Sharing best practices
Least privilege, link expiration, passwords for sensitive documents, periodic reviews and revocation: the habits that keep your shares under control.
Sharing a file takes a second; keeping that share under control takes a few habits. Here are the best practices we recommend for staying in control of what you distribute.
In short
Share the minimum necessary, with the lowest access level that works, protect sensitive documents with a password and an expiration, verify the recipient before sending, then review and revoke access that is no longer needed on a regular basis.
Share the minimum necessary
Apply the least-privilege principle: give each person the minimum access they need — view rather than download when that is enough, a specific file rather than a whole folder when possible. The detail of access levels is in our article on sharing permissions.
Set an expiration on your links
A link with no time limit stays accessible for as long as it circulates. An expiration — in days, hours, or views — reduces your exposure: the link stops working once the threshold is reached.
Password-protect sensitive files
For any sensitive document (a contract, an ID document, personal data), require a password and share it through a channel separate from the link. That way, someone who intercepts the link still cannot open the content.
Verify the recipient before sharing
Before sending a link, check that the recipient is the one you intended: a wrong address or channel happens fast. If a mistake occurs, end the share immediately.
Tip — Set a recurring moment, for example monthly, to review your active shares and remove the ones whose purpose is over.
Review your shares and revoke access that is no longer needed
A share that has served its purpose should not outlive it. Review what you have shared periodically, and revoke access as soon as it is no longer necessary: it is one of the simplest ways to reduce risk.
Common issues
I sent a link to the wrong person. What should I do?
End the share immediately. If the link was protected by a password and an expiration, exposure stays limited in time.
Should every share have a password?
No, but it is strongly recommended for any sensitive document.
How often should I review my shares?
It depends on how sensitive the content is: a monthly review is a good rhythm for professional content; for everyday content, a check at the end of each project or collaboration is usually enough.
What happens when a link expires?
It stops working after the defined number of days, hours, or views; the content is no longer accessible through that share.
Was this article helpful?
Thanks for your feedback.
Still need help?
Can't find what you're looking for? Our support team can help.