Sign in

Sharing a report externally

Create a scoped link to an issued release, gate it behind an agreement, and see who accepted what.

Updated October 2, 2026
3 min read
collaboration
security
reports

Share from an issued release. You get a link scoped to that release — not access to the project, and not access to your workspace.

Setting a share up

  1. Pick the release and, if your plan has editions, the edition.
  2. Name the recipient. A share is issued to a person, so the acceptance record names somebody.
  3. Choose the agreement the reader must accept before the report opens.
  4. Set an expiry. A diligence report should not be readable indefinitely.
  5. Decide on a second factor. For sensitive releases, require a one-time code at each visit in addition to the link.

The agreement gate

Before the report renders, the reader is shown the agreement you attached and has to accept it. Two defaults matter:

  • A confidentiality agreement binds the reader on the contents.
  • A non-reliance notice states that the report was prepared for your client and that the reader may not rely on it. This is the default posture for anyone outside the project, and it is deliberate: a report that circulates without it is a report someone can claim they relied on.

Acceptance is recorded with the person, the agreement version, and the timestamp, and the ledger is exportable — which is the artifact you need when someone asks who had access.

Seeing who holds what, later

Versions and sharing on the project lists every version with the people who can open it beside it — name, whether they have opened it yet, whether their invitation has expired, and their reliance posture. It opens with the number that matters: how many people outside your team can open this report right now, and how many of them hold a version you have since replaced.

Revoking

Revoking a person's access ends it immediately. Stop sharing on a version does the same for everyone holding it, in one action, after naming who loses access. Close the earlier issues does it for every superseded version at once.

The acceptance record stays in either case; a revoked share does not erase the fact that someone accepted an agreement and read a version. A link that has been revoked, and a version that has been withdrawn, both tell the reader the report was withdrawn rather than simply failing.

What a reader cannot reach

The project workspace, your analyst files, unreviewed drafts, other releases, other projects, your team, or your settings. A share is a document, not a door.

Availability

Access agreements are part of the deal plans. A workspace without them cannot share confidential material externally at all — that is a deliberate limit, not an upsell prompt: an ungated share of a real diligence report is exactly the thing we should not make easy.

Next

Was this article helpful?

Votes are read: an article that keeps failing gets rewritten.