







Fifth shape in the atproto permissioned data series: polls. The member list is the electorate, your PDS holds only your own ballot, a vote's record key mirrors the poll's, and a leaked ballot proves nothing because permissioned commits are deniable.
Permissioned Data Shapes: Polls
ngerakines.leaflet.pubJul 20, 2026 at 6:27 PM
Permissioned Data Shapes: Polls - Nick's Blog
A poll is a space, a ballot is an address, and read_self is the ballot screen: voters cast and change their own votes while no voter's client can read anyone else's.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned data is a love triangle - Nick's Blog
Permissioned data is a love triangle between the user, the identities they grant permissions to, and the applications everyone uses to view controlled data. We don't need to change or reinvent the protocol to have it, because ATProtocol already supports it.
Permissioned Data PDS Lexicons
I wanted to share a first pass of the PDS lexicons for the permissioned data protocol to get some feedback while the paint’s still wet! You can check them out on my working branch: Comparing main...permissioned-data · bluesky-social/atproto · GitHub They’re all under the com.atproto.space namespace: atproto/lexicons/com/atproto/space at permissioned-data · bluesky-social/atproto · GitHub Confidence rating on Lexicons is probably like ~70-80%. Broad strokes, I think the shape is there. Though ...


Permissioned data on atproto — pick your depth
A private room in a place with no walls: how engineers are adding permissioned data to atproto. Read it plain-language or technical.
Permissioned Data Diary 3: Your Bucket, My Data - Daniel's Leaflets
The third in a series of posts building up a solution to permissioned data on atproto. We look at two different models for where buckets live and why the simpler-looking one doesn’t work out.
Fourth shape in the atproto permissioned-data series: forums. The Gem City Forum mixes public and private categories, moderates with wrapper records instead of labels, and stays open to any app view its members trust.
Permissioned Data Shapes: Forums
ngerakines.leaflet.pubNext up is private events as I explore the shapes of permissioned-data spaces in atproto.
Permissioned Data Shapes: Private Events
ngerakines.leaflet.pubSeventh in the atproto permissioned-data series: notifications. One self-keyed space per identity, every app writing through a create-only grant, and a reader you choose doing the triage. The self shape returns, direction flipped.
Permissioned Data Shapes: Notifications
ngerakines.leaflet.pubThird shape in the atproto permissioned-data series: a Pokémon Go club with its own DID. Ordinary Bluesky posts in a members-only space, moderation notes and labels inside the same boundary, and one allowlisted app view as the only window in.
Permissioned Data Shapes: Community-Moderated Content
ngerakines.leaflet.pub