
Bolt rebuilt project sharing from the ground up
Bolt has overhauled its project sharing model with a new role-based collaboration system designed to give teams more granular control over who can view, edit, and manage projects. The update introduces three distinct permission levels, a redesigned publishing flow, and built-in security protections for sensitive credentials.
The new collaboration model defines three roles: Viewer (open, view, duplicate projects), Editor (prompt and edit code), and Co-owner (full control including access management). Teams can now invite individual members by email, select from a team directory, or set a team-wide default role that automatically applies to new projects. This last feature addresses a common workflow gap where teams previously had to manually configure access for every new project.
Publishing splits from permissions
Publishing is now handled through a separate interface. Project owners and co-owners can choose between Public (live site visible to anyone) or Private (invite link with trusted domain controls). The trusted domain feature lets organizations automatically grant viewer access to anyone with an approved email domain, such as @company.com, without requiring individual invites for every team member.
Only project owners and co-owners can publish projects or modify site visibility settings. This separation prevents editors from accidentally exposing work-in-progress projects while still allowing them to contribute code.
Environment variables stay hidden from viewers
The update includes a security feature that prevents viewers from accessing environment variables, even when they can see the codebase. This addresses a longstanding risk in collaborative development platforms where sharing access to a project could inadvertently expose API keys, database credentials, and other secrets stored in environment configuration.
The feature is particularly relevant for teams using Bolt's recent Supabase integration or Netlify deployment options, where database connection strings and deployment tokens are typically stored as environment variables.
Why this matters
Bolt's approach mirrors enterprise collaboration patterns seen in tools like GitHub and Vercel, but adapted for prompt-driven development. By separating viewing, editing, and ownership permissions, teams can share prototypes with stakeholders without granting code modification rights, or let developers collaborate on projects without exposing infrastructure credentials.
The team-wide default role feature is especially useful for agencies and consultancies who spin up multiple client projects. Setting a default of "No access" ensures new projects start private, while internal tools can default to "Viewer" for company-wide visibility.
The update rolls out to all Bolt users immediately. Teams already using Bolt will need to review existing project access settings, as the new role system replaces the previous binary shared/not-shared model.
Sources
1 checkedHow we cover tool news: Create With's tool desk drafts these reports with AI from the sources listed above and checks them against those sources before publishing.





