Plan: Not Available: Intermediate Available: Pro or Elite
Users: Available: All users
Practice Management Source: Available: All sources
Secure Link (beta) allows practices to securely send sensitive FYI documents to clients or contacts by email when the recipient needs to access and download the files for their own records. FYI sends a verification code by email or SMS so recipients can verify they are the intended recipient before downloading the documents.
When sharing documents using Secure Link, users can select Forms (Elite plan only), Word, Excel, PowerPoint, and PDF documents stored in FYI. Form templates (Elite plan only), Phone Calls, Meetings, File Notes, or any documents currently being edited cannot be shared. Documents must be finished editing before sharing.
This feature is currently in beta. Learn more about beta registrations.
Setting up Secure Link
Before sharing documents, complete the following steps to configure Secure Link and prepare your data.
When sharing documents using Secure Link, you must select an Email Template that contains the Merge Field used to insert the link to the shared documents. If the Email Template does not contain this Merge Field, you will not be able to share documents using Secure Link.
Email templates can be created by an FYI Admin or a user with permissions enabled for Templates.
- Create a new Email Template and add the body text to be sent to the recipient.
- Position the cursor in the Email Template or Signature where you want the link to appear.
- Expand the Document section and click Secure Link.
- The Merge Field code will be added to the body of the Email Template, displayed as
{{ DocumentSecureLinkURL | web_link }}.
When sending the email, the link will be displayed as "Click here".
When verifying the identity of the recipient accessing the files, Secure Link uses the contact details stored in FYI.
Ensure these contact details are correct before sending documents using Secure Link. Incorrect or missing details will impact the recipient's ability to enter a code and access the documents. Documents will need to be reshared if the details are updated.
For practices on the Elite plan, FYI offers a custom process for updating client details using Forms, allowing clients to review and update their details.
Secure Link checks the following contact details:
| Details | Location |
| Recipient Email Address |
|
| Recipient Phone and Mobile fields |
The details for both the client and primary contact will be reviewed. If a valid mobile number is not available, the code will be sent by email instead. |
An FYI Admin can update the Documents Practice Settings to configure how long links to shared documents remain available, and the default email template used when sharing documents using Secure Link.
By default, access to documents will expire 30 days after they have been shared. Changes to the expiry period will only apply to new documents shared via Secure Link. Any existing shared documents will retain the expiry date configured when the documents were shared.
When sharing documents using Secure Link, the default email template will be selected automatically (unless you have already selected a template when creating an email).
- Click Settings in the top-right corner, and select Practice Settings.
- Select Documents.
- Click the Secure Link tab.
- Enter a new Share expiry period value between 1 and 365 days.
- Select a Default Email Template from the drop-down.
- Changes will be saved automatically, and a message will be displayed to confirm that the settings were updated successfully. An alert will be added to Practice Activity to record changes made to the settings.
Sharing documents using Secure Link
When sharing documents using Secure Link, you can send one or more documents stored in FYI, including Forms (Elite plan only), Word, Excel, PowerPoint, and PDF. Documents can be shared individually by email, or automatically using a custom process.
Form Templates (Elite plan only), Phone Calls, Meetings, File Notes, or any documents currently being edited, including internally co-edited documents, cannot be shared. Documents must be finished editing before sharing.
Files are limited to a maximum of 50 MB each. Up to 10 files can be shared at the same time.
Documents cannot be shared for archived clients using Secure Link.
Sharing documents individually
To manually share a document using Secure Link:
- Select one or more documents from the Documents list.
- Click the Share button in the toolbar to display the Create Email drawer.
If the Share button is disabled, ensure that the selected documents are the correct Document Types and have been finished editing before sharing.
- You can select additional recipients to send the email to. Each recipient will be required to verify their identity separately to access the documents.
Click the 1 Recipient link and then click the drop-down to display contacts or to enter a new email address.
Additional recipients must be added using To. BCC and CC recipients cannot access documents shared via Secure Link.
