← All postsHow-to

Online document sharing: permissions, links and what to check first

Online document sharing is one click and a decision you rarely revisit. Here is how to pick the right level, and the review habit that keeps old access from piling up.

How-toO

Online document sharing is the most-used feature in any office suite and the least-reviewed. Every share is a small permission decision, made in a hurry, that stays in force until somebody deliberately removes it — and almost nobody does. The result is not a dramatic leak; it is a slow accumulation of contractors, former colleagues and forwarded links with access to documents nobody remembers sharing.

Two habits prevent nearly all of it.

Pick the level, not the default

  • Viewer — for anything the recipient only needs to read. This should be your default, and it rarely is.
  • Commenter — for review. It gets you feedback without the document changing under you.
  • Editor — only for people genuinely producing the document with you. Editor-by-default is how documents get altered by people who meant to look.
  • Named invitation versus link is the more important choice: an invitation is a list you can audit and revoke; a link is forwardable and, once out, uncountable.

Assume every link you create will eventually be forwarded, because that is what links are for. If a document would embarrass you posted publicly, it needed an invitation rather than a link — and if the link already exists, revoking it is the only fix.

The review habit

  1. Set a recurring quarterly reminder to review sharing on anything sensitive: client folders, financial documents, HR files.
  2. Check the list on each, not the folder. Access is often inherited from a folder nobody thinks about.
  3. Remove anyone whose project ended. Ending access is part of ending an engagement, not an afterthought.
  4. When someone leaves the company, transfer ownership of their documents before the account closes — after is too late.
  5. Use expiry dates where the tool supports them, especially for external reviewers.
  6. Keep a note of what is deliberately public, so a periodic check has something to compare against.

Sharing that survives the file changing

The other half of good sharing is not sending copies. An attachment is a fork: from that second there are two versions, and every comment on the copy has to be merged by hand. Share access to the living document and the recipient always opens the current one.

The exception is deliberate: a signed contract, a final invoice, a report someone needs to archive. Those should be sent as fixed files, because their whole value is that they do not change.

In Ettex, every document starts private and sharing is a deliberate step: invite named people at Editor, Commenter or Viewer level, or switch to a link that anyone can open, with levels changed or revoked from the same panel. Storage lists everything you have in one place regardless of which app made it, with a Shared with me filter, filters by date, source and size, and Ctrl+K search across the lot — which is what makes a quarterly access review possible at all rather than theoretical.

Common mistakes

  • Sharing a folder when a single document was meant.
  • Using link sharing for convenience during a project and never turning it off afterwards.
  • Granting Editor because it is the first option offered.
  • Company documents in personal accounts, which leave when the person does.
  • No record of what is deliberately public, so nobody can tell an intentional link from an accident.

Frequently asked

What is the safest way to share documents online?

Invite named people at the lowest level that lets them do their job, and review those lists periodically. Links are convenient and cannot be audited.

Should I share a link or send an attachment?

Share access while the document is still changing; send a fixed file only when the point is that it will not change — a signed contract or a final invoice.

How do I stop shared documents piling up?

A quarterly review of sharing on sensitive documents, expiry dates on external access, and ownership transfer whenever someone leaves.

Can I tell who opened a shared document?

Only with named access and a tool that logs views. Anonymous links cannot tell you who read them, which is one more reason to prefer invitations.

What happens to shared documents when an employee leaves?

That depends on ownership — transfer their documents before the account is closed, or access disappears with the account.

Online document sharing goes wrong slowly. Choose the level deliberately, prefer invitations over links, and review access four times a year — that is the whole discipline.

AS
Written by Alex S.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.