







Stepping outside the shapes series for a deep dive: how space configuration decides which people and which apps get credentials. Here be dragons.
Permissioned Data Shapes: Notifications - Nick's Blog
A self-keyed space gives notifications a home you control: every app gets an append-only sink to write into, you pick the reader that turns them into pushes and emails, and allowing or revoking an app is an access control you already have.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Diary 5: What’s in a Name? - Daniel's Leaflets
In this permissioned data diary, we dive deep into the URI structure for permissioned data on atproto and use it to motivate a bunch of the larger design.
Permissioned Data Interlude: Spaces - Daniel's Leaflets
In which I retcon the naming of everything.
Permissioned Data Shapes: Self-Only Bookmarks - Nick's Blog
A self-only space is the smallest shape permissioned data can take: one authority, one member, one repo, and private bookmarks that share a record shape and a write path with public ones.
Spaces as Layers - Nick's Blog
Public anchor records paired with sidecar records in permissioned spaces give ATProtocol apps a composable pattern for blending open discoverability with controlled access.
Permissioned Data Diary 2: Buckets - Daniel's Leaflets
The second in a series of posts building up a solution to permissioned data on atproto. We introduce buckets: a new protocol primitive for creating a shared social context.
How to handle granular permissions | Authorization Resources | Google for Developers
Granular permissions give users more control over the specific data they share with apps, improving transparency, security, and trust.

Permissioned Data Shapes: Private Events - Nick's Blog
here it is folks! lots of details to still nail down, but this is roughly where our heads are at for the design of a permissioned data protocol give it a read and let me know your thoughts!
Permissioned Data Diary 4: The Big Picture
dholms.leaflet.pubSeventh in the atproto permissioned-data series: notifications. One self-keyed space per identity, every app writing through a create-only grant, and a reader you choose doing the triage. The self shape returns, direction flipped.
Permissioned Data Shapes: Notifications
ngerakines.leaflet.pubA deep dive on permissioned-data space access. The dials, policies, and the difference between handing out keys and revoking them.
Permissioned Data: Space Access
ngerakines.leaflet.pubThere is one area with Permissioned Data Spaces that I haven't seen discussed. It reveals that data is currently stored in the (I think I'm coining a term here) *Public Space* on Personal Data Servers. Remember, most people on Bluesky aren't aware of where their data is stored, or what that means.
The smallest permissioned data shape: a bookmarks space with a member list that never grows past me. Same bookmark record the atmosphere already uses, same write path, different address. URIs, scopes, tokens, and the full credential flow inside.
Permissioned Data Shapes: Self-Only Bookmarks
ngerakines.leaflet.pubPermissioned Data Shapes: Self-Only Bookmarks - Nick's Blog

The Atproto Spaces Alpha is Live - AT Protocol
Reintroducing Spaces - Daniel's Leaflets
Permissioned Data Diary 1: To Encrypt or Not to Encrypt - Daniel's Leaflets