If sharing a form with multiple recipients, the form can only be submitted once and will become unavailable to other recipients. A reminder message will be displayed when creating the email. Refer to Using Forms with Secure Link below.
- Select a Template from the drop-down. The selected template must have the Secure Link Merge Field included to ensure a link is sent to the email recipient.
- Update the filing details as required.
- Select an option from the Save or Send field to save the email as a draft in FYI or Outlook, or to send the email immediately.
- In Send Attachments select Secure Link.
To select Secure Link as the default Send Attachments method when sharing documents for this client, update the Send Attachments field in Client Settings. - The Expiry Period is displayed at the bottom. Once expired, recipients will need to contact the practice to request a new link.
Access to shared forms will expire based on the Secure Link Expiry Period, or once the form has been completed and submitted.
- Click Create.
- A notification is displayed in the bottom-right corner to confirm that the email is being sent.
Sharing documents automatically
Documents can be automatically shared via Secure Link using the Create Email automation step. Refer to Setting up Custom Processes.
When sharing documents using Secure Link via a custom process:
- Recipients must be added as a "To" recipient. BCC and CC recipients cannot access documents shared via Secure Link.
- The selected template must have the Secure Link Merge Field included to ensure a link is sent to the email recipient.
- Ensure Secure Link is selected in the Send attachment(s) field.
Accessing documents using Secure Link
To ensure that shared documents are only opened by the intended recipients, the client or contact will be asked to verify their identity before they can access shared documents.
These steps must be completed each time the link is used to access the files.
Receiving the shared document link
- The client or contact receives an email notification with a link to the shared documents.
- The recipient clicks on the link and is prompted to enter their email address.
The email address must be the same email address that the documents were shared with. If a recipient's email address is changed after documents have been shared, the documents will need to be shared again using the new address.
If the recipient enters an incorrect email address three times, access will be denied. The recipient will need to contact the practice to confirm their details and request a new link. - Click Continue. A multi-factor authentication (MFA) code will be sent to the recipient by SMS or email.
- The recipient enters the verification code.
- The code will be authenticated, and a download link will be displayed to download the documents or forms.
Receiving the MFA verification code
By default, FYI will first attempt to send the code by SMS. If a matching mobile number cannot be found in FYI for the recipient, an email will be sent instead.
If more than one contact in FYI uses the same email address, the recipient will be asked to select their mobile number before the code is sent. Click "My number is not displayed" to send the code by email instead.
The verification code is valid for 5 minutes, with the expiry date and time displayed in the recipient's local time. A new code can be requested once the current code expires.
If an invalid code is entered five times, the recipient will be locked out for 30 minutes. After the lockout time expires, they will be able to request a new code.
SMS
An SMS will be sent to the recipient when a mobile phone number is stored in FYI in either the Phone or Mobile fields for the client or primary contact.
If more than one contact in FYI uses the same email address, or the client's primary contact in FYI uses different mobile numbers, the recipient will be asked to select their mobile number before the code is sent. Select "My number is not displayed" to send the code by email instead.
When the SMS is received:
- The sender will be displayed as "FYI".
- The practice's name will be displayed at the start of the message.
- The message will be displayed as follows:
"(Practice name) has shared documents with you. Your verification code is (code). This code expires in 5 minutes. Do not share this code with anyone."
If a mobile number cannot be found in FYI for the entered email address, or the recipient selects "My number is not displayed", the code will be sent by email.
When the email is received:
- The email will be sent from the email address no-reply@fyi.app.
- The email subject will be "Your FYI verification code".
- The message will be displayed as follows:
"(Practice name) has shared documents with you securely via FYI. Your verification code is:
(code)
This code expires in 5 minutes. If you did not request this code, you can ignore this email - no further action is required.
Do not share this code with anyone."
Viewing the download link
The download link is only valid for 15 minutes. After 15 minutes, recipients will need to click the link in the email and restart the verification process.
