







I've been exploring permissioned data spaces technology and components, thinking about what the end-result is going to look like. @dholms.at's last dev diary has some good nuggets and I decided to jump into an ECMH implementation.
ngerakines.me/ecmh-rs
tangled.orgApr 3, 2026 at 9:26 PM
Permissioned data by dholms · Pull Request #94 · bluesky-social/proposals
This is an initial proposal for permissioned data. Details, terminology, and behaviors are all likely to change. For a friendly introduction to the protocol, check my my Leaflets. For discussion, f...
Permissioned Data Diary 2: Buckets - Daniel's Leaflets
The second in a series of posts building up a solution to permissioned data on atproto. We introduce buckets: a new protocol primitive for creating a shared social context.
Permissioned Data Diary 3: Your Bucket, My Data - Daniel's Leaflets
The third in a series of posts building up a solution to permissioned data on atproto. We look at two different models for where buckets live and why the simpler-looking one doesn’t work out.
The Arbiter - Group Management for Permissioned Spaces and Beyond - Zicklag's Leaflets
The permissioned data proposal has the concept of membership, but leaves it to the app to orchestrate it. The arbiter is our idea for a general-purpose, interoperable ATProto group membership service.
Permissioned Data Diary 1: To Encrypt or Not to Encrypt - Daniel's Leaflets
The first in a series of posts about major design decisions along the way to a permissioned data protocol for atproto.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned data on atproto — pick your depth
A private room in a place with no walls: how engineers are adding permissioned data to atproto. Read it plain-language or technical.
here it is folks! lots of details to still nail down, but this is roughly where our heads are at for the design of a permissioned data protocol give it a read and let me know your thoughts!
Permissioned Data Diary 4: The Big Picture
dholms.leaflet.pub@dholms.at thinking about permissiones data. What if: Permissioned data URI was at://<PDS did>/<record type>/<rkey> exactly the same as public data. The PDS would handle the space assignment opaquely and do a 4xx response with some space aturis. Client goes and grabs a space cred and retries
continuing to build up our permissioned data protocol! this one asks what a bucket actually is and where the data that constitutes a bucket is stored. it argues for maintaining the atproto ethos in the permissioned data protocol as always, looking forward to hearing your thoughts!
Permissioned Data Diary 3: Your Bucket, My Data
dholms.leaflet.pubhere it is folks! lots of details to still nail down, but this is roughly where our heads are at for the design of a permissioned data protocol give it a read and let me know your thoughts!
Permissioned Data Diary 4: The Big Picture
dholms.leaflet.pubMe and @zicklag.dev have been having a closer look at the system sketched out in @dholms.at's Permissioned Data Diaries - we generally like it! And have some scenarios in mind that may be worth considering
Evaluating permissioned spaces for community contexts
meri.leaflet.pubPermissioned Data Shapes: Self-Only Bookmarks - Nick's Blog

The Atproto Spaces Alpha is Live - AT Protocol
Reintroducing Spaces - Daniel's Leaflets
Permissioned Data Diary 1: To Encrypt or Not to Encrypt - Daniel's Leaflets