NOWREP
  • Home
  • Journal
  • Documentation
  • Pricing
  • FAQ
Sign InGet Started
    • Quick Start
    • Navigation Guide
    • Account Setup
    • User Settings
    • Glossary
    • Publishing Content
    • Pages
    • Posts
    • Branding
    • Navigation
    • Integration
    • Templates
    • Generating Showcards
    • Customization
    • Drafts
    • Document Library
    • Uploading Documents
    • Managing Documents
    • Sensitive & Private Documents
    • Entity Documents
    • Talent Library
    • Creating Talents
    • Talent Profiles
    • Profile Details
    • Custom Attributes
    • Measurements
    • Documents
    • Management
    • Subscription & Billing
    • Members & Seats
    • Roles & Permissions

Sensitive & Private Documents

Protect confidential files with password-locked sensitive documents and role-restricted private documents.

Overview

Not all documents should be visible to everyone on the team. The Documents module offers two levels of restricted access beyond the default Normal visibility:

VisibilityWho can see itHow access works
NormalAll team members (per role)Direct access — no extra steps
SensitiveAll team members, but requires the org passwordHidden by default; entering the password unlocks them for a limited time
PrivateAdmin and Owner onlyRole-based — Members and Viewers never see these documents

Sensitive is ideal for HR-type documents like passports, visas, and signed NDAs — files that any team member may need access to, but shouldn't be casually visible while browsing.

Private is for highly confidential admin documents like financial statements — files that only administrators should ever see.

Setting the Org Password

The org password is a shared password used to unlock sensitive documents. It is configured by an Admin or Owner.

Setup

  1. Navigate to Settings > Documents
  2. Enter a password and confirmation
  3. Optionally add a Hint — visible to all users when prompted to unlock (e.g., "Ask your office manager")
  4. Set the Unlock Duration in minutes — how long an unlock session lasts before sensitive documents are hidden again
  5. Click Save

Changing or Removing the Password

  • To change: enter the new password and confirmation, then save
  • To remove: click Remove Password and confirm. Sensitive documents will become freely visible to all team members until a new password is set.

Note: The org password is separate from individual user passwords. It is shared across the team and entered when needed to access sensitive files.

Unlocking Sensitive Documents

In the Central Library

  1. Click the lock icon in the toolbar (shows the count of sensitive documents)
  2. The Password Prompt dialog appears, with the hint if one was set
  3. Enter the org password
  4. On success:
    • Sensitive documents become visible in the library (marked with a lock badge)
    • An emerald banner appears: "Sensitive documents unlocked — N minutes remaining"
    • The unlock persists across page navigation within the duration

On Entity Profile Tabs

The same flow applies — click the lock toggle in the Documents tab header and enter the password.

Session Expiry

When the unlock timer expires, sensitive documents are automatically hidden again. If you're downloading a sensitive document and the session expires mid-action, a re-authentication prompt appears. After re-entering the password, the download proceeds automatically.

Manual Hide

Click the lock toggle again at any time to manually hide sensitive documents without ending the unlock session. This lets you quickly clear sensitive content from view if someone walks by.

Private Documents

Private documents require no password — they are simply invisible to Members and Viewers. Only users with the Admin or Owner role (specifically the documents.view_private permission) can see them.

Private documents do not appear:

  • In the central library for Members and Viewers
  • In entity Documents tabs for Members and Viewers
  • In link counts or stats for users who cannot see them

To make a document private, set its Visibility to Private in the Upload dialog or the Edit Details dialog.

Access Logs

Admins and Owners can audit who has been accessing sensitive documents.

Viewing Access Logs

  1. Navigate to Settings > Documents
  2. Scroll to the Access Logs section

The log shows a paginated table of recent access events:

ColumnDescription
DocumentName of the accessed document
UserDisplay name and email of who accessed it
ActionType of access: view, download, or failed_auth
ResultWhether access succeeded or failed
TimestampWhen it happened

What Gets Logged

  • Successful unlocks — When a user correctly enters the org password
  • Views and downloads — When a user views or downloads a sensitive document during an active session
  • Failed attempts — When a user enters an incorrect password (useful for spotting unauthorized access attempts)

Tips

  • Use Sensitive for shared-access files — Passports, visas, work permits — things the team may occasionally need but shouldn't see by default
  • Use Private for admin-only files — Financial documents, confidential agreements, internal strategy docs
  • Set a reasonable unlock duration — Short durations (5-10 minutes) are more secure; longer durations (30-60 minutes) are more convenient for bulk work
  • Review access logs periodically — Check for unexpected failed attempts or unusual access patterns

Related Pages

  • Documents Overview — Module overview and key concepts
  • Document Library — Browse and manage the library
  • Managing Documents — Edit, link, download, and delete
  • Entity Documents — Documents tab on entity profiles
NOWREP

The Future of Talent Management is NowRep

© Copyright 2026 NowRep. All Rights Reserved.

About
  • Journal
  • Contact
Product
  • Documentation
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy