Secure document sharing
Send selected documents to a workplace behind three checks: a unique private link, the recipient email and a short access code you provide separately. Available on Plus.
What secure document sharing does
Secure document sharing is for files where a link alone is not enough. You select the documents, enter the workplace recipient’s email address and create the share. Sessional emails a unique link to that address, but never places the access code in the same message. You give the 6-digit code to the recipient separately, such as during a phone call.
The recipient needs the link, the same email address and the current code before any document names appear. A forwarded or intercepted email is therefore not enough on its own. The workplace does not need a Sessional account, and the share does not expose anything else in your account.
Create and deliver a share
- Open Secure document sharing under Documents and tick only the files this workplace needs.
- Enter the recipient email. You can add their name and a label for your own share history.
- Create the share. The private link lasts seven days and is emailed to the recipient.
- Copy the 6-digit code shown on screen and provide it through a separate channel. The code is shown once and expires after 15 minutes.
- If the code expires, generate a new one from the share history and give the replacement to the recipient.
Keep the link and code in separate channels. The email tells the recipient that you will provide the code separately. It does not contain the code, and Sessional does not send the code for you.
What the workplace sees
The recipient opens the link and sees an identity check, not a document list. They enter the email address that received the message and the current access code. Only after both values match does Sessional return the selected document names and their expiry dates. The workplace can then view supported images or download the files while the short unlock remains valid.
Five failed attempts lock the share. This stops repeated guessing. You can generate a fresh code from your dashboard, which resets the failed-attempt count and unlocks the share for another try. A fresh code does not extend the seven-day life of the link.
Expiry, revocation and control
Every secure link expires seven days after creation. The access code has its own shorter 15-minute expiry, and a successful unlock lasts for 30 minutes in that browser. These timers are separate: regenerating the code does not renew the link, and an unlocked browser cannot keep using a share after you revoke it or the seven-day link expires.
Your share history shows the recipient, status, document count and unlock count. Revoke a share at any time to stop further access immediately. If a workplace still needs the documents afterwards, create a new share rather than sending the old link again.
Sessional shares, it does not verify
For routine document bundles where link-only access is appropriate, compare this protected flow with the compliance passport. You can also read how your uploaded records and expiry reminders work in the document store guide.
Frequently asked questions
Is the access code included in the email?
What happens when the 15-minute code expires?
Can I revoke access after the workplace has unlocked it?
Does the workplace need a Sessional account?
Which plan includes secure document sharing?
Share sensitive documents with separate access
Upgrade to Plus, choose the exact files a workplace needs, and protect the private link with the recipient email and a separate short-lived code.