Workflows & examples
Common workflows
-
New-hire document pack
- From the Employee’s own detail page, use the Attachments panel — files upload straight into that employee’s HR app folder, no manual folder selection needed.
- Generate the offer letter from a template and save it as an attachment.
- Send the employment contract for e-signature; the signed PDF auto-saves back and attaches automatically.
- Set sensitivity to Confidential on compensation-related files so only HR roles with
documents:confidentialcan see them.
-
Proposal-to-contract for a Deal
- From a CRM Deal’s Attachments panel, upload or attach the proposal — it’s filed under the Deal’s CRM app folder automatically.
- Share it with the prospect via a share link with an expiry date, instead of granting folder access.
- On acceptance, generate the contract and route it through Approvals.
- Send for e-signature; the executed PDF is archived under the Deal, and linked to the Contact as well via Links → Add Link.
-
Certification expiry sweep
- Ensure each certification has an Expiry date set on upload.
- Review /documents/overview expiry panel weekly.
- Act on Documents Librarian flags for the 30-day window.
- Upload renewed versions to clear each flag.
-
Tightening access on a sensitive folder
- Identify the folder (e.g.
HR / Compensation) that should never be broadly visible. - Open Manage Access → disable Inherit parent permissions → grant access only to the HR-admin role.
- Set the folder’s minimum sensitivity to Confidential or Restricted so nothing uploaded into it defaults to a lower level.
- Confirm with a non-HR test account that the folder no longer appears in Browse or search.
- Identify the folder (e.g.
A worked example — a signed contract on a project
Attach it
Open the project, drag the PDF onto the attachments panel. You do not pick a folder — the server places it under Apps / Projects / <project name> and stamps app_key = projects.
Who can see it now
| Person | On the project page | In the Documents app |
|---|---|---|
| You (uploader) | Yes | Yes |
A project member with projects:read | Yes | No — the app folder needs projects:write |
A project manager with projects:write | Yes | Yes |
Someone with documents:read but no project access | No — the project page gates them out first | No |
Raise the sensitivity
Mark it confidential. Now only people with documents:confidential see it — on both screens.
Sensitivity only ratchets up. Moving a confidential file into a public folder does not make it public; it keeps the stricter of the two. That is deliberate: a move should never widen access by accident.
Share it outside
Create a share link. It carries a token, expires, and can be revoked — and it is the one path that ignores all five axes. Anyone with the URL has the file.
If the project is deleted
The pointer is cleaned up on a hard delete. The document itself stays in the library — deleting a project is not a reason to destroy the contract that governs it.