The situation is common. A temp at the loading dock needs to log deliveries, a volunteer at the door needs to record arrivals, a contractor needs to note each inspection. The spreadsheet those rows belong in also holds everything else: other tabs, phone numbers, rates, last year's records. You want them to add a row and see nothing.
Google Sheets sharing has three levels, viewer, commenter and editor, and none of them means add rows only. So the answer is never a sharing setting. It is something that sits in front of the sheet and writes the row on the person's behalf, while the sheet itself stays shared with nobody new.
Written by QR to Sheets, which sells the scanner link described below, so weigh that accordingly. The free routes come first, and for typed input from a handful of people the first one is genuinely enough. Google behaviour was read from Google's own help pages on 2026-10-06.
Why sharing the file is the wrong tool
The instinct is to share with the least access possible and lock down the rest. It is worth being precise about what each level actually exposes before relying on it:
- An editor can open every tab, change or delete any cell that is not protected, and open version history to see what the sheet looked like before.
- A viewer can read everything. Google's help states that spreadsheet viewers can still access content in hidden sheets: a viewer who makes a copy can unhide them.
- Anyone with the link set to editor is the riskiest version of all. The link gets forwarded, and every person who receives it has full edit access with no name attached.
- Removing access means remembering to remove each person afterwards. With rotating temps and volunteers, that list is never quite current.
Free route 1: a Google Form in front of the sheet
This is the standard answer and usually the right one. Build a Google Form with a question per column, link it to your spreadsheet, and give staff the form link or a printed QR code that opens it. Each submission becomes a new row. Google's help separates two kinds of sharing: collaborators can edit the form and see its data, while responders can only fill it in and submit. Staff are responders, so they never get the spreadsheet.
For typed answers from a few people, stop here. It costs nothing. Where it breaks:
- Everything is typed. A form field is a text box with no camera scanner, so a parcel number, an asset tag or a badge ID is typed or pasted from another app, with typos to match.
- Results can leak through a setting. If View results summary is turned on, Google shares summary charts and text responses with anyone who can respond. Keep it off.
- Limiting each person to one response needs a sign-in. Google states that Limit to 1 response requires respondents to sign in to their Google Account, which most temporary staff will not want to do on a work task.
- The link works for anyone who has it, from anywhere. A form cannot tell you which phone or which location a row came from.
- No signal, no row. A submission attempted without a connection fails, and in a basement or a warehouse corner that is a lost record.
A longer side-by-side of the two approaches is in Google Forms versus a scanner link.
Free route 2: share the file and protect ranges
Data, Protect sheets and ranges lets you lock tabs or cells so that only chosen people can change them, or show a warning before an edit. Both owners and editors can set protection, and the owner can always edit a protected range. It is a good way to stop trusted colleagues breaking formulas by accident. It is not a way to keep data from people:
- Staff still need edit access to the file, so they can open every tab, protected or not.
- The warning option does not block anything. Google describes it as a message asking people to confirm that they really want to edit.
- Hiding a tab hides nothing. Google states that all spreadsheet editors can unhide and view hidden sheets.
- Google's own help says protection should not be used as a security measure, because people can print, copy, paste, and import and export copies of a protected spreadsheet.
Free route 3: a separate intake sheet
Give staff their own small spreadsheet with only the input columns, and pull its rows into your private master sheet with IMPORTRANGE, filtered with QUERY if you need to. The master is never shared. Google's help explains that the first IMPORTRANGE from a new source asks for permission, and that access stays in place until the person who granted it is removed from the source.
- The intake sheet is still shared, so every member of staff can see, edit and delete everyone else's rows in it.
- The import is a mirror, not a copy. A row deleted in the intake sheet disappears from the master too, so the master is not a record unless you copy rows out of it.
- Add-ons automate a version of this. Share Single Sheet, listed on the Google Workspace Marketplace as free of charge with paid features as of 2026-10-06, shares one tab as a separate spreadsheet with two-way sync. The recipient still edits a normal spreadsheet, with the same exposure as above for that tab.
Free route 4: an Apps Script web app
Google Apps Script can serve a small web page whose submit button appends a row. Deployed with Execute as set to Me, Google's documentation says the script always executes as you, the owner of the script, no matter who accesses the web app. Staff therefore add rows without any access to the spreadsheet, and with the access setting at Anyone they need no Google account either. It works, and it is free. The costs are real:
- You write and maintain the page and the script. A camera scanner, an offline queue and protection against double submits are all your own work.
- Quotas apply. Google lists 6 minutes per execution and 30 simultaneous executions per user, and states that all quotas are subject to elimination, reduction or change at any time.
- It belongs to one person's account. When the person who wrote it leaves, someone has to own the script and the deployment.
