Access and participants
Private polls and invitations
Inviting people, revoking access, and what happens to a ballot afterwards.
A private poll is visible only to the people its owner invites. Everyone else is told the poll does not exist.
Inviting people
On the poll's invitation page, search for someone by name or email address and select them. Invitations reference existing accounts — there is no invite-by-email-address flow, so you can only invite people who have already registered.
Everyone invited gets an in-app notification and a queued email, in their own language, with a link straight to the poll. The poll also appears on their dashboard.
Inviting is idempotent. Saving the same list twice does not send a second email, and the database has a unique constraint on the pair of poll and person as a backstop.
Access errors are deliberately vague
Someone who was not invited does not get "you are not allowed to see this poll". They get not found, exactly as though the link were wrong.
This is intentional. "Forbidden" would confirm that a poll exists at that address, which is itself information — that a decision is being made, and roughly when. The 404 page is generic and mentions no poll.
The same applies to a draft: until it is published, everybody but its owner gets not found.
Revoking access
Revoking blocks all future participation immediately. The person loses sight of the poll, cannot vote, and cannot change anything they had submitted.
A ballot they already cast is kept, and still counts.
This is a deliberate decision worth being explicit about. The alternative — deleting the ballot — would let an organiser change a published or pending result by removing voters after the fact. That is precisely what a voting tool must not permit. So the ballot survives, the activity log records that it was preserved, and the count stays honest.
Re-inviting someone whose access was revoked restores it, and sends a fresh invitation.
Who can do what
| Owner | Invited | Signed in, not invited | Not signed in | |
|---|---|---|---|---|
| See the poll | yes | yes | not found | not found |
| Add options | yes | if the poll allows it | no | no |
| Vote | yes | yes | no | no |
| See published results | yes | yes | not found | not found |
| Manage the poll | yes | no | no | no |
| Export results | yes | no | no | no |
Every row is a policy check on the server, tested against the whole matrix. No row depends on a hidden button.
Public polls do not use invitations
Invitation management is unavailable on a public poll and the endpoints refuse it — the link is the access grant. If you need to control who takes part, make the poll private.
Regenerating the link
Invited people still reach a private poll through its unguessable link, so if that link leaks the owner can regenerate it. The old URL stops working immediately, for everybody. Invitations are unaffected; only the address changes.
When to prefer a private poll
Use one whenever it would matter that somebody voted twice.
Both kinds of poll now require an account to take part, and in both the database allows exactly one ballot per account. The difference is who is entitled to one: a public poll admits anybody who registers, so a determined person can confirm a second address and vote again. A private poll admits exactly the accounts on its invitation list, which makes a second ballot impossible rather than merely inconvenient.