Decide whether this grant fits the intended sharing
Sharing should begin with a question about scope: what does the advisor need to see, for which organization, and for how long? A recipient name and a convenient link are not enough to answer that question.
RiskSensai’s advisor access interface offers evidence access choices and expiry. Its current evidence scope is important: access includes the available organization evidence during the lifetime of the grant, including material added later. It is not an individually selected, frozen subset of files.
If your intended review requires only one document, do not assume a broad evidence grant is narrow enough. Consider whether an appropriately scoped packet workflow or another approved process is needed. Do not create broader access simply because the form is ready.
Check the organization and your authority
Open the advisor workspace in the correct organization. Confirm that you are authorized to arrange access and that the organization owner understands the proposed scope. Existing role and tenant boundaries remain in effect.1
Review the recipient description carefully. A typed email or name describes your intended recipient; it is not proof that the link can only be used by that person. The current access mechanism is a bearer link. Anyone who receives a forwarded usable link can carry that access.
If your policy requires authenticated identity, a particular contract or another stronger control, resolve that requirement before using the grant. Do not treat a label in the form as a substitute for the organization’s approval process.
Understand the evidence choices
| Choice | What to understand before selecting it |
|---|---|
| None | No evidence access through this evidence scope |
| Metadata | Evidence-record context rather than file bytes |
| Files | File access within the grant’s organization evidence scope |
Select the minimum scope appropriate to the task. Metadata can still contain sensitive information in titles or descriptions, so “no file bytes” does not mean “no information disclosed.” Review that context as well as the attachments.
Files is a broader decision. The current form’s evidence access is not narrowed by a framework filter. A framework choice applies to the gap summary, while the evidence scope includes available organization evidence across the grant’s lifetime.
Account for later additions
Imagine that an advisor needs to inspect your organization evidence this week. You select Files and a 14-day lifetime. Tomorrow, a colleague adds a new evidence file. Under the current scope, that later file can be part of the available evidence during the remaining lifetime.
That behavior can be useful for a continuing review, but it is not a frozen disclosure. Before creating access, tell the relevant team members that additions can fall within the grant. If that is unacceptable, do not proceed with the broad grant and assume you can fix the scope afterward.
| Intended review | Question before granting access |
|---|---|
| One specific export | Is a broad organization-evidence grant appropriate at all? |
| A continuing evidence review | Which later additions may become available during the grant? |
| A framework gap discussion | Does the selected framework affect only the summary rather than file access? |
This check prevents a visual filter from being mistaken for an authorization boundary.
Choose an expiry deliberately
The current dialog offers 7-, 14- and 30-day durations. Choose a duration based on the work rather than the longest convenient option. Confirm when access needs to end and who will review it if the work changes.
Expiry limits future access through the grant. It does not delete copies that someone already downloaded or forwarded. If the organization requires a specific treatment of downloaded material, agree that requirement separately with the recipient.
Do not infer a professional engagement from the access duration. A two-week grant is not a booked two-week review, a service-level agreement or a promise that an advisor will complete work within that period.2
Review the complete decision before creating access
Use a short pre-action checklist:
- The organization is correct.
- The intended recipient and sharing purpose are clear.
- None, Metadata or Files accurately reflects the permitted disclosure.
- The team understands that evidence scope can include later additions.
- The duration is appropriate and a person owns revocation if needed.
- Bearer-link forwarding and identity limitations are acceptable for this task.
If any item is unresolved, stop at review rather than creating the grant. The privacy policy and your organization’s handling rules remain relevant to what can be shared.3
Confirm the result without assuming delivery
After the permitted creation action, inspect the saved grant and the interface’s receipt. A created access link is not proof that an email arrived, that the named person opened it or that a review began.
Use an approved delivery channel and explain the scope and expiry to the intended recipient. Do not publish a bearer link in a broadly accessible document or paste it into an unrelated conversation. Forwarding the usable link forwards access.
If the write result is uncertain, check the saved grant state before creating another one. Preserve the error and resolve ambiguity rather than leaving multiple grants active accidentally.
Revisit access as the work changes
If the review ends early, the recipient changes or new evidence makes the scope inappropriate, use the existing revocation process. Confirm the relevant grant rather than revoking a similarly named record by assumption.
Revocation blocks future use through that grant; it cannot recall previously downloaded material. Keep the recipient’s handling obligations and your own disclosure record separate from the application control.
A sound sharing decision ends with a known organization, an acceptable scope, a deliberate lifetime and a clear owner. It does not end with a link alone, and it does not establish advisor availability, formal assurance or verified recipient identity.
Sources and references
-
RiskSensai. RiskSensai Security. Describes current evidence and access-control limits. ↩
-
RiskSensai. Request a Trust Readiness Review. Explains working-brief preparation and matching limits. ↩
-
RiskSensai. RiskSensai Privacy Policy. Provides the published data-handling policy. ↩

