Watch links and edit links
Two links per room, what each one allows, and how to revoke them.
A room has exactly two links, and they are the whole access story. Both are shared from the Access level row of the share sheet: pick the level, press Copy link, and what you copied is the link for that level. Show link puts the link itself on screen if you would rather read it.
Watch live
Anyone with this link joins, signed in or not. They see every edit and every cursor as it happens and run the simulation on their own machine. They cannot change the circuit, and their pointer shows as a muted bubble.
This is the link for a projector, a parent, or a class watching you build something before they build it themselves.
Edit together
Anyone signed in who opens this link works on the same circuit with you.
The role is in the link
Not in the interface. The role is carried by the token in the link and enforced by the room itself: an edit from a viewer is refused on the server. The read-only canvas a viewer sees is the courtesy, not the control, so there is nothing to be clever with.
Asking for the pen
A viewer gets a Watching pill beside the project title with an Ask to edit button on it. Pressing it sends one request and nothing else. The same button is in the share sheet, where somebody who joined a room they did not open sees You are watching this live with Ask to edit and Leave the room in place of the access row.
The owner gets a small toast with Allow. Pressing Allow makes that person an editor for this room. Ignoring it is also an answer: the toast goes on its own.
Inviting by email
Under People with access in the share sheet is a field placed Add people: an address, Can edit or Can watch, and Invite. Sending one needs a signed-in account. Free can invite one other person into the room. Pro and Student hold five people, and Teacher and Classroom hold the whole class.
The mail carries the room's standing link for that role rather than a token of its own, so a new link takes back every invite that went out with the old one and there is one thing to revoke instead of two. The reply goes to you, not to a noreply address. Twenty an hour per account.
If the environment has no mail switched on, the sheet says the invite could not be sent rather than claiming it was.
New link
While a live level is on, a small New link sits under the access row. It mints a fresh token for that role and kills the old one.
Revoking is per role. A new watch link drops the people holding the old watch link and leaves the editors alone, and the other way around. The room itself carries on.
Use it when a link has been forwarded further than you meant.
Ending it
Moving the access level off watch live or edit live ends the room: it takes both links back and lets everybody go. Everyone who was in it keeps their own copy of the circuit as it stood.
More on that, and on how many people fit, in how many people fit, and ending a room.
Who can share these
Only the project's owner, signed in, on any plan. The owner's plan sets how many people the room holds. See rooms.