---
title: Access and sharing
description: Every person and organization that can see part of your Lexpoint file, exactly what each one sees, and how to revoke each kind of access.
product: Lexpoint — Individuals
audience: People managing their own Canadian immigration
doc_type: reference
canonical_url: https://docs.lexpoint.io/individuals/account/access-and-sharing/
app_routes: https://my.lexpoint.io/app/settings/access, https://my.lexpoint.io/app/settings/associations
last_verified: 2026-09-05
keywords: who can see my Lexpoint data, revoke access, share ImmiReport, partner organization, third party case access, household account, employer connection, stop sharing
license: Documentation © Lexpoint. Quote with attribution and a link to the canonical URL.
---
# Access and sharing

Five different kinds of access can exist on a Lexpoint account, and they are not the same thing.
A shared ImmiReport link is public to whoever holds it. A partner-code connection is profile consent.
An employer sees what you consented to on an invite page. They are granted separately and they are
revoked separately. The default servicing organization listed under Associations is a routing
default, not an access grant and not a client–counsel relationship — see
[Lexpoint and professional advice](/individuals/consultations/who-advises-you/).

Sharing controls live at
[**Settings → Access**](https://my.lexpoint.io/app/settings/access) (ImmiReport link and case grants).
Relationships live at
[**Settings → Associations**](https://my.lexpoint.io/app/settings/associations) (family, partners, employer).
Old `/app/settings/security` links redirect there.

```media
id: settings-access-sharing-overview
type: screenshot
caption: Settings → Access → ImmiReport. Sharing lives here; family, partners, and employer live under Associations.
shot: /app/settings/access?tab=immireport — ImmiReport / Cases tabs, Link & access, Primary service provider with new routing caption. Light mode, 1440×900 cropped to 1383×776. Hide header name/email. Keep Immigratic.
src: /media/individuals/settings-access-sharing-overview.webp
```

## The five kinds of access

| Access | Who gets it | What they see | Where you revoke it |
|---|---|---|---|
| **Shared ImmiReport link** | Anyone who has the link, plus the PIN if you set one | Your ImmiReport | ImmiReport → Link & access |
| **Primary service provider** | Your default servicing organization | ImmiReport visibility only | Read-only — contact support |
| **Third party case access** | A partner-code organization you already connected, on one named case | One Immigratic-hosted case, at the level you choose | Cases → Third party |
| **Partner connection** | An employer, school, agency, or other organization you connected with a partner code | Basic profile and immigration status (as consented) — not counsel | Partners → Active → **Revoke** |
| **Employer connection** | An employer whose invite you accepted | Immigration information shared through the connection, and roster visibility | Employer → Active → **End** |

Sharing lives under **Settings → Access** (ImmiReport, Cases). Relationships live under
**Settings → Associations** (Family, Partners, Employer). The default servicing organization on
Partners is a routing default — see [Lexpoint and professional advice](/individuals/consultations/who-advises-you/).

---

## Your ImmiReport link

The **ImmiReport** tab has three sub-tabs: **Link & access**, **PIN & expiry**, and **Activity**.

If you have not created an ImmiReport yet, the tab reads *Create an ImmiReport first to enable
sharing*.

### Turning sharing on and off

Under **Link & access**, **Share with others** — *Allow others to view this report via a secure
link* — is the master switch. Turn it on and Lexpoint generates a link of the form
`/report/<your report code>`, shown under **Shareable URL** with a **Copy** button.

Lexpoint may generate a PIN at the same time, shown as **PIN Auto-Generated** with a **Copy**
button and the note *Save this PIN securely. Share it with anyone who needs to access your report.*

:::caution[The link is the credential]
The panel says it plainly: *Anyone with this link can view your report.* There is no per-person
invitation and no way to see who a link was forwarded to. If you sent it to a consultant who then
forwarded it, the report is open to whoever holds the URL until you turn sharing off or a PIN
blocks them.
:::

Turning **Share with others** off stops the link working. It is the single fastest way to close
everything in this section.

### PIN

Under **PIN & expiry**, **PIN management** adds *an extra layer of security with a 6-digit PIN*.
The PIN must be exactly six digits — a shorter one is rejected with *PIN must be exactly 6 digits*.

**PIN Status** reads **Active** or **Inactive**. When a PIN is set, the current PIN is displayed
and copyable from this panel, so you can retrieve it later rather than resetting it.

### Expiry

Also under **PIN & expiry**, **Link expiration** states the rule: while sharing is on, the link
stays valid for **30 days** from when you last turned sharing on or changed your PIN. The panel
shows the exact expiry date and a countdown chip — *12 days left*, *1 day left*, *Expires today*,
or **Expired**.

