Enhanced Document Privacy & Access Controls

Modified on: Mon, 10 Aug, 2026 at 6:55 AM

Document Management

Enhanced Document Privacy & Access Controls

Securely share contact documents with configurable link types, expiration dates, and download permissions
What You'll Learn

Enhanced Document Privacy & Access Controls upgrades how you share files from the contact record's Documents panel. Instead of every file behaving like a public URL, you can generate configurable share links with different security levels, expirations, and download permissions.

This guide walks through the four link types, access controls, and how to implement secure document sharing that aligns with your internal security policies and client expectations.

Labs Feature

This feature is available through Labs and may evolve over time. If you don't see it in your account, ask an Agency or Sub-account Admin to check Settings → Labs and enable it for your location.

1

What is Enhanced Document Privacy & Access Controls?

Enhanced Document Privacy & Access Controls upgrades how you share documents stored in a contact's Documents panel on the Contact Detail Page. Instead of every file behaving like a public URL, you can generate configurable share links with different security levels, expirations, and download permissions. You also gain visibility into who accessed what and when.

Historically, documents under contacts could be accessed by anyone with the URL, which meant sensitive information required extra care. With this feature enabled, new links default to private/internal access, and you explicitly choose when a link should be public, email-verified, or password-protected.

Important

This feature is delivered through Labs and may evolve based on feedback. Behavior and UI can change over time as the product team refines the experience.

2

Key Benefits

Stronger document controls protect your clients and your team while keeping everyday work simple. These benefits focus on how the feature improves real-world document workflows:

Stronger security for client files — Choose between private, one-time passcode, password-protected, or public links based on the sensitivity of the document.
Better alignment with policies & compliance — Match sharing behavior to your internal data handling rules and industry requirements, instead of relying on a single, always-public link type.
Clearer auditability & accountability — View document details and access history so teams can quickly answer "who accessed this and when."
Reduced risk of oversharing — Links are private by default, limiting unexpected exposure when someone copies a URL into chat, email, or tickets.
Flexible client experience — Let internal teams use private links, while clients and external partners get OTP- or password-protected links that don't require a HighLevel login.
3

Link Expiration & Download Controls

Expiration dates and download permissions add fine-grained control over how long a link stays active and what recipients can do with the file. Used together, they significantly reduce the risk of documents lingering in inboxes or being downloaded inappropriately.

Control 1
Link Expiration

Set a specific date when the link should stop working. This is ideal for time-boxed offers, sensitive reports, or compliance-driven data retention policies.

Control 2
Download Permissions

Choose whether recipients can download the file for their records, or restrict to view-only access (where supported). This helps keep copies under tighter control.

Best Practice

Combine shorter expiration windows and restricted downloads for documents that carry the most risk if leaked.

4

Document Details & Access History

Document details and access history give you visibility into how each file is being shared and interacted with. This is especially helpful for audits, internal reviews, and troubleshooting questions like "Did the client open this yet?"

From the document's details view, you can:

  • See the link type (public, private, OTP, password-protected) and whether downloads are allowed
  • Confirm expiration settings and when the file was last updated
  • Review access history, such as when links were opened and by whom (where available), giving you an at-a-glance audit trail for that document

Combined with activity tracking and message history, this gives teams a fuller picture of contact engagement around key documents.

Getting Started
Ready to Implement Secure Document Sharing?
Follow the step-by-step setup guide below to enable the feature and start creating configurable share links for your contact documents
5

How to Set Up Enhanced Document Privacy & Access Controls

Setting up this feature has two main parts: enabling it through Labs (where available) and then using the new controls while sharing documents from the contact record. A careful setup ensures your links default to the correct privacy level and your team knows which option to choose in each scenario.

