A complete overview of access controls on share pages, how they interact, who can configure them, and recommended defaults by use case.
Recommended setup
- Name the file clearly before upload.
- Preview the share page before sending it externally.
- Add a password when the file contains customer, account, contract, or operational data.
- Choose an expiry window that matches the real review period.
- Use copy-all handoff text when the recipient needs link, password, and expiry details together.
Choose controls from the recipient's job
Start with the smallest access window that lets the recipient finish the work. A client reviewing a proposal for two days needs a different setup from an internal teammate downloading a build artifact. Password protection is useful when the link and password can be sent separately. Expiry is useful for every handoff with a clear end date. Download limits are best reserved for a known, small recipient group; an arbitrary low limit can block a legitimate reviewer.
Test the recipient experience
Open the finished link in a private browser window before you send it. Check that the title identifies the right version, the password prompt appears when expected, and the preview or download works without your signed-in session. This simple test catches expired links, incorrect filenames, and controls that were configured for the wrong share.
Close the handoff deliberately
When a review, incident, or delivery is complete, allow the link to expire or remove it from active circulation. Creating a new share for a revised file is clearer than relying on recipients to distinguish two attachments with similar names.
Pick controls from the risk, not from a template
Use password protection when disclosure of the link alone would be harmful and you can deliver the password through a different channel. Use expiry when access has a known end date. Use a download limit only when you know how many people need a copy and a failed download will not interrupt a legitimate review. These controls work together, but none of them changes the sensitivity of the file itself. Remove unnecessary data before upload.
For example, an internal design review may need a named file and a seven-day expiry, while a contract for an external reviewer may also need a password sent in a separate message. A production log containing tokens needs redaction first; a password is not a replacement for that work.
Handoff checklist
Before sending, record the recipient, purpose, expiry, and version in the same ticket or work item that explains the handoff. Send the link with a one-line description of what it contains. If a password is required, tell the recipient where it will arrive without placing it beside the link. After the deadline, verify that a replacement link was created for any continued access rather than silently extending an old share.
Common questions
Should every link have a password? No. A password adds a second delivery step and is most useful when the link can travel separately from the access code. For ordinary, non-sensitive collaboration, a clear title and appropriate expiry may be the better experience.
Can a download limit prevent copying? No. It limits completed downloads, not screenshots, forwarded files, or material already saved by an authorized recipient. Treat it as a workflow boundary, not digital-rights management.