How to Give Clients Visibility Without Exposing Your ClickUp Workspace
Short answer: Start from the fact that Spaces, Folders, Subfolders, Lists, tasks and Goals in ClickUp are public by default — only Dashboards are private out of the box. That default, combined with four specific inheritance behaviors, is why agencies keep discovering clients could see more than intended. You can lock this down inside ClickUp with private structures and disciplined naming, and you should. But the only approach that removes the risk permanently is not putting clients inside your workspace at all.
Below: what's exposed right now, the four ways access leaks silently, a ten-minute audit, and the two real strategies.
The default nobody checks
From ClickUp's documentation: Spaces, Folders, Subfolders, Lists, tasks and Goals are public by default. Dashboards are the exception — those start private.
"Public" here means visible to everyone in your Workspace with their role-based permissions, not visible on the open internet. That distinction matters, but it doesn't help much when the person you added to your Workspace is a client.
Making things private is available on all plans. Only Enterprise workspaces can set new Spaces to be private by default, which means on every other plan, every new Space your team creates starts open and stays that way until somebody remembers.
The four ways client access leaks
These are all documented ClickUp behaviors, not bugs. Each one has caught agencies out.
1. Tasks in Multiple Lists carries visibility with it
A task living in a private Space, added to a public Space via Tasks in Multiple Lists, becomes visible to everyone who can access the public Space. The privacy of the original location does not travel with the task.
This is the most common leak in agency workspaces, because Tasks in Multiple Lists is exactly the feature people use to surface client work into a shared delivery view.
2. Moving a Folder or List out of a private Space makes its tasks public
Move a Folder, Subfolder or List from a private Space into a public one and the tasks inside become public. Reorganizing your hierarchy — which every growing agency does — silently changes who can see what.
3. Permissions survive a Space going public
When members or guests with limited permissions are granted full access to a Space, Folder or Subfolder, and that location later changes from private to public, they retain those permissions. Access granted for one temporary reason persists after the context that justified it is gone.
4. Everything inside a shared item is shared
Share a List with a guest and they get what's in it: task names, internal comments, custom field values, assignees, estimates, attachments. There is no client-safe rendering layer. A task titled "hold this until we sort out the Q3 overrun" is visible the moment its List is shared.
The ten-minute audit
Do this before you change anything. You need to know your current exposure.
List everyone external. Workspace avatar → People. Note every guest and limited member, and what type each one is.
Check the lock icons. Open each Space. A lock icon means private; the icon in the upper-right shows how many people and Teams have access. No lock means public — and public means every guest with a route into that hierarchy.
Audit your Tasks in Multiple Lists usage. Any task pulled from a private Space into a shared one is exposed. This is where to look first.
Read your task names as a client would. Search your workspace for the words your team uses when something is going wrong — "escalate", "fired", "margin", "internal", "don't send". Anything in a client-shared location gets renamed today.
Check custom fields. Internal rates, margins, effort scores and account health flags all render inside the task. If a client can open the task, they can read the field.
Check who was granted temporary access. Anyone given elevated permissions during a project that has since ended still has them.
One operational note from ClickUp's docs worth knowing: if the only person with access to a private Space leaves it, the Space becomes inaccessible to everyone. Always keep at least two people on private Spaces.
Strategy 1 — Lock it down inside ClickUp
This keeps clients in your workspace and puts structure around what they can reach. It's free and it works up to a point.
Separate internal from client-facing at the Space level
Two Spaces per client relationship, or one client-facing Space and one internal Space that never gets shared. Delivery tasks that clients should see live in the shared structure; anything about the account, the margin, or the relationship lives in the private one. The rule has to be simple enough that a new hire follows it without asking.
Set privacy at creation, not later
Because everything starts public on non-Enterprise plans, "we'll lock it down when we share it" means there's a window where it's open. Make privacy part of the template for a new client Space.
Adopt a naming convention that assumes a client is reading
Not "don't write sensitive things in task names" — that fails under pressure. Instead: every task in a client-facing structure is named as if the client is looking at it, because they might be. Internal context goes in a comment inside the private counterpart, or in a Doc that isn't shared.
