Sharing
Share bid analyses and proposals with teammates or via secure expiring links
Sharing
Share bid analyses and proposals with teammates in your organization, or with anyone through a secure link. You control the permission level, can set links to expire, and can see exactly who accessed what.
Two ways to share
Open the Share dialog on an analysis or proposal. It has two tabs:
Share with a teammate
- Select a user from your organization.
- Choose a permission level: View only, Can comment, or Can edit.
- Create the share. The item appears for that user with the access you granted.
Share via link
- Choose the permission level for anyone who opens the link.
- Choose an expiration: 1 day, 7 days, 30 days, or never.
- Create the link and copy it.
Warning
The link token is shown once, when the link is created — Cothon stores only a secure hash of it. Copy the link right away. If you lose it, revoke it and create a new one.
Anyone with the link can open the shared item without a Cothon account, until the link expires or you revoke it.
Permission levels
| Level | What it allows |
|---|---|
| View only | Read the analysis or proposal |
| Can comment | View plus participate in discussion |
| Can edit | View, comment, and make changes |
You can change a share's permission level after creating it, and update a link's expiry.
Revoking access
Every share — user or link — is listed in the Share dialog with a Revoke option. Revocation is immediate:
- Revoked user shares remove the teammate's access on their next request
- Revoked links stop working for everyone, even if the link has been forwarded
Access activity log
Cothon records the activity on each share:
- When the share was created, changed, or revoked, and by whom
- Each access through a share link, including timestamp, IP address, and browser (user agent)
- An access counter per link
Review this log from the Share dialog to know whether — and how often — a link you sent out has been opened.
Note
For privacy, plaintext link tokens never appear in the logs; accesses are recorded against a short non-reversible fingerprint of the token.
Security notes
- Link tokens are long, random, and stored only as SHA-256 hashes — a database leak would not expose working links
- Expired links are rejected automatically at access time
- Only the owner of an analysis or proposal can create, modify, or revoke its shares
- Share creation, permission changes, and revocations are recorded
Good practices
- Prefer user shares for teammates — access follows their account and ends when they leave your organization
- Use expiring links (1–7 days) for external parties such as teaming partners
- Revoke links as soon as the recipient no longer needs access
- Check the access log after sharing sensitive pricing or strategy content
What sharing does not include
To keep expectations clear: there are no password-protected links, watermarks, download restrictions, or email-verification gates on shared content. A link share grants the permission level you chose to anyone holding the link — treat links accordingly.
Next steps
- Activity & Audit Logs — the full picture of activity tracking
- Comments & Notes — discussing shared content
Related Articles
Was this page helpful?