Docs
Data Rooms

Room Access and the Front Door

Room link rules. NDA viewer agreements, email verification, watermarks, capture shield, and per-link overrides.

A data room's front door is its link. And a room can have several, each with its own rules. Set the access defaults in the room's Settings, then create per-audience links under Links.

ControlWhat it does
Viewer agreement (NDA)Shows your agreement at the door; the visitor types their name to accept. The acceptance is a signed, audited event. Pick the NDA from your templates.
Email verificationThe visitor proves their inbox with a code before entering. Every entry is tied to a real email.
PasswordAn extra shared secret. 12+ characters, same rules as document links.
AllowlistOnly specific emails or domains get in. Everyone else is denied and logged.
WatermarkEvery page carries the visitor's identity. Overlay or burned in, with intensity and density controls.
Screenshot protectionThe capture shield: blur on leave, capture-key blocking, spotlight, idle blur.
Expiry / view limitThe link closes itself on a date or after N opens.
Disable download / print / text selectionRoom-wide defaults. per-file overrides live on the files themselves.

The viewer agreement (NDA)

This is the room's signature gate. Stronger than a document link's NDA:

  1. Pick an NDA from your templates (create one under Library → Templates or from the agreement editor).
  2. Visitors see the agreement text at the door and type their name to accept.
  3. The acceptance is recorded as a signed event. Timestamped, attributed, and part of the room's audit trail.

You can see exactly who accepted, when, and under which agreement version.

Groups and the gate

A link's allowlist can reference groups. So "Bidder A" gets its own link and its own agreement, while "Advisers" enters under looser rules on another link. Each link's analytics stay separate, which makes per-bidder engagement measurable.

Editing the door after opening

Everything is changeable while live: tighten an allowlist, swap the agreement, switch the watermark on, expire a link early. New opens apply the new rules; the URL never changes. Revoking a room link works exactly like a document link. New requests refused instantly, existing sessions keep their current read, and Reactivate brings the same URL back.

Denied attempts

Every refused entry is logged with timestamp and region. Wrong password, off-allowlist, expired link, over the view cap, after revocation. Watch these: a denied attempt from an unexpected place is usually a forwarded link or a competitor probing the gate.

On this page