Where QR to Sheets fits
QR to Sheets is built for the case where the row is a scan: a delivery, an arrival, an asset, a checkpoint. The admin signs in with Google once, connects the spreadsheet and creates a scanner link that writes to one tab. Staff open the link in their phone browser, allow the camera and scan. QR to Sheets writes each scan as a new row, so the person scanning never has access to the spreadsheet, not even view access, and never needs a Google account.
- Revoking the link stops it at once, from anywhere. There is no sharing to undo and no account to delete, which is what makes it workable for running check-in remotely with venue staff you have never met.
- Each phone that scans takes a device slot, and a phone beyond your plan's device count cannot add rows.
- Scans made without signal are kept on the phone and sent when the connection returns, keeping their scan time.
- Rows are only ever added. The person scanning cannot edit or delete earlier rows, because they never touch the sheet.
- A damaged code can be typed into the scanner's manual entry field, which writes the same kind of row.
- For typed input rather than scans, QR to Sheets Forms puts a public form in front of the same kind of sheet; submitters never see the spreadsheet. Forms is a paid feature with a free trial of one form and 10 submissions.
What the person scanning sees is the camera view, a manual entry field and the last code scanned on that phone. Nothing from your spreadsheet appears on their screen: not other rows, not other tabs, not the file name in their Drive, because nothing was ever shared with them.
If you also protect the scan tab, keep the Google account connected to QR to Sheets among the people allowed to edit it, or new scans cannot be written.
The honest limits. A scanner link is a URL, like a public form: anyone who has it, on a phone your plan has room for, can add rows until you revoke it. A row records what was scanned, when, and which link and device type it came through; it does not prove who was holding the phone. And a person can download a CSV backup of the scans made on their own phone, which is their own work rather than your spreadsheet. For a reception desk where visitors and contractors sign in, the visitor and contractor log shows the same pattern.
| Capability | Google Forms / sharing settings | QR to Sheets |
|---|---|---|
| Staff can open the spreadsheet | Form: no. Shared file: yes, every tab | No |
| Google account needed by staff | No, unless Limit to 1 response is on | No |
| What staff enter | Typed answers | Scanned codes, or typed by hand when a code will not read |
| Staff can edit or delete earlier rows | Form: no. Shared file: yes, unless protected | No |
| Stopping one person or link | Remove them from sharing, or close the form for everyone | Revoke the scanner link |
| No signal | Form cannot submit | Kept on the phone, sent later |
| Cost | Free | Free to 300 scans in total, one link and one phone; then 7 USD per registered device per month |
On price: the free plan is one scanner link, one Sheet, one registered device and 300 scans in total, not per month. That covers one door, one dock or a trial. Beyond it, the paid plan is 7 USD per registered device per month with unlimited scans and links, priced by phone rather than by person, so a rotating crew sharing two phones costs two devices.
Which route should you choose?
- A few people typing answers into a few fields: a Google Form. Free, and staff never see the sheet.
- Trusted colleagues who already need the whole file: share it and protect the ranges they should not touch, to prevent accidents.
- Staff who need to see and correct their own entries: a separate intake sheet, accepting that they see each other's rows.
- A custom page with your own logic, and someone to maintain it: an Apps Script web app.
- Rows that are scans, from temps, volunteers or contractors on their own phones, with no accounts and nothing to undo afterwards: a scanner link.
Combining routes is normal: a Google Form for the occasional typed report and a scanner link for the repeated scans, each writing to a tab that only you can open. Whichever you choose, open the Share dialog on the spreadsheet itself when the job ends. Anyone still listed there can open everything, whatever route they used to add rows.
Frequently asked questions
Can I let someone add rows to a Google Sheet without seeing the rest of it?+
Not with a sharing setting. Viewer, commenter and editor all let the person open the spreadsheet. Put something in front of the sheet that writes for them instead: a Google Form, an Apps Script web app running as you, or a scanner link.
Do protected ranges stop people seeing my data?+
No. Protection controls who can edit a range, not who can see it, and staff still need access to the file to work in it. Google's help says protection should not be used as a security measure.
Can Google Form respondents see the spreadsheet?+
No. Responders can only fill in and submit the form. If View results summary is turned on, they can see summary charts and text responses, so keep that setting off when the answers are private.
Do staff need a Google account to use a scanner link?+
No. They open the link in their phone browser, allow the camera and scan. Only the admin signs in with Google, and the people scanning never get access to the spreadsheet.
How do I stop a temp adding rows after they leave?+
With a scanner link, revoke it from the dashboard; it stops working at once. With a Google Form, you can close the form for everyone or share a new link. With a shared spreadsheet, remove the person from sharing, and check that the link was not set to anyone with the link.
Does hiding a tab keep it private?+
No. Google's help states that all spreadsheet editors can unhide and view hidden sheets, and that viewers can reach hidden content by making a copy. Keep private data in a spreadsheet the staff are not shared on.