Sharing

Decide who outside your organisation can be given a report and how: guests, secure links, domains and public links. And whether a guest may approve a request.

Reports are private by default. Admin → Sharing sets the outer limits of what the people who publish may do with them: nothing here shares a report, and nothing here loosens a report's own permissions. Owners, admins and security admins can change it.

External access

SettingStartsWhat it does
Guests and secure linksOnLets people who publish invite someone outside the organisation to a report, and create secure links. Turned off, a secure link is refused when it is opened.
Guests may approveOffLets a guest you have already given access be named as an approver, and decide from their email. Needs guests and secure links on.
Public linksOffAllows a report to be read with no sign-in at all. Even when on, every report stays private until a person makes it public.
Permitted guest domainsNoneDomains a report can be shared with as a whole — anyone at customer.com. Readers prove their address with a one-time code.

Guests

A guest is someone outside your organisation who has been given a report. They read it after proving their email address with a one-time code, and hold no account. A guest can also be asked for a review or for information. Guests never take a seat. How a report is shared with them is in Publishing and sharing reports.

Guest approvers

With Guests may approve on, an approval can name a guest by their email address — a client signing off their own accounts, for example. Because a guest decides from a link in their email rather than a signed-in session, two limits apply:

  • Only low and medium risk requests can go to a guest.
  • A request that one of your ethics rules has flagged needs a member who signs in, and cannot be sent to a guest.

A request that breaks either limit is refused when it is made, with the reason, rather than sent to someone who could not answer it.

Public links are included in Free, Team, Business and Enterprise, and stay off until an administrator turns them on. Agents can never make a report public — only a person can — and your organisation's default policies keep confidential and restricted reports inside the organisation.

Permitted guest domains

Add a customer's or partner's domain to let reports be shared with everyone at it, without naming each person. Removing a domain from this list withdraws every share that relied on it.

Defaults for readers

SettingStartsWhat it does
DownloadsOnLets readers save a copy of a report. Restricted reports cannot be downloaded under the default policies.
Show viewer identitiesOnLets report owners see who opened a report, not only how many people did.
Watermark readersOffStamps each page with the reader's email address and the date. A deterrent for screenshots, best kept for the material where that matters.

How long sharing lasts unless the person sharing says otherwise, in days, up to 365. A new secure link's expiry starts at this number in the share dialog, and the sharer can change it or clear it. A report sent by email with no expiry of its own — from the app or through the API — stays open this long. Left blank, secure links start at 30 days and sent reports do not expire.

It applies to what is shared after you save; links and sends that already exist keep the expiry they were given.

Save the page for any change to take effect. Each save writes one org.sharing_policy_changed event to the audit log, listing every setting that changed with its old and new value.

What a published report may do in a reader's browser — run scripts, load images, be embedded in your intranet — is set separately, on Admin → Security. See Security, audit and legal holds.