Click the sections below for examples of how the download link is displayed depending on the type of documents shared.
Single document
The following is an example of when only a single document has been shared using Secure Link.
Single form
The following is an example of when a form has been shared using Secure Link.
Multiple documents
The following is an example of when multiple documents have been shared using Secure Link.
Multiple forms
The following is an example of when multiple forms have been shared using Secure Link.
Documents and forms
The following is an example of when both a document and a form have been shared using Secure Link.
Working with Secure Link
Supported SMS verification mobile number formats
For details on supported phone number formats, click the relevant region below.
The following phone number formats are supported.
| Supported formats | Example |
| Mobile number with an AU country code, excluding the 0. Spaces may or may not be included. | +61412345678 +61 412 345 678 +61412 345 678 |
| Local number (no country code) with a 0 prefix. Spaces may or may not be included. | 0412345678 0412 345 678 |
| Local number (no country code) with hyphens. | 0412-345-678 |
The following phone number formats are unsupported.
| Unsupported formats | Example |
| Missing a prefix. | 412345678 |
| Missing the + before the AU country code. | 61412345678 |
| Landline number (doesn't start with a 4 after the prefix). | 0212345678 |
The following phone number formats are supported.
| Supported formats | Example |
| Mobile number with an NZ country code, including short variants, excluding the 0. | +64211234567 +6421123456 |
| Local number (no country code) with a 0 prefix, including short variants. | 0211234567 021123456 |
The following phone number formats are unsupported.
| Unsupported formats | Example |
| Missing a prefix. | 211234567 |
| Missing the + before the NZ country code. | 64211234567 |
| Prefix is in brackets or parentheses. | (+64) 211234567 |
| Landline number (doesn't start with a 2 after the prefix). | 0311234567 |
| Mobile number contains spaces or hyphens. | 021 123 4567 021-123-4567 |
The following phone number formats are supported.
| Supported formats | Example |
| Mobile number with a UK country code, excluding the 0. Spaces may or may not be included. | +447911123456 +44 7911 123456 |
| Mobile number with a UK country code, excluding the + prefix. | 447911123456 |
| Local number (no country code) with a 0 prefix. Spaces may or may not be included. | 07911123456 07911 123456 |
The following phone number formats are unsupported.
Mobile numbers from the Republic of Ireland are not supported.
| Unsupported formats | Example |
| Mobile number with hyphens. | 0791-1123456 |
Activity tracking
The Activity section of the Document drawer displays updates when using Secure Link. This includes when:
- A link has been generated and sent, including the user who generated it.
- An MFA code is requested, including the recipient's email address and the method used to send the code (SMS or email).
- The shared document has been accessed using the link, including the email address of the recipient who accessed the link.
- There have been 3 unsuccessful email verification attempts.
- An incorrect code has been entered more than 5 times, and the user is locked out for 30 minutes.
- The Secure Link verification code fails to be delivered, including the Recipient's email address and the method used to send the code.
Using Forms with Secure Link
Form names will only be displayed to the recipient after they have verified their identity and accessed the shared documents.
Where multiple forms have been shared, the recipient can click on the Open Form link to open and complete the form in a new window.
If sharing a form with multiple recipients, the form can only be submitted by one recipient. Once submitted, the form will become unavailable to the remaining recipients.
A reminder will be displayed to the user in FYI prior to sending the email.
If the form is required to be submitted by each recipient, you will need to create and share a separate form for each recipient.
Secure Link expiration
Access to documents will end when the Secure Link expiry period is reached, or the form is submitted.
Archiving, restoring, or merging clients in FYI will not affect documents shared using Secure Link. Access to the documents will be removed as per the configured Expiry Period.
When Secure Link access expires:
- The recipient will not be able to access the documents using the link.
- An entry will be added to the Document drawer Activity section to show that the Secure Link has expired.
- Shared documents remain within FYI, and the practice will continue to have access as required.
If the recipient needs access to the documents, they will need to be shared again from FYI.