What shows up there
- Documents you shared — a motion email play whose attachment rides as a portal link, a packet applied to the account, or a document shared from the account’s Documents section in Studio’s orbit. Rows are attributed — “Shared by Sam” or “Shared by your team” — with the share date.
- Documents the customer uploaded — attributed “You uploaded.”
The index and viewer
Each row shows a real first-page thumbnail — for PDFs, Thread renders page one of the actual file (images are downscaled directly); when a file type can’t be rendered, a quiet file-type tile stands in. No generic icon grids. Clicking Open slides an in-portal viewer over the list — never a new tab, never a route change. Every open mints a fresh short-lived signed URL, so document access always reflects what’s currently shared: revoking a share on your side revokes the customer’s access on their next open.Landing pages for emailed links
When an email play delivers a document as a portal link, the branded “View document” button in the email carries the customer through their magic link straight to a per-document landing page: the file name, who shared it and when, an inline viewer, a download button, and a ”← All documents” link back to the index. Two properties worth knowing:- Views are recorded. When a customer opens a document you shared, the view is logged, so link-mode attachments are trackable in a way file attachments never are.
- Dead links degrade gracefully. If a document has been revoked or the link is stale, the customer never hits a broken page — they see “This document is no longer available” with a pointer to the most recent email from your team, which always carries a current link.
Customer uploads
Customers can upload from the Documents page (Upload — PDF, PNG, JPG, TXT, and CSV) or by handing a file to the concierge chat. The page’s empty state invites exactly this: “Upload a document to share it with your team.”- Uploads land back on the account on your side, alongside the account’s other documents.
- Customers can Remove their own uploads — but only their own; documents you shared aren’t removable by them.
- There are no folders or renaming on the customer side — the surface is deliberately simple: upload, open, remove.
Files a customer submits inside a collection flow are read for
data extraction rather than published to this list — the collection’s confirmed result is what
lands on the account.
