Sharing a Ledger Device | Access Boundary, Screen Prompt, and Local Record
Sharing a Ledger device should be treated as an access-boundary question. The device can show prompts and account-related screens, but PIN digits and recovery phrase words should not become shared notes or casual instructions.

Direct Answer: Separate Device Access From Backup Records
The first boundary is simple: device handling, PIN use, and recovery phrase storage are different categories. A borrowed or shared device situation should not mix those categories into one informal handoff.
Use the Screen Prompt as the Shared Reference
If another person is present, the visible screen prompt is the only useful shared reference. The role distinction in Ledger PIN and recovery phrase helps keep device unlock and recovery material separate.
Keep App Data Boundaries Clear
Account views and app prompts should be handled as display and confirmation states. The article Ledger Wallet data boundary explains why private-key and app-view roles should not be mixed.
Write a Local Record Before and After Use
Record who handled the device, what entry was used, and what screen state was visible. The record format in organizing a daily Ledger use flow is enough; it should not include PIN digits or recovery phrase words.
If the access boundary is unclear, do not continue the shared-use flow. Return to the owner-controlled entry and verify the device state there.