







Sixth in the permissioned data series: what spaces do to feeds. The firehose stops at the space boundary, the credential flow becomes your membership source-of-truth, and one feed URI serves a different skeleton to every viewer.
Permissioned Data Shapes: Feeds
ngerakines.leaflet.pubJul 24, 2026 at 7:35 PM
Permissioned Data Shapes: Feeds - Nick's Blog
Public feed generators drink from a firehose that permissioned data never enters, so a feed that includes space content has to become a syncer, keep a live model of who can see what, and serve a different skeleton to every viewer.
Permissioned Data: Space Access - Nick's Blog
Stepping outside the shapes series for a deep dive: how space configuration decides which people and which apps get credentials. Here be dragons.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Interlude: Spaces - Daniel's Leaflets
In which I retcon the naming of everything.
Sometimes You Just Want to Hold the Entire Network in Your Hand - AT Protocol
Jim and Alex are back on the livestream. The permissioned data proposal has shipped, updates from Tangled, Roomy, and Anisota, and a look ahead at Jetstream v2.

Modeling communities on permissioned data - Daniel's Leaflets
Arguing against "universal spaces" and raising a couple questions that come up as a result.
Overview | HappyView
Spaces are containers for permissioned data in atproto. Unlike regular public records that live in a user's repo, space records are gated by membership — only members can read or write data within a space.

Spaces as Layers - Nick's Blog
Public anchor records paired with sidecar records in permissioned spaces give ATProtocol apps a composable pattern for blending open discoverability with controlled access.
@dholms.at thinking about permissiones data. What if: Permissioned data URI was at://<PDS did>/<record type>/<rkey> exactly the same as public data. The PDS would handle the space assignment opaquely and do a 4xx response with some space aturis. Client goes and grabs a space cred and retries
There is one area with Permissioned Data Spaces that I haven't seen discussed. It reveals that data is currently stored in the (I think I'm coining a term here) *Public Space* on Personal Data Servers. Remember, most people on Bluesky aren't aware of where their data is stored, or what that means.
Seventh in the atproto permissioned-data series: notifications. One self-keyed space per identity, every app writing through a create-only grant, and a reader you choose doing the triage. The self shape returns, direction flipped.
Permissioned Data Shapes: Notifications
ngerakines.leaflet.pubnew data diary! (and i think final in the main series) this gets into the permissioned repository itself. how it's structured, signed & synced. give it a read & as always, lmk your thoughts!
Permissioned Data Diary 7: Off the Record
dholms.leaflet.pubA deep dive on permissioned-data space access. The dials, policies, and the difference between handing out keys and revoking them.
Permissioned Data: Space Access
ngerakines.leaflet.pubPermissioned Data Shapes: Self-Only Bookmarks - Nick's Blog

The Atproto Spaces Alpha is Live - AT Protocol
Reintroducing Spaces - Daniel's Leaflets
Permissioned Data Diary 1: To Encrypt or Not to Encrypt - Daniel's Leaflets