Blog/Data rooms

Data room permissions that hold up under scrutiny

Why folder-level data room permissions leak, what per-investor access actually requires, and how to prove after the fact who saw which document and when.

·6 min read·Data rooms

Almost every fund data room starts as a shared drive with folders per investor, and almost every one of them eventually leaks something: a document in the wrong folder, a link forwarded, an investor who left the fund but whose access never got revoked. Related: What Goes in a Fund Subscription Package and Who Signs What.

Folder permissions are the wrong shape

The mental model behind folder permissions is that documents live somewhere and access follows location. The actual requirement is close to the opposite: a document has an audience, and that audience changes over its life.

A quarterly report goes to all current investors. A capital account statement goes to exactly one. A side letter goes to one investor and the fund's counsel. An amended LPA goes to everyone who signed the original, including investors who have since redeemed. None of those groups is a folder.

When the model is folders, the workarounds are duplicated files, and duplicated files are how the wrong version gets sent.

What per-document, per-investor access requires

  • Identity at the document, not the link. Access is granted to an investor, and it is evaluated when they open the document. A URL that works for whoever holds it is not access control.
  • Revocation that is retroactive in effect. Removing an investor removes their access immediately, including to anything already open in another tab.
  • Group membership that is derived, not maintained. "All investors in Fund II with a signed subscription" should be a query, not a list someone updates.
  • Versioning that does not break links. A superseded document stays retrievable for anyone who was shown it, because that is the record of what they were shown.

The question you will eventually be asked

At some point, someone asks: did this investor receive the amended terms before they signed?

Answering it requires a per-investor, per-document access log with timestamps, retained for the life of the fund and beyond. Not "the document was uploaded on the 3rd", but "this investor opened this revision on the 5th at 14:12".

Most shared drives can tell you the first. Very few can tell you the second, and the second is the one that settles the argument.

Watermarking and download control, honestly

Dynamic watermarking with the viewer's name and view-only mode are worth having. They deter casual forwarding and they make the source of a leak identifiable.

They are not confidentiality controls. Anyone determined can photograph a screen. Treat them as attribution and deterrence, price them accordingly, and do not let their presence justify putting something in a data room that should not be there at all.

The practical starting point

If you are running on folders today, the highest-value change is not migrating everything. It is separating the two document classes that actually differ: fund-wide materials, where the audience is "current investors" and can be a derived group, and investor-specific materials, where the audience is one party and every access should be logged individually.

Most of the leak risk lives in the second class, and it is usually the smaller pile.

Keep reading

More on investor operations.

Ready to run this on your own domain?

One portal for the entire investor journey: subscriptions, e-signatures, identity, data rooms and wire instructions, branded entirely to your fund.