Workflows & examples

Common workflows

  1. New-hire document pack

    1. From the Employee’s own detail page, use the Attachments panel — files upload straight into that employee’s HR app folder, no manual folder selection needed.
    2. Generate the offer letter from a template and save it as an attachment.
    3. Send the employment contract for e-signature; the signed PDF auto-saves back and attaches automatically.
    4. Set sensitivity to Confidential on compensation-related files so only HR roles with documents:confidential can see them.
  2. Proposal-to-contract for a Deal

    1. From a CRM Deal’s Attachments panel, upload or attach the proposal — it’s filed under the Deal’s CRM app folder automatically.
    2. Share it with the prospect via a share link with an expiry date, instead of granting folder access.
    3. On acceptance, generate the contract and route it through Approvals.
    4. Send for e-signature; the executed PDF is archived under the Deal, and linked to the Contact as well via Links → Add Link.
  3. Certification expiry sweep

    1. Ensure each certification has an Expiry date set on upload.
    2. Review /documents/overview expiry panel weekly.
    3. Act on Documents Librarian flags for the 30-day window.
    4. Upload renewed versions to clear each flag.
  4. Tightening access on a sensitive folder

    1. Identify the folder (e.g. HR / Compensation) that should never be broadly visible.
    2. Open Manage Access → disable Inherit parent permissions → grant access only to the HR-admin role.
    3. Set the folder’s minimum sensitivity to Confidential or Restricted so nothing uploaded into it defaults to a lower level.
    4. Confirm with a non-HR test account that the folder no longer appears in Browse or search.

A worked example — a signed contract on a project

Attach it

Open the project, drag the PDF onto the attachments panel. You do not pick a folder — the server places it under Apps / Projects / <project name> and stamps app_key = projects.

Who can see it now

PersonOn the project pageIn the Documents app
You (uploader)YesYes
A project member with projects:readYesNo — the app folder needs projects:write
A project manager with projects:writeYesYes
Someone with documents:read but no project accessNo — the project page gates them out firstNo

Raise the sensitivity

Mark it confidential. Now only people with documents:confidential see it — on both screens.

Sensitivity only ratchets up. Moving a confidential file into a public folder does not make it public; it keeps the stricter of the two. That is deliberate: a move should never widen access by accident.

Share it outside

Create a share link. It carries a token, expires, and can be revoked — and it is the one path that ignores all five axes. Anyone with the URL has the file.

If the project is deleted

The pointer is cleaned up on a hard delete. The document itself stays in the library — deleting a project is not a reason to destroy the contract that governs it.