Generate passwords, choose expiry, and copy complete handoff text so recipients can access protected files on the first try.
Recommended setup
- Name the file clearly before upload.
- Preview the share page before sending it externally.
- Add a password when the file contains customer, account, contract, or operational data.
- Choose an expiry window that matches the real review period.
- Use copy-all handoff text when the recipient needs link, password, and expiry details together.
Send the password separately
A password protects a share only when it is not sent in the same message as the link. For example, send the link in the support ticket and the password through an agreed chat channel. Use a new password for each sensitive handoff. Never reuse a work account password, a recovery code, or a password that protects another service.
Pair it with an expiry
Passwords do not solve the problem of an old link being forwarded months later. Choose an expiry that matches the review deadline, then create a new share if access is needed again. For a long-running project, use a managed workspace instead of treating one password-protected link as permanent storage.
Make first access easy
Tell the recipient the file name, the link, where the password will arrive, and when the link expires. Ask them to confirm that they opened the intended version. This avoids copying passwords into a ticket or email thread where they are likely to be retained and forwarded.
Choose a password delivery channel
The useful boundary is separation. Send the share URL in the work system that needs the record, then send the password through an agreed chat, phone call, or other independent channel. Do not put the password in the filename, document body, QR-code label, or a second comment on the same public ticket. A recipient should be able to identify the file without learning its access code from the same place.
Use a generated, one-purpose password. It should not match a company, email, cloud-storage, or recovery password. When more than one person needs access, coordinate the password through the recipient team rather than creating several uncontrolled copies of the same handoff message.
Recover without weakening the handoff
If a recipient cannot open a protected share, first confirm the exact link, expiry, and password channel. Do not lower the controls or post the password publicly to resolve a single access problem. If the password may have reached the wrong person, invalidate the share and create a new one with a new password. That gives the incident a clear boundary instead of leaving an uncertain link active.
What a password does not do
The password protects access to the share page. It does not encrypt a copy after an authorized recipient downloads it, remove sensitive metadata from a file, or make credentials safe to distribute. Redact unnecessary information before sharing and use an internal approved system for material that policy or law requires to remain there.