Forms
Forms only your people can open
Login required is the access type for when it matters who answered. A respondent has to be signed in, and you can limit that to a list of addresses or to everybody on a domain.

Two ways to say who
A list of individual email addresses, for a small named group like a committee or a set of approvers. Or a whole domain rule, so anybody with an address at your company can open it. The domain rule is what you want for staff forms, because it keeps working when somebody joins without you editing the form.
What it buys you
Certainty about who submitted. That matters for approvals, for anything with a policy attached, and for any form where a response triggers something on somebody’s behalf. It also removes the field asking people to type their own email address, which is one fewer thing to get wrong and one fewer thing to fake.
What it costs you
A sign-in step, which is a real barrier for anyone outside your organisation. Never use login required on a form you send to customers or the public: you will lose most of them at the sign-in screen, and the people you do get will be the ones who already had an account.
Combining with the other three
The four access types are exclusive, so a form is public, key protected, login required or domain restricted, not a combination. If you need a public form that only certain people can complete, the honest approach is a public form with a reference number field you check afterwards.
How it works, in three steps
Step 1
Choose login required
It is one of the four access types in the publish settings.
Step 2
Add addresses or a domain rule
A named list for a small group, a whole domain for staff. The domain rule survives people joining and leaving.
Step 3
Publish
Access settings are stored with the published version, so the live link picks the change up on publish.
The full walkthrough with screenshots is in the guide Control who can fill in your form.
Limits worth knowing
- The four access types are exclusive. A form has one of them.
- Login required is a real barrier for anyone outside your organisation.
- An allow-list is edited by hand, so it needs maintaining as people change.
See it on a finished piece
Questions people ask
Can I allow everyone at my company?
Yes, with a whole domain rule. That is usually better than a list of names, because it keeps working when somebody joins.
Should I use this for a customer form?
No. A sign-in step will lose most people who do not already have an account. Use public or a secret key instead.
Does it record who submitted each response?
Yes, that is the reason to use it. It also means you can drop the field asking people to type their own email address.
Make your own form
The button opens the generator with this use case already described. Change the wording to match yours, generate, then edit anything you like.
Create a form with OneCraftRelated pages
Control who can fill in a form
A form has exactly one access type, and choosing it is a trade between how many people can get in and how sure you are about who they were. Here are all four, and the case for each.
Embed a form on your website
A form on its own link works. A form inside your own page works better, because people never leave your site to fill it in. The piece most people miss is restricting which sites are allowed to embed it.
Forms with photo upload
When you need to see something rather than read about it, ask for a photo. The photo field takes one image, which sounds like a limitation and is actually the thing that makes the results usable: one named field per shot you need.
More finished work of this kind is on the form examples hub.


