
Your Client's Contract Isn't Supposed to Be Google-able
A signed contract sitting behind a link that anyone on the internet could open isn't a feature. It's a liability you didn't know you had. If you've ever attached a file to a contact — a signed agreement, an intake form, a medical release — the share link you sent probably defaulted to public.
Four ways to share, not one



Now you get four options when generating a share link: Public (the old default), Private (restricted to your logged-in team), One-time passcode (recipient gets a code sent to their email before viewing), and Password-protected (you set the password yourself).
The old default was "anyone with the link." The new default is "you decide."
Expiration dates and download limits

Beyond who can open it, you control how long the link works and what they can do once they're in. Set an expiration date so a link sent for a one-time signature doesn't quietly stay live for the next three years. Restrict downloads so someone can view a file without walking away with a saved copy.
How to actually turn it on
An admin flips it on under Settings → Labs. Then: open the contact record, go to Documents panel, pick the file, hit "Share link," choose the link type that matches how sensitive the document is, set an expiration date and download permission if needed, copy, send. Check back later — you can see who's accessed the file and when.
The takeaway
Go pull up a contact record you've sent something sensitive to before and check what link type it's actually using. If it's still public, decide whether it needs to be, and reset it if it doesn't.
