Articles

How to share files securely (and stop emailing attachments)

The moment you attach a file to an email, you have made a copy you cannot revoke, cannot expire, and cannot see. It sits in a mailbox you do not control, gets forwarded without your knowledge, and is still there when the person leaves the company.

Sharing a link instead solves that — but only if the link is configured. An unconfigured “anyone with the link” URL is an attachment with extra steps.

Start by deciding: person, or link?

These are different tools for different jobs, and picking the wrong one is the most common mistake.

  • Named access ties permission to a person's account. It survives forwarding — a forwarded link still asks the new person to sign in as someone entitled to open it. Use it for anyone you work with repeatedly.
  • Link access ties permission to whoever holds the URL. It is right for one-off recipients who should not have to create an account, and wrong for anything ongoing.

Give the least role that works

Most sharing is done at Editor because it is the default that never causes a complaint. It is also how documents get overwritten by people who only needed to read them.

  • Viewer — they need to read it. This is most people, most of the time.
  • Commenter — they need to give feedback without changing the document. This is what most “Editor” shares should actually be.
  • Editor — they are genuinely working on it with you.

Then put the three controls on the link

If you share by link, configure it. Three settings do almost all of the work:

  • An expiry date. Ask “when should this stop working?” and set that. Most sharing has an obvious end — a deal closing, a term ending, a project shipping — and almost nobody sets it.
  • A password, sent through a different channel from the link itself. A password in the same email as the link is decoration.
  • Named access instead of a link, if the file should only ever open for your own people. This is the strongest option of all, because it fails closed no matter who the URL reaches.

Know what a preview-only link can and cannot do

Turning off downloading is a genuinely useful business control: it stops a draft becoming a file on someone's desktop that later comes back as a version you do not recognise.

It is not a security guarantee, and any honest vendor will tell you so. Anyone who can see a document can photograph the screen. Treat it as a way to keep versions straight and to signal intent, not as a way to stop a determined person keeping a copy.

Keep a record, and review it

A per-file audit log — who was given access, when it changed, who opened it — turns “I think we only sent it to them” into something you can check. It matters most in exactly the situations you cannot predict in advance, which is why it needs to be on by default rather than switched on when you get suspicious.

Then actually review shares occasionally. Access accumulates: the contractor from eighteen months ago, the link for a pitch you lost. Pick a cadence and prune.

A short checklist

  • Send a link, not an attachment.
  • Named access for ongoing collaborators, link access for one-offs.
  • Lowest role that does the job — usually Viewer or Commenter.
  • Set an expiry. There is nearly always a right answer.
  • Password for anything sensitive, sent separately.
  • Named access, not a link, for anything internal.
  • Check the audit log when something matters, and prune old access on a schedule.

For how this works in NevTan Drive specifically, see Sharing and permissions.

What to do when a link has already gone to the wrong person

It happens, and the response is more useful than the prevention talk. Revoke the link first — that is the only step that stops further access, and it should take seconds. Share links covers where that control lives. Then check the file’s access log to see whether it was opened at all, and by how many people, before deciding whether this is an incident or a near miss.

This is the practical argument for tokenised links over emailed attachments. An attachment that goes to the wrong address cannot be recalled, cannot be counted, and leaves no record. A link can be killed, and the log tells you whether you needed to.

Common questions

What is the most secure way to share a file?

Naming the person, rather than publishing a link. An invitation by email is tied to an account, carries a role you choose, and can be withdrawn. Use a link when the recipient has no account and you need it to be easy — and when you do, give it an expiry date.

Should I put a password on a share link?

Yes for anything confidential, and send the password by a different channel from the link. A password in the same email as the link protects against almost nothing, because anything that exposes one exposes the other.

Why not just email the file as an attachment?

Because you lose control of it at the moment you press send. There is no expiry, no revocation, no record of who opened it, and every forward makes another uncontrolled copy. A link keeps one copy, with a switch you can still turn off.

Try NevTan Drive freeThe editors, sharing controls and per-file audit log are on every account, free ones included. Only storage is ever paid for.