Use view-only public links instead of guest seats where you can
Publicly shared items are view only, which is a limitation and also a safety property. A shared view with filters applied is the tightest read-only surface ClickUp offers, and it costs nothing. Note that private Lists, Subfolders, Folders and Spaces cannot be shared publicly at all.
Re-audit on a schedule
Quarterly, or every time you reorganize the hierarchy. The four leak behaviors above all trigger on ordinary work — moving things, sharing things, hiring people. A one-time cleanup decays.
What this strategy can't fix
Every new client is another configuration job, and configuration is where mistakes live
Guests cannot access Chat, so conversation still happens in email regardless
Your client is still looking at your project management tool
Permission-controlled guests are billable once you exceed your plan's allowance
One person forgetting one setting undoes it
Strategy 2 — Don't put clients in the workspace at all
The leak vectors above exist because the client is inside the system. Move them outside it and the entire category of problem goes away.
A portal layer reads your ClickUp data and renders a separate client-facing surface. The client logs into their portal. They never have a ClickUp account, never appear in your People list, and never inherit anything when you reorganize your hierarchy.
What changes practically:
Exposure becomes opt-in rather than opt-out. You choose what surfaces instead of auditing what leaked.
Reorganizing is safe. Move Folders between Spaces freely — no client visibility changes.
Onboarding is a repeatable step, not a permissions decision made under time pressure.
Internal language stays internal. Your team names tasks however it wants.
Cost stops tracking client contact count.
BluOps works this way: connect your existing workspace, point each client at the Lists their work already lives in, and they get a portal with their projects, progress, files, messages and invoices. No restructuring, unlimited internal users, priced on active clients.
Which strategy fits
Lock it down inside ClickUp if
You have a handful of clients, one contact each, a workspace with little sensitive material, and someone who will genuinely run the quarterly audit. Cost: zero, plus the audit time.
Move clients outside the workspace if
You're adding clients regularly, more than one person creates structures, your workspace contains rates or account notes, or you've already had a moment where a client saw something they shouldn't have. Cost: a flat monthly fee, and the audit stops being a recurring job.
Frequently asked questions
Are ClickUp Spaces private by default?
No. Spaces, Folders, Subfolders, Lists, tasks and Goals are public by default. Dashboards are private by default. Only Enterprise workspaces can set new Spaces to be private by default.
Can ClickUp guests see my internal comments?
Yes, if the comment is on a task in a location shared with them. Everything inside a shared item is visible — comments, custom fields, assignees and attachments included. There is no client-safe view of a task.
Can guests see my whole ClickUp workspace?
No. Guests only see what's explicitly shared with them, and guests do not have access to Spaces at all. The risk isn't broad workspace access — it's that shared locations expose more than intended, and inheritance behaviors quietly widen what's shared.
Does making a Space private hide its tasks from clients?
Usually, but with two exceptions. A task from a private Space added to a public Space via Tasks in Multiple Lists is visible to anyone who can access the public Space. And moving a Folder, Subfolder or List from a private Space to a public one makes its tasks public.
How do I stop clients seeing my internal ClickUp structure?
Inside ClickUp: separate client-facing and internal Spaces, set privacy at creation, name tasks as though the client is reading, and audit quarterly. The alternative is a portal layer so clients never enter the workspace and the structure is never visible to begin with.
Can I show clients progress without giving them ClickUp access?
Yes, two ways. Public link sharing gives a read-only view with no account required, but it's view only and unavailable for private Lists and Folders. A client portal renders your ClickUp data in a separate branded surface with two-way interaction and no workspace access.
The short version
ClickUp starts public, and four ordinary actions — using Tasks in Multiple Lists, moving a Folder, a Space going public, sharing a List — quietly widen what a client can reach. You can manage that with private Spaces, strict naming and a recurring audit, and for a small roster that's the right call.
Past a certain client count, the audit is a job nobody wants and eventually nobody does. At that point the cleaner answer is that clients don't belong in the workspace. See what that looks like — 7 days of full access is $1.
Sources: ClickUp — Make Spaces, Folders, Lists, and tasks private, ClickUp — Share locations and items with a public link. Accurate as of July 2026.
