Skip to the page
Get started

Docs · Publishing

Publishing a Check

Giving a Check an address anybody with the link can read — what they see, and what they cannot.

Publishing gives a Check an address that anybody with the link can open, with no account.

It is an admin's decision, described in the code as the single most consequential button in the product. That is the right framing: you are putting figures from your systems on the open internet, protected by nothing but the obscurity of the address.

#Doing it

Open the publish panel. Before publishing it states plainly what you are about to do:

Anybody with the link — No account needed to read it. Readers cannot change anything.

Press Publish and you get the address, a copy button, and a way to mail it to somebody.

The slug is minted once and never re-minted. Unpublish and republish and the same address comes back, which means a link you sent last year still works.

Publishing is refused if:

  • the licence has lapsed — though unpublishing is always allowed, on every tier and in every state, because a licence that could trap a report in public would be worse than one that expired;
  • the tier does not include publishing;
  • the Check has no comparison chosen yet.

#What a reader can do

They canThey cannot
Read the resultChange anything
Re-run it against your live systemsSee the SQL, the connection or the data source names
Filter — by the Check's enabled parameters, and by row statusSee parameter bindings
Export to Excel or PDFReach any other Check
Read a specific past run at its own address
Summarise, where a model is attached
Run an investigation, only if you opted in

That second row deserves attention: a reader can cause queries to run against your production systems, at whatever rate they press the button.

#What is exposed

The name, the description, the enabled parameters with their bindings stripped, the resolved choices for those parameters, and the result.

Never: connection strings, SQL, data source names, aggregation internals, or how a pick list is bound.

An investigation shown to a reader is narrowed further — each step gives its name, its kind and a target name rather than an id, because a name cannot be turned into a request. When a reader runs one, Mosaic looks the row up from the stored run rather than accepting a row from the browser.

#Access control, stated plainly

It is a secret link. There is no authentication.

  • No password, no expiry, no allow-list, no per-reader identity.
  • Anyone with the link, for as long as it is published.
  • The published flag is the authorization, and every request re-checks it rather than trusting the link.

If a Check contains figures that must not be seen by whoever the link reaches, do not publish it. There is no halfway setting.

Unpublishing takes effect immediately, including run permalinks and investigation endpoints.

#Addresses

AddressWhat
/checks/<slug>A published Check
/reports/<slug>A published flat report
/checks/<slug>/run/<id>One run, as it finished — what a notification links to
/checks/<slug>/investigate/<id>One investigation
/apps/<slug>A published app

Plural is published; singular is the editor. /check/<id> is the workspace's own address and /checks/<slug> is the reader's. That one letter is load-bearing, and the fork is taken before either half of the application loads — a published link can never open the editor.

Either segment opens either kind, for ever. Every page lived at /reports/<slug> when a Check was still called a report, and slugs are unique across both, so the page draws itself correctly and quietly corrects the address afterwards.

#Letting readers investigate

A separate switch, off until you say otherwise, and also an admin's:

Anybody with the link can run these investigations against the systems their steps name, and read the figures of any check a step runs — including checks that are not themselves published.

Read that twice before turning it on. It reaches past the published Check into others.