Step 1
Enable the Feature in Labs
  1. Sign in with an Agency Admin or Sub-account Admin account that can access Settings and Labs
  2. From the appropriate workspace (Agency or Sub-account), go to Settings → Labs
  3. Locate the feature card named similar to "Enhanced document privacy & access controls" or referencing document link controls for contacts
  4. Toggle the feature ON. If the card supports assignment, select the sub-accounts/locations that should get access, then save
  5. Refresh your Contact Detail Page and confirm that the new sharing options appear when you share a document from the Documents panel
Step 2
Open the Contact's Documents Panel
  1. Go to Contacts and open any contact record
  2. In the right panel, click the Documents tab/module to view files associated with that contact (internal docs, synced attachments, and other stored files)
Step 3
Choose a Document to Share
  1. Locate the file you want to share in the contact's Documents list
  2. Click the more actions menu (shown as three dots) next to the file name, then choose Share link 
Step 4
Configure the Link Type

In the share dialog, select one of the available access types:

  • Public link — anyone with the URL can view (respecting your download and expiry settings)
  • Private link — only authorized HighLevel users can access
  • One-time passcode link — recipients must confirm access through a code sent to the contact's primary email
  • Password-protected link — requires a passcode that you define

Confirm that the access type matches the sensitivity of the document and your internal policies.

Step 5
Set Expiration and Download Options
  1. Set an expiration date (optional but recommended): Pick the date when this link should no longer be accessible
  2. Choose download permissions: Enable "Allow downloads" if recipients should save a copy. Disable it to keep access as view-only where supported
  3. Review the summary of your chosen settings before finalizing
Step 6
Copy and Send the Link
  1. Click Create or Generate link (wording may vary)
  2. Use the Copy link button to copy the URL to your clipboard
  3. Paste and send the link via your preferred channel (email, SMS, WhatsApp, client portal message, etc.), following your security practices—for example, sharing passwords or sensitive details via a separate channel
Step 7
Review Document Details & Access History (Optional)
  1. Return to the contact's Documents panel
  2. Open Document details for the shared file (e.g., via a details icon or more options menu)
  3. Review: Link type and expiration, Download settings, Access history where available (e.g., last accessed timestamps)
  4. Use this view to confirm that settings are correct and to support internal reviews or client inquiries
6

Frequently Asked Questions

Q: Do recipients need a HighLevel login to open these links?
It depends on the link type. Private links require a logged-in HighLevel user with appropriate permissions. Public, one-time passcode, and password-protected links can be opened by external recipients without a HighLevel account, subject to the verification you configure.
Q: Is this feature available to all accounts or only through Labs?
At launch, Enhanced Document Privacy & Access Controls is a Labs feature. Availability depends on your plan and whether your agency has made it visible and enabled for your sub-account in Labs.
Q: What happens to older document URLs once this feature is enabled?
Labs behavior may vary as the feature evolves, but new share actions use the enhanced controls and default to internal/private access unless you choose otherwise. For highly sensitive files that previously relied on public-style URLs, generate new links with stricter controls and stop using any legacy links that no longer meet your security standards.
Q: Can I see who accessed a document and when?
Yes. The document details and access history view provides improved visibility into how each file is being used and when access has occurred, helping teams support audits and investigations more easily.
Q: Can I control which team members are allowed to generate public links?
Link creation follows your existing permissions for accessing the contact and its Documents panel. To reduce risk, limit document access to trusted roles and provide guidance on when it's appropriate to use public versus more secure link types. Additional per-role link restrictions may be introduced over time as the feature matures.
Q: Will these controls also apply to documents stored in custom fields or notes?
Not yet. Enhanced Document Privacy & Access Controls apply to files in the contact record's Documents panel. The product team plans to extend the same privacy and access controls to document attachments in notes and custom fields in a future phase.
Q: Can I still sync message attachments into the Documents panel and then secure them with these controls?
Yes. Attachments from channels like Email, SMS, Instagram, Facebook, and WhatsApp can be added to the contact's Documents area (for example, using "Add to Documents"), and once stored there, they can benefit from the same privacy and access controls when shared.
Q: What should I do if the feature doesn't appear in my account?
Ask an Agency or Sub-account Admin to review Settings → Labs. If the feature card isn't visible, your plan or account might not yet have access. If it is visible but disabled, an admin can enable it for the relevant locations.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article