Hi Ryan, Although I don't know of an option as such to prevent users from sharing projects with outside vendors, I suspect you could get very close by restricting the creation of users to SysAdmins only, and then procedurally ensuring that only end users whose email addresses belong to your organization (ie "internal only") are ever assigned Access Levels. A healthy dose of widely scrutinized exception reports would be prudent, too. That said (although you'd need to educate your internal reviewers), I'd also suggest that implementing a well-designed and controlled Group Based security would be an even better solution. Regards, Doug Doug Den Hoed - AtAppStore