Access by role, not by person
Rights granted person by person look simple at first and become impossible to manage after the thirtieth employee. The model that holds up is role-based: you define what a role can do — for example "HR officer" or "accountant" — and assign the role to people. When someone changes jobs, you change their role, and rights adjust on their own. When someone leaves the company, you deactivate their account and every access they had disappears at once, including anything granted ad hoc. On top of roles sit rights by department and by document category, so a manager sees everything in their own area, and nothing from areas that aren't theirs.
Expiring links for those without an account
An external auditor, a lawyer, a bank or a partner occasionally needs documents, but doesn't need a permanent account. For them, the platform generates links with a term: you choose the document or file, the validity period, and whether you allow downloading or only viewing. The link can require an extra password and can be revoked at any time, even before it expires. Unlike an email attachment, which slips out of your control the moment it's sent, a link stays yours: you can see how many times it was accessed and close it once the collaboration is over.
Watermark and log: deterrence and proof
No technical measure stops a photo of the screen. What you can do is reduce the temptation and keep the proof. The watermark applied on viewing and downloading carries the user's name, date and time — and a document that circulates further shows its own origin. The access log completes the picture: every opening, download and share stays recorded, with author and timestamp. In the event of a suspected information leak, the question "who had access to this document over the last three months?" gets an exact answer, not a list of guesses.
Sharing and GDPR compliance
Many of a company's documents contain personal data: personnel files, certificates, correspondence with employees, data on partners' representatives. For these documents, access control isn't a matter of organizational preference, it's a compliance requirement. The practical principle is minimization: each person sees strictly what they need for their task. The access log provides the second required component — the ability to demonstrate who accessed what. Together with the retention rules, these are the two things an inspection checks first when it asks how the data in your archive is protected.