← Help

Product help

Reviewed private-file delivery

Product team · Reviewed

Open Files → Selected-file delivery to send a particular original without exposing the rest of a project or your reusable library. Each approval creates one expiring private link and one email in the existing delivery queue.

Review before sharing

Choose a retained version and a named CRM recipient. A private project version can go only to a recipient explicitly linked to that project. A reusable original can go to a selected current contact in your business. Shared wedding participation does not grant access to private originals.

Write the subject and message, choose one to 90 days of access, then select Review this delivery. The preview shows the filename, immutable revision, checksum, exact recipient address, message and expiry policy. Open Inspect the exact private original if you need to check its contents. Confirm the review to queue the email. A changed recipient, unavailable source or stale review requires a new preview.

For example, send version 3 of your venue setup guide to Jordan's current project contact. A later replacement with version 4 does not alter Jordan's selected original. If version 3 should no longer be available, revoke that specific delivery and review a new version separately.

Use files in an automation

Add Review and deliver a selected file to the workflow editor. Select an exact reusable version, write the message with supported merge fields and choose an access lifetime. Save, simulate and publish with the named source review. Publication never sends the file.

When a run reaches this step it holds for an owner or administrator. Its control shows the exact original and current intended recipient. Approving queues one private file link and moves the run to Waiting for delivery. It continues only after the original email is accepted or delivered by the provider. Failed, cancelled or uncertain outcomes hold for review; they do not generate replacement links or duplicate messages. Changes to the workflow draft or reusable library cannot silently replace the selected version.

The original publisher and approving operator must remain authorized before dispatch. Workspace and run pauses hold pending work. Reply, booking, payment and project stop rules still apply. Cancelling the run also closes file access already created by that run. A normally completed run leaves its approved link available until expiry or revocation.

Delivery and access are different

The history lists the email's queue/provider status separately from whether the file link is open, expired or revoked. A download count means that the server admitted a download request; it does not prove someone read or saved the file. Email security scanners and forwarded links can also request files.

These are bearer links: anyone who possesses a link can use it while access remains open. The private page explains this and serves one exact version. It does not provide a project index, other files, a public storage URL or access to client finances. Email delivery uses the existing private conversation and provider configuration.

Use Close this private link, enter a reason and revoke it to stop future access. Unattempted queued email is cancelled. An already attempted send may still arrive; its link remains closed. Files already downloaded cannot be recalled. Email or project-link changes, recipient archival/merge and workflow cancellation also invalidate access; correcting those source conditions can make an unrevoked, unexpired link usable again. Revoke explicitly when permanent withdrawal is intended.

Originals, recovery and limits

Source archival blocks new sharing but retains previously approved originals until their delivery access expires or is revoked. Retained versions remain protected from generic cleanup. Original contents are checked against their recorded size and SHA-256 before download, and access is rechecked after loading. A corrupt or missing original fails closed for recovery.

Retry an uncertain approval with the same request and reviewed details; the service returns its original receipt. An unknown provider result uses the existing email outbox recovery path and never reports delivered merely because approval succeeded. Signed agreement assets, isolated media purposes and legacy public documents are excluded from this file-sharing path. Complete private-storage migration first for legacy files; use signature-specific delivery for executed agreements.

The composer initially offers up to 300 retained project versions, 300 recent reusable originals and 1,000 current contacts. Open a specific historical version from its private file history to share it beyond the initial source picker. The versioned API accepts any authorized retained source and current recipient. Files use the existing 9MiB private-document limit; no bulk or public-folder sharing is implied. This workflow deliberately requires a fresh recipient approval for each automated run.

The named /api/v1/document-deliveries API uses the same review, revision, idempotency and permission checks. Real email provider delivery and private object-store recovery remain part of the coordinated activation rehearsal.