A share link is convenient because anyone who has it can use it, and that's also its risk. Links get forwarded, saved in chat histories and left in old emails. Three simple controls, permission, password and expiry, turn a link from an open door into something much closer to a key that you hand out deliberately.
The three controls
Permission: what can the recipient do?
View-only access lets someone look at a file or folder. Edit access lets them change it. Give the least that lets the person do their job. A client reviewing a proposal needs to view; a colleague co-writing a document needs to edit.
Password: who can open it?
A password means that having the link isn't enough. If the link leaks, the person who found it still can't open the file. It's an especially useful layer for personal documents, financial records and client data.
Expiry: for how long?
An expiry date means the link stops working on its own. That prevents the slow buildup of forgotten links that stay live for years, long after the reason for sharing has passed.
Choosing settings for common situations
| Situation | Permission | Password | Expiry |
|---|---|---|---|
| Sending a contract to a client for review | View | Yes | 1 to 2 weeks |
| Delivering final photos after payment | View and download | Yes | 30 days |
| Sharing a public brochure or price list | View | No | None, or a long expiry |
| Working on a document with a colleague | Edit | Not needed if shared with specific people | None while the project runs |
| Sending ID or bank documents for verification | View | Yes | 24 to 72 hours |
| Family album | View | Optional | Long, or none |
Best practices
- Send the password by a different route from the link, such as a call or SMS when the link goes by email.
- Use a passphrase of several unrelated words rather than a short word with a number on the end. It's easier to remember and harder to guess.
- Never reuse the password you use for your account or other services.
- Set the expiry when you create the link, not later, because later is when it gets forgotten.
- Tell the recipient when the link expires so they download what they need in time.
- Review your active links every few months and delete any you don't recognize or need.
Mistakes that undo the protection
- Pasting the link and the password into the same message.
- Posting a protected link in a public group, where the password ends up being shared too.
- Setting a password like 1234 or the recipient's name.
- Leaving links with no expiry on sensitive documents.
- Assuming view-only means no one can save the content. People can still take screenshots or photos of the screen.
Removing access
Sometimes you'll need to cut off access early: the wrong file was shared, the project was cancelled, or a link was sent to the wrong person. Look for the option to delete or disable the link in the sharing settings. It should stop working immediately, regardless of any expiry date.
NGDS share links let you set a permission level, add a password, and choose an expiry date, and they can be removed at any time from the sharing dialog. Used together, those three settings make sharing files far safer than sending attachments around by email.