To start a new 30-day period, either turn sharing off and on again, or change your PIN while
sharing is on.

:::note[Why a link can work after you revoke]
The panel adds that access tokens remain valid for **7 days** after being issued. A viewer who
already passed the PIN holds a token for that window. Turning sharing off is still the correct
action; understand that a session already established is not necessarily severed the same second.
:::

### Who has opened it

**Activity** shows the access log: **Date & Time**, **Email**, **Status**, and **Browser** for each
attempt, with a **Professional** badge on viewers Lexpoint identifies as professionals. Denied
attempts appear alongside granted ones.

The access log is a **Pro** feature. On the free plan the tab shows an upgrade panel instead of the
entries. Full filters and export live on the dedicated share page, reachable from **Open full
sharing page →** at the bottom of the tab.

### Primary service provider

Above **Share with others** sits **Primary service provider** — *Whether your ImmiReport is visible
to your default servicing organization. This is report access, not a retainer.* It reads *Shared
with [organization]*, *Not currently shared with [organization]*, or *No primary service provider
is assigned to your account yet.*

This toggle is **read-only**. Changing it does not change who a consultation or case would be routed
to. Contact support if the named organization looks wrong.

The default servicing organization itself lives on
[**Settings → Associations → Partners**](https://my.lexpoint.io/app/settings/associations?tab=partners-active).
Listing a firm there does not create a client–counsel relationship — see
[Lexpoint and professional advice](/individuals/consultations/who-advises-you/).

---

## Cases

### Third party case access

**Cases → Third party** is how you let an organization you have already connected see one specific
case. The panel describes it as sharing *specific Immigratic-hosted cases with partners you have
already connected under Partners (profile consent)*.

Two constraints are enforced by the form itself:

- The case list contains **only Immigratic-hosted cases you own**.
- The organization list contains **only organizations you have granted profile access to** under
  Partners. With no active partner connections, the form tells you to add a partner first.

Each grant carries an access level:

| Level | Meaning |
|---|---|
| **View** | Read the case |
| **Contribute** | Take part in the case |
| **Manage** | Manage the case |

Grant one from the **+ Add** sub-tab: pick the case, pick the partner organization, pick the access
level, then **Grant access**.

**To change a level**, use the dropdown on the row under **Active** — the change saves immediately.

**To revoke**, click the bin icon on the row. You are asked to confirm: *Remove third party access
for this case? The organization will no longer see it on the partner portal.* Revoked grants move to
the **Revoked** sub-tab, where a restore button puts one back if you removed it by mistake.

Revoking the underlying partner connection removes this too — the panel states that case access is
removed automatically if you revoke that partner connection.

---

## Associations

### Family

Family lives at [**Settings → Associations → Family**](https://my.lexpoint.io/app/settings/associations?tab=family),
not on Access.

**Household Account** shows your connected household account, with a **Disconnect** button.
Disconnecting asks you to confirm — *Disconnect this household account? This will remove the active
household link.* — and then removes the active link.

**Invites & History** holds pending invites and the record of disconnected or unlinked spouse and
common-law records. Pending invites can be resent or revoked from here; revoking an invite asks
*Revoke this invite?* first.

If an invite cannot be sent because of a conflict, Lexpoint blocks it before sending and explains
why in an **Invite Blocked** dialog, rather than sending something that would fail.

There is no Delegates setting. Nobody has delegate access to your account.

### Partners

Partners has two blocks that are easy to mix up.

**Default servicing organization** is a routing default — who Lexpoint would send a consultation,
proposal, or case to. Being listed is not a retainer or a client–counsel relationship. Immigratic is
the only service provider rolled out on Lexpoint today. Other licensed firms are not available yet.
See [Lexpoint and professional advice](/individuals/consultations/who-advises-you/).

**Partner organizations** are connections you make with a **partner code**. They are profile
consent: an employer, school, agency, or other organization can view parts of your profile and
immigration status. A partner-code connection is not a client–counsel relationship and it is not how
licensed second-opinion firms will work when that is available.

```media
id: settings-primary-service-provider
type: screenshot
caption: Associations → Partners — default servicing organization (routing) above partner-code connections (consent).
shot: /app/settings/associations?tab=partners — Default servicing organization (Immigratic + licence line) above Partner organizations Active. Light mode, 1440×900 cropped to 1383×776. Hide header name/email. Keep Immigratic. Redact other partner names.
src: /media/individuals/settings-primary-service-provider.webp
```

**To connect one**, open **+ Add New**, enter the partner code or referral link they gave you (a
short code such as `passage`, or the full link), and press **Preview**. Lexpoint shows you who the
organization is, its type, and the specific data they will be able to access, before anything is
granted:

| Scope shown in the preview | What it covers |
|---|---|
| **Basic profile & status** | Your basic profile and immigration status |
| **Immigration report** | Your immigration report |
| **Case progress** | Your case progress |

You then have to tick the consent box — *I consent to share my basic profile information and
immigration status with this organization. I can revoke this access at any time* — before the
**Connect** button becomes usable.

