---
title: "Restrict who can view a demo (allow and block lists)"
slug: "/help/account/company-settings/restrict-viewer-access"
topic: "demos"
last_updated: "2026-07-22T09:20:45.328Z"
---

Walnut lets you control exactly who can open a published demo by maintaining an **allow list** and a **block list** of viewer emails or domains. You can manage these lists per demo in its Share settings, and set a company-wide default in Company Settings.

## **Overview**

By default, access to a demo is governed by your demo access settings (for example, "anyone with the link" or "specific viewers"). On top of that, allow and block lists give you fine-grained control over **which email addresses or domains** are permitted to view a demo:

-   **Allow list** — only the listed viewers can open the demo; everyone else is denied. Use it to restrict a demo to specific customers or internal teams.
-   **Block list** — the listed viewers are denied; everyone else can view. Use it to keep out competitors or specific domains.

You can add either individual **email addresses** (for example, `jane@acme.com`) or whole **domains** (for example, `@acme.com`) to either list.

:::note[Reviewer note]

Confirm the exact in-product labels and menu paths (Share settings / access controls) against the live app before publishing — the labels below are described generally and may differ slightly in the UI.

:::

---

## **Set Access for a Single Demo**

Each demo can carry its own allow and block lists, which override or add to your company defaults for that demo.

1.  Open the demo you want to restrict.
2.  Go to its **Share** settings.
3.  Find the access controls where you can manage the **allow list** and **block list**.
4.  Add the viewer **emails** or **domains** you want to allow or block.
5.  Save your changes.

The lists take effect for that demo's shared link.

:::tip[Emails vs. domains]

Add a full email address (`jane@acme.com`) to allow or block one person, or a domain (`@acme.com`) to cover everyone at an organization.

:::

---

## **Set a Company-Wide Default**

Admins and Account Owners can maintain workspace-wide allow and block lists that apply to **every demo** automatically, so you don't have to configure access on each demo individually.

1.  Go to **Company Settings → Account settings → Demo access control**.
2.  Locate the **allow and block lists**.
3.  Add the emails or domains you want to allow or block across all demos.

Only Admins and Account Owners can edit the company-level lists.

For the full set of related workspace access controls, see [**Company Settings**](/help/account/company-settings).

---

## **Bulk Upload with CSV**


To set up a long allow or block list quickly, you can use a **CSV bulk upload** so you can import many emails or domains at once instead of entering them one by one. This is rolling out gradually and may not be available in your workspace yet.


---

## **FAQs**

### **What happens if a viewer is on both lists?**

Reviewer to confirm precedence in the live app before publishing. Typically a block takes priority, but verify the exact behavior.

### **Can I use these lists together with "collect viewer email"?**

Yes. Allow and block lists work alongside your other demo access settings, such as gating the demo behind a viewer email. See [**Company Settings**](/help/account/company-settings) for the related toggles.

### **Who can edit the lists?**

Anyone with access to a demo's Share settings can manage that demo's lists; the company-wide default lists can only be edited by Admins and Account Owners.
