The companion to Share access & invite caregivers:
that one shows you how to let someone in. This one answers the harder
questions — what can they actually see, what stays private, and what
changes the moment you take access away.
About 10 minutesFor: whoever owns the record
Three things worth knowing first
Sharing grants access. It never transfers ownership. The
record stays yours. Everyone else works in it as a guest, at a level
you chose and can change.
Hidden is not deleted. When something isn't visible to
someone, it is being withheld from them — not removed from your
record. It's still there, and still yours.
Access is per record. Granting someone access to one
person's record tells them nothing about any other record you manage.
If you look after two people, that's two separate decisions.
“What can this person see?”
Everything follows from the access level you pick. The single biggest
line is between processed content — AI summaries, the care picture,
care plans, open items — and the original uploaded documents
behind it.
Access levels you can grant through sharing, and what each one carries. These are the shipped defaults, applied as a set — you pick the level, not the individual permissions.
Level
Summaries & care picture
Original documents
Add records
Chat
Export
Manage access
Caregiver
Yes
Yes
Yes
Yes
Yes
No
Guardian
Yes
Yes
Yes
Yes
Yes
Yes
Advocate
Yes
No
No
Yes
No
No
Viewer
Yes
No
No
No
No
No
Two things the table can't show
Nobody but you can delete. Deleting records isn't part of any
level you can grant — not even guardian. That stays with the record's
owner.
Guardian is caregiver plus one thing: the ability to manage
who else has access. If you give someone guardian, they can invite and
remove other people from your care team. Give it deliberately.
Care team · Ana Belova-Ferreira
Rai Okonjo-Lindqvist — caregiver · adult child
Can view · raw records · add records · chat · export
Wren Aleksandrov — advocate · professional
Can view · chat · no raw records
A schematic care team with two synthetic people at different levels. Each row spells out what that person can do.
Summaries versus the original documents
This is the distinction that makes limited access useful rather than
merely restrictive.
Shown
What an advocate or viewer still sees
The AI-written summaries, the care picture assembled from them, care
plans and follow-ups, open items, and structured values pulled out of
your records — lab results and vitals, for instance. Enough to follow
what is happening and be useful in a conversation.
Withheld
What they don't get
The uploaded files themselves and the raw text taken from them. Where a
document would be, they see a short line saying raw records aren't
visible at their level, with the summary underneath. Passages that
would have quoted raw text directly are blanked out of the summary too
— the sanitising is applied to the content, not just the file.
“What stays private?”
Beyond the access level, individual items carry their own visibility. Two
people at the same level can see different things.
Per-item visibility
Shared with the care team — the default. Everyone with access
to the record can see it.
Private — only the person who created it. Not the care team,
and not the other party. A private note or appointment you write stays
yours; one a caregiver writes stays theirs.
Shared with specific people — supported underneath, but the
picker for choosing those people isn't in the app yet, so in practice
today you are choosing between team-visible and private.
Conversations with the CAIR Agent
Chat is not automatically an open book to everyone on your care team. It
follows the same per-item rule as notes and appointments.
How a conversation's visibility setting decides who can open it. The check runs after record access, so it can only narrow the audience, never widen it.
Setting
Who can open it
Shared with care team
Anyone with access to the record.
Private
Only whoever started it.
Shared with specific people
Whoever started it, plus anyone explicitly added. (No picker in the app yet.)
The questions people actually ask
Does giving someone access show them my old conversations?
Only the ones already marked as shared with the care team. A private
conversation stays private to whoever started it — changing someone's
access level does not reach back and open it.
Is a private chat deleted? No. It is withheld from others and
still fully yours.
What about after I remove someone? Record access is checked
first, so once it's gone, every conversation in that record is closed
to them — shared ones included.
Exports
Exporting is the one place where two permissions have to line up, and it
catches people out.
A care-plan export needs both export rights and original-document access
The exported plan carries raw record text inside it, and there is no
summary-only version yet. So the app requires both — and checks
them separately. Someone without original-document access is refused
even if export was switched on for them, with a message explaining that
record exports are unavailable at their level.
In practice: caregivers and guardians can export; advocates and
viewers cannot. There is no summary-only export for limited roles
today.
Two different things called “export”
The Care Plan export — one care plan as a document to take to
an appointment. Covered in
Export the Care Plan.
A full copy of your account data — a different, account-level
request, with its own rules. It covers your own account rather
than records you have access to, and it honours the same raw-document
rules the app enforces.
Exporting a copy of your data
covers what's in it and what it leaves out.
Removing someone's access
You can do this at any time, for any reason, without warning them. It
takes about ten seconds.
1
Select the right record
Access belongs to one record, so start by making sure that record is
the one selected at the top of the app. If you manage more than one
person, removing someone from Ana's record leaves any access they
have to Bo's record untouched.
2
Open Sharing
Go to app.naviacair.com/sharing. The Care team panel
lists everyone with access, each with their level and a plain summary
of what they can do. You'll only see this panel on records where you
are allowed to manage access.
3
Press Remove, then confirm
Each member's row has a Remove button. Pressing it doesn't do
anything yet — the row turns into a confirmation asking
“Remove access?” with Yes, remove and No. Nothing
happens until you choose.
Care team
Wren Aleksandrov — advocate · professional
Remove access? [ Yes, remove ] [ No ]
The inline confirmation. The owner's own row has no Remove button — you can't remove yourself this way.
On success you'll see “Access removed for {name}.” If something
goes wrong you'll get a plain failure message and the person stays on
the list — nothing is half-done.
4
Invitations and requests are cancelled separately
Someone who hasn't accepted yet isn't on the care team, so they have
no row to remove. Instead:
A pending invitation has its own Revoke button,
with its own confirmation — “Revoke invitation?” — and
confirms with “Invitation revoked.” The emailed link stops
working.
A pending access request is theirs, not yours: you decline
it from your inbox, and the person who sent it can withdraw it from
their side. See
Requesting access to a patient.
“What changes when I remove them?”
Their access ends at the server the moment you confirm. Here is what that
actually looks like from their side.
Gone
The record disappears from their app
It drops out of the patient selector, so they can no longer choose it.
If they were helping only you, they're left with nothing to open.
Gone
Every part of the record is refused
Summaries, original documents, care plans, conversations, exports — all
of it. Keeping a direct link doesn't help: the app answers as though the
record simply isn't there, which is deliberate, so a removed person
can't confirm it still exists.
Gone
A page they already had open
Anything already drawn on their screen stays drawn until the app next
asks the server for something — a refresh, a navigation, or the next
background fetch. There is no live wipe of another person's screen. The
moment it does ask, it is refused. Treat “as soon as they reload” as the
honest answer, not “instantly, everywhere”.
Stays
Anything they already took out of NaviaCAIR
A care plan they exported, a page they printed, a screenshot, notes they
copied elsewhere. Removing access cannot reach those. This is the one
limit worth understanding before you share with anyone.
Stays
What they contributed, and the fact that they had access
Records they uploaded, notes and conversations they created stay in your
record, still attributed to them — removing someone doesn't erase their
work from your care history. The access itself is marked as withdrawn
rather than wiped, so the history of who had access, and when, remains.
A few edges worth knowing
You can't remove the last owner. A record must always have
one; the app refuses and says so.
Changing your mind later is fine. Re-granting access reuses
the same care-team entry rather than creating a second one, and you can
bring someone back at a different level than before.
Removing twice is harmless. If it's already done, the app just
confirms it's done.
Only someone allowed to manage access can remove people —
you, or anyone you made a guardian.