who-can-read-it

## Choose who can read it [#choose-who-can-read-it]

`permissions` is required on every push, so a sharing decision is never made
by leaving a field out. In a datasource visible to the workspace:

| `permissions`                             | Who can read the document                                  |
| ----------------------------------------- | ---------------------------------------------------------- |
| `{}`                                      | Every member of the workspace                              |
| `{ "allowedUsers": ["ana@example.com"] }` | Only the people listed                                     |
| `{ "allowedGroups": ["GROUP_ID"] }`       | Members of those workspace groups, including nested groups |
| `{ "allowAllTenantMembers": false }`      | Refused: a document nobody can read is a delete            |

To change who can read a document without sending its content again, use
`POST /documents/push/permissions`. Making an already-restricted document
visible to the whole workspace additionally needs the `index:acl-widen` scope,
so a routine sync cannot quietly undo a restriction someone set by hand.