Access Controls
Every gate a link can enforce, password, email verification, allowlists, NDA, expiry, view limits, and forwarding lock, in detail.
Access controls decide who gets in and for how long. You set them when you create the link, and you can change them at any time afterward. The next visit enforces the new rules.
Password
Require a passphrase before the document opens.
- Minimum 12 characters. The form refuses shorter passwords.
- You choose the passphrase and share it separately from the link. The product hint says it plainly: "Share it separately from the link."
- Viewers see a single password field with a show/hide toggle. Correct entry opens the reading room.
- On an existing link you can change the password or remove it entirely. Removing takes effect on the next visit.
Email verification
Ask viewers to prove their email before access.
- The viewer enters their email, receives a 6-digit one-time code, enters it, and continues. Codes expire after 10 minutes and can be resent after a short cooldown.
- Verified viewers appear by name and email in analytics and in the room's people list as Verified. Versus Claimed, meaning they typed an email but have not proved it yet.
- On shared links the code goes to their browser. Possession of the link alone is not enough.
Allowlist and domain rules
Restrict access to the people you intend.
- List individual emails (
anna@acme.com) or whole domains (acme.com). "anyone with an @acme.com email address". - Mixing both is normal: one partner company by domain, one adviser by address.
- Everyone not on the list sees a polite denial. And the attempt is logged with a timestamp and region, so a denied viewer is never invisible.
NDA gate
Require viewers to accept a viewer agreement before the document opens.
- The NDA text comes from an NDA template you manage in settings. The link picker lists your templates, and the gate cannot be enabled until one exists.
- The viewer sees the agreement as a clean first step: read, accept, enter.
- Every acceptance is timestamped and stored. You have a record of who agreed to what, and when.
Expiry
Give the link a shelf life.
- Presets: Never, 7 days, 30 days, 90 days. Or pick an exact date.
- The link stops working automatically afterward and shows as Expired in the list.
- An expired link is not deleted: editing the date brings the same URL back to life.
- Expiring links surface on the Docshark home attention panel ahead of time so nothing dies silently.
View limit
Cap how many times a link can be opened.
- Leave the field empty for unlimited views, or set a whole number. The link deactivates itself after that many opens.
- Useful for one-time deliveries, limited-circulation materials, or a "first five reviewers only" preview.
Disable forwarding
Lock the link to the invited audience.
- Combined with email verification, only the invited address can open. A forwarded link asks for a code the forwarder cannot receive.
- Turning this on automatically requires email verification; the two work as one control.
Stacking controls
Controls compose. A link can require email verification and an allowlist and an expiry. "only people at acme.com, verified by email, until Friday." Gates apply at the door; failing any one of them denies access and logs the attempt. The strictest applicable rule always wins for the viewer.