The panel is explicit about the ceiling. Partners can see:

- Your name and contact information
- High-level immigration case status
- Key milestones and progress

And it states that they **cannot** see your documents, detailed answers, or financial information.

**To revoke**, open **Active** and press **Revoke** on the organization. You are asked to confirm:
*Are you sure you want to revoke access for [partner]? They will no longer be able to see your
profile or case status.* The connection moves to the **Revoked** sub-tab, which keeps the date you
connected, the date you revoked, and the reason — so the history of who once had access is not
erased along with the access.

```media
id: settings-partner-preview
type: screenshot
caption: The partner preview, showing who the organization is and what they would be able to see, before consent.
shot: /app/settings/associations?tab=partners-add — enter a valid demo partner code and press Preview so the preview card, scope chips, and consent checkbox are all visible. Demo account, light mode, 1440×900. Redact the partner code.
```

### Employer

**Employer connections** lists *employers on your Lexpoint workforce roster*, under **Active**,
**Ended**, and **Pending**.

```media
id: employment-settings-employer-connections
type: screenshot
caption: Settings → Associations → Employer → Ended. Active, Ended, and Pending are the three lists. Immigratic kept; the other employer name is redacted.
shot: /app/settings/associations?tab=employer-ended — Employer tab, Ended selected, two ended cards. Light mode, 1440×900 cropped to 1383×776. Hide header name/email. Keep Immigratic Visa Services. Redact GetGuide Inc.
src: /media/individuals/employment-settings-employer-connections.webp
```

Each active row shows the employer name, the connection status, the date you connected, and, where
recorded, your job title, the employment period, and the employment context.

**You cannot connect yourself with a code.** Your employer sends an invite email with a Lexpoint
link — *they must invite you; this is not a partner code*. Invites you have signed in for but not
yet consented sit under **Pending**. You finish consent on the invite page itself.

**To revoke**, press **End** on the row. The confirmation spells out the consequence:

> End connection with [employer]?
>
> [employer] will lose access to immigration information shared through this connection, including
> visibility on their workforce roster. You can reconnect later if they send a new invite.

Ended connections move to the **Ended** sub-tab with both the connected and ended dates. Reconnecting
requires a fresh invite from the employer — ending a connection is not something you can undo on
your own.

---

## If you want to close everything

There is no single master switch. In order of how exposed each one leaves you:

1. **ImmiReport → Link & access** — turn **Share with others** off. This is the only access that a
   stranger can hold.
2. **Cases → Third party** — remove each active grant.
3. **Partners → Active** — **Revoke** each organization. This also clears their case access.
4. **Employer → Active** — **End** each connection.
5. **Family → Household Account** — **Disconnect**.

ImmiReport visibility to the default servicing organization is platform-managed. Changing the
default servicing organization is not self-serve — contact support through
[**Help & Support**](https://my.lexpoint.io/app/tickets). Revoking a partner code does not change
the default servicing organization.

## Related

- [Privacy and your data](/individuals/account/privacy/) — what Lexpoint stores and how to export it
- [Deleting your account](/individuals/account/delete-account/) — the end of the line, and what survives it
- [Two-step verification](/individuals/account/two-step-verification/) — stopping someone signing in as you in the first place
- [Your ImmiReport](/individuals/immireport/) — what is actually in the report you would be sharing
- [Employment](/individuals/employment/) — the employee side of an employer relationship

## Frequently asked questions

### How do I stop sharing my ImmiReport immediately?

Go to Settings → Access → ImmiReport → Link & access and turn off Share with others. The link stops working right away. Anyone who already loaded the report keeps what is on their screen, but cannot reload it.

### Can a partner organization see my documents?

No. The Partners panel states that partners see your name and contact information, high-level immigration case status, and key milestones and progress. It also states they cannot see your documents, detailed answers, or financial information.

### If I revoke a partner, does their case access go too?

Yes. Third party case access is built on top of a partner connection, and the panel states that case access is removed automatically if you revoke that partner connection.

### Why can I not turn off sharing with my primary service provider?

That toggle is ImmiReport visibility to your default servicing organization. It is read-only. Changing it does not change who a consultation or case would be routed to, and it is not a retainer. Contact support if it looks wrong.
