Practical guidance for sharing files, managing access and retaining approval records.
Download PDFStart with the files your team handles, who needs access and how long the files should be kept. A creative proof, a personnel file and a sensitive client record can require different handling. Choose controls for the actual information and workflow.
Share only what the reviewer needs
Check the recipient and attachment before sending. Remove unrelated personal or confidential information from the proof where practical. Treat a private review link as sensitive: a recipient may be able to forward it.
Confirm how your chosen service handles access, link expiry, revocation and downloads. A link alone does not establish that the viewer is the intended person.
Protect the accounts around the workflow
Use strong, unique passwords where passwords are required and enable multi-factor authentication where supported. Protect the email account used for login and recovery. Review access when someone changes role or leaves the team.
The NCSC guide to using online services safely explains practical steps for small organisations using cloud services.
Keep the proof and decision connected
Record the exact filename or version alongside the decision, approver and date. Do not overwrite an approved file with an amended version. Keep review permissions and approval authority clear: being able to view a file does not necessarily mean a person can authorise production.
Use the artwork approval form for a simple record structure.
Set a retention and backup plan
Agree which working files and approval records you need to retain, who owns the archive and when it should be reviewed. Check the service's actual file and activity-log retention rules; do not assume an online approval record is permanent.
Keep needed copies in your organisation's controlled storage. Check that the team can restore essential records. The NCSC small-organisations guide includes backup guidance.
Know what to do when a file goes to the wrong person
Tell the responsible person promptly. Confirm what was shared, with whom and when. Use the service's available access controls and follow your organisation's incident process. Revoking a link does not retrieve a copy that someone has already downloaded.
Prepare contacts and recovery steps before an incident. The NCSC incident preparation guidance is a starting point.
Check provider claims before relying on them
Ask what protections apply to data in transit and at rest, which people or systems can access it, how records are deleted and what export options exist. Where your organisation has specific legal or contractual requirements, have the responsible owner assess the service against those requirements.
Approval software can support a workflow, but using it does not by itself establish compliance or guarantee a security outcome. Demonstrate the process and verify the controls you need.
For day-to-day review organisation, see the document approval best practices and client approval process.
Save this guide for offline reading