Pass sharing is the wallet's built-in way to forward a pass. Apple Wallet shows a share action on a pass, and using it sends a copy to another person, who adds it to their own wallet. It is convenient for exactly the passes that are meant to move: a ticket bought for a friend, a gift card, a coupon.
The issuer controls it. In pass.json a single flag, sharing prohibited, removes the share action from the pass. Google Wallet passes do not carry a share sheet in the same way; a pass is delivered through a save link, and whether that link can be reused is decided by how the issuer builds it.
Turning sharing off is not the same as making the pass unshareable. A screenshot of a QR code travels as easily as the pass itself, and a member number typed at the till works for whoever knows it. The pass becomes genuinely personal only when the identification route cannot be copied, which is what account binding on an NFC pass delivers: the encrypted tap comes from the device the pass was issued to, and a copy on another phone does not exist.
The decision is per program. Membership, member pricing and staff benefits are credentials, and sharing them costs the program real money, so they should be locked down. Coupons and gift cards are usually meant to change hands, and locking them defeats their purpose. A points card sits between: sharing it is a small leak, and most programs leave it open rather than add friction.

