SHARING GUIDE / CHOOSE YOUR AUDIENCE

How to share an HTML page privately.

A client report. Two reviewers. One link.

To share an HTML page privately with share/artifacts, keep it owner-only while reviewing, then choose Restricted access. Allow specific verified email addresses, one exact email domain, or a password. Save the settings, check the recipient experience, and send the share link. You can set an expiration or change access later without changing that link.

Choose the right access
DELIVERY NOTE

WHAT YOU ARE SENDING

The report.

WHO YOU ARE SENDING IT TO

The people you choose.
SAME LINK
CHOSEN AUDIENCE
Decide who gets access before the link leaves your hands.

01 / MATCH ACCESS TO THE JOB

Who should be able to open your page?

“Private” can mean a draft for yourself, a named client, or a group with a password. Start with the audience, then choose the setting that matches.

Only me

You are still reviewing the draft.

Only the signed-in owner can open it.

Sending this link does not grant someone access.

Specific people

A client report is for two named reviewers.

Each person signs in with the exact email you allowed and verifies it.

A forwarded link alone does not admit a different account.

Email domain

Anyone with a verified email at one domain may read it.

The signed-in, verified email must match the domain you entered.

This checks an email domain, not team membership. Subdomains do not match automatically.

Password

Your audience needs access without signing in.

The reader enters the page password to open the HTML.

Anyone with both the link and password can get in. It does not identify a particular person.

Anyone with the link

You intend to make the page public.

The link opens without a password or email check.

This is public sharing, even if the URL is hard to guess.

02 / WORKED SHARING EXAMPLE

Send a proposal to two reviewers.

You have reviewed a proposal and want Maya and Leo to open it. Someone who receives a forwarded link should still need permission. Choose Restricted → Specific people, add their exact emails, and leave password and domain access off.

EXAMPLE SETTINGS

Project proposal

Access
Restricted · Specific people
Allowed emails
maya@example.com
leo@example.com
Password / domain
Both off

What happens at the link?

  • Maya, verified matching emailCan open the proposal.
  • Leo, signed into a different accountNeeds to switch to the allowed email and verify it.
  • Someone else, forwarded linkCannot open it with an unlisted email.
Example addresses illustrate the access rules. These are not invitations or a live sharing form.

Want to create the proposal first? Explore a complete proposal example, then bring your own approved material to your agent.

03 / FROM REVIEW TO RECIPIENT

How do you set up private sharing?

  1. Review the page before sharing

    Open the HTML draft with your agent and check the content, sources, and sensitive details. Approve publishing when it is ready. New pages are owner-only unless you explicitly choose another audience.

  2. Choose who can open it

    In your dashboard, open the page and find Who can open this? Select Restricted, then enable Specific people, Email domain, or Password. Use only the methods you want to grant access.

  3. Save the access settings

    Enter the approved email addresses, exact domain, or password. Optionally set Stop sharing on. Select Save sharing and check the Current summary before copying the share link.

  4. Check the recipient experience and send

    Test the link in a separate browser session. Your owner account can open the page even when others cannot. Confirm that an intended recipient can get in, then send the same share link to your audience.

Open your page settings

Sign in with the account that owns the page. Saving email addresses does not send invitations; send the share link yourself. Need a connection first? Connect your agent.

04 / HELP YOUR READER GET IN

What will the recipient need to do?

For email access

Open the link, sign in or create an account with the allowed email, and verify that email if prompted. A domain rule requires the exact domain, such as example.com; mail.example.com is different.

If access fails, check which account is signed in, verify the email, and ask the owner to confirm the address and expiration. Signing in alone does not grant permission.

For password access

Open the link and enter the password from the owner. A share/artifacts account is not required for this method. Send the password separately from the link when practical.

If it does not work, ask the owner whether the password changed or access expired. Do not paste the password into the address bar.

05 / WHEN THE WORK IS OVER

How do you stop sharing or remove someone?

Remove one person
Remove their email and save sharing. Also check that a password or domain does not still give them another way in.
Stop everyone else opening it
Change access to Only me, or unpublish the page to take it offline. The share URL is preserved.
Set an end date
Use Stop sharing on to end recipient access at a chosen time. Expiration does not erase the page or prevent its owner from reviewing it.
End current sessions
Invalidates current viewing access for a restricted or owner-only page. People still allowed by the settings can open it again; this does not remove their permission.

Changing access cannot recall screenshots, saved copies, or content already loaded in a reader’s tab. New access checks use the current settings.

Need to correct the content? Update the HTML at the same link. Updating the HTML keeps the existing audience and expiration.

06 / KNOW WHAT PRIVATE SHARING COVERS

Is a hidden link enough to keep HTML private?

No. A hard-to-guess link can still be forwarded. A noindex instruction asks search engines to leave a page out of results; it does not decide who may open it. Use access settings for that. Read Google’s explanation of noindex.

Access controls limit who can load the page. They do not prevent an authorized reader from copying it, and they are not end-to-end encryption. Review sensitive material before publishing and use a system approved for your data requirements.

Safe Static checks disable scripts, forms, embeds, and active API calls. HTTPS images and fonts may still load from their original hosts, which can receive those requests. Remove external assets if that is inappropriate for your material.

How to share an HTML page privately | share/artifacts