Loading

Access Links

An access link lets somebody with no account reach one specific record for one specific purpose, such as downloading a document or completing a risk assessment. Unlike older link types, an access link can expire, can be limited to a number of uses, and can be taken back. This article explains how they work across the platform, so you can judge when to issue one and how to withdraw it.

Where to find it

Access links are created and withdrawn on the record they open, not from a menu. Today two features issue them:

  • Document share links, on a document's sharing panel, under Share links. See Document Access.
  • Risk assessment links, which let somebody without an account fill in an assessment. See Assessment Instruments.

Architect Panel → Data:

  • Datastores — the Access Links datastore holds every link ever issued, for audit; it deliberately has no menu entry of its own

What makes an access link different

  • One record, one purpose. A link is issued for a particular record and states what it is for. A link made to download a document cannot be used to open anything else, even on another part of the site.
  • It expires. Document share links last 168 hours (seven days) unless you choose otherwise; assessment links last 30 days.
  • It can be limited to a number of uses. Document share links default to five downloads. Assessment links have no use limit, because an assessment may be completed over several sittings.
  • It can be taken back at any moment, and stops working immediately.
  • It is shown once. The platform stores only a scrambled fingerprint of the link, never the link itself. When you create one, copy it straight away: it cannot be displayed again. If it is lost, create another and take back the first.

Creating and withdrawing a document share link

  1. Open the document and its sharing panel. Only an administrator can create share links.
  2. Under Share links, fill in Who it is for (a note), Hours it lasts and Times it can be used, then click Create a link.
  3. Copy the link from the message "Link created. Copy it now - it cannot be shown again." and send it to the person.
  4. To withdraw it, find it in the list (which shows who it was for, how many uses are spent, when it expires and who made it) and click Take back. It is then marked "taken back".

A document that may not be downloaded, or that lives in a File Store, cannot be shared by link; the refusal says why.

What the person holding the link sees

A working link opens the document or assessment with no sign-in. A link that has expired, been used up, been taken back, or was never valid gets the same message, for example "This link is not valid. It may have expired, been used already, or been withdrawn." The platform never says which, so a stranger guessing links learns nothing. Repeated failures from one address are counted and can get that address blocked, as with failed sign-ins.

Who to tell what

The note in Who it is for is a record of who you meant to send the link to. It is not checked: anybody the link is forwarded to can use it. Choose the expiry and number of uses with that in mind, and use a named grant instead when the person has, or can be given, an account.

What goes wrong

  • "Only an administrator can create a share link." Share links are administrator-only.
  • The recipient says the link does not work. Check the link's row: used up, expired or taken back. Create a fresh one if they should still have access.
  • A link was sent to the wrong person. Take it back at once. Its row records whether it had been used, and when.

Worked example

A housing association needs to send a surveyor's report to an external contractor without creating an account. An administrator creates a share link for "Contractor - Smith & Co", lasting 48 hours with 3 uses, and e-mails it. Two days later the list shows "2 of 3" used and the link expired. When the contractor asks again a month later, a new link is issued; the old row stays as a record that the first was sent.

Recommendations

  • Prefer a named grant when the recipient can have an account.
  • Keep expiry short and uses few for anything sensitive.
  • Copy the link immediately; it cannot be shown again.
  • Take back links as soon as their purpose is served.