LegalAI Space

Client sharing without the risk: passcodes, view logs and what your client actually sees

Emailing a Word attachment gives you no idea whether it was read, by whom, or where it went next. A link with a passcode and an expiry answers all three, within limits worth stating.

Published
Reading time
6 minutes
Written by
The LegalAI Space team, Cognesio LLP

The default way a firm sends work to a client is a Word attachment on an email. It works, it is familiar, and it tells you nothing. You do not know whether it was opened, by whom, whether it was forwarded to the client's accountant, or whether the copy being discussed in a meeting six weeks later is the version you sent or the one before it. A share link with a passcode and an expiry answers the first three of those questions and improves the fourth.

What the client actually sees

A read-only page, in a browser, with no account to create and nothing to install. That last point decides adoption more than any security feature: a client who has to register for a portal will email you asking for the attachment instead, and you will send it, and the control will have achieved nothing.

You choose what travels. The result, the files, the authorities table, the open questions: four separate decisions, made before you send. That is more granular than it first appears. Sending the open questions to a client is sometimes exactly right, because it shows what remains unresolved and why. Sometimes it is exactly wrong, because those questions are internal working notes and will read as doubt.

Why the passcode travels separately

Links are protected with a six-digit passcode by default, and the passcode is meant to be passed on separately: by telephone, in a different message, in a conversation you are already having. Sending the passcode in the same email as the link recreates the problem you were solving, which is a link sitting in an inbox that may be forwarded, breached or simply left open.

Six digits is not a cryptographic secret and we would not describe it as one. What it does is put a second, separately transmitted factor between a forwarded URL and your client's confidential advice. That is a meaningful improvement over an attachment, which requires nothing at all from whoever ends up holding it.

Expiry, and the check that runs every time

Links expire after seven days by default, with thirty and ninety available. The expiry is checked on every open, not only at the first one, so a link that worked yesterday stops working today when its window closes. That is the behaviour you want and it is worth confirming with any supplier, because a link checked only at creation is not really expiring.

Short windows are better than long ones for a specific reason: they make re-sending normal. A client who needs the advice again in three weeks asks, and you send a fresh link, and the second sending is recorded too. A ninety-day link is a document you have lost track of, with better presentation.

The email gate, and its honest limit

You can require an email address before the page opens. It is worth knowing exactly what that gives you, because it is easy to overstate. The address is self-identified and not verified. Anybody holding the link and the passcode can type anything into that field, and the page will open.

So the email gate is a record of what the person said, not proof of who they were. Used properly, it is still useful. It tells you the shape of the audience: if you sent a link to a general counsel and the log shows three different addresses at the same company, the advice has been circulated internally, which is usually fine and always worth knowing.

The log, and what it is good for

Every open, every download and every failed passcode attempt is recorded, and it all lands in the audit and compliance register alongside the run that produced the work. Links are revocable, so a share can be closed the moment a matter changes or somebody realises the wrong recipient was on the email.

Two practical uses. The first is ordinary client service: a partner who can see that the note was opened twice, both times before the board meeting, knows whether to lead with a summary or a reminder. The second is the awkward conversation. When a client says they never received advice on a point, the log is a neutral record of what was sent, when, what was included, and whether it was opened. That is a better position than searching a sent-items folder.

When not to share at all

Some work should not leave the firm in this form, and the controls do not change that. Do not share output that has not been read and signed off by a supervising solicitor: a run is raw material until somebody qualified has taken responsibility for it. Do not share work carrying an authority with a needs a check or not found verdict without dealing with it first, because the client will click the link, and they should be able to.

Do not send the authorities table to a client who will read a verified verdict as a promise that the case supports the point. Verified means the passage was found, word for word, on an approved public source. It is a statement about existence, not about strength, and if that distinction will not survive the client's reading of it, either explain it in the covering note or send the result on its own.

The honest edge

Nothing here prevents a determined recipient copying the text, taking a screenshot or reading the page aloud on a call. Read-only means the page does not offer a download when you have not enabled one; it does not mean the content cannot leave. Any product claiming otherwise is selling you a feeling rather than a control.

The passcode protects against a forwarded link, not against a recipient who forwards both. The email gate records a claim rather than an identity. And the log tells you a page was opened, not who was in the room. These are real limits, they are the same limits every comparable mechanism has, and a firm is better off knowing them than discovering them in a complaint.

See it run on your own matter.

Free plan, two seats, 500 welcome credits, no card.