From the [Share] button on your SOP, you can issue an external sharing URL that can be accessed without login. Use this feature to share SOPs with contractors, business partners, or event participants who don't have a Dive account.
💡 Not sure about the difference between "external sharing URLs" and "Guest" access? Check out External SOP sharing: Usage guide first. You'll find a decision flowchart and comparison table on one page.
You can protect issued URLs with either (or both) of the following:
- Expiry date: Access becomes unavailable after the specified date
- Password: A password is required when viewing
Once issued, URLs can be modified for expiry date, password changed (rotated), disabled, or re-enabled. A record remains showing who issued which SOP and when.
Before you start: Team activation required
The External Sharing feature is disabled by default for security. An Owner must configure team settings to use it.
- See I want to enable and use External Sharing for setup instructions
After activation, users in applicable roles can use this feature.
Issue an external sharing URL
- Open the SOP you want to share externally
- Click the [Share] button at the top
- In the modal that appears, open the [External sharing (no login required)] tab
- Turn on [Set expiration] and select the expiry date (the limit is 23:59 on the specified date)
- If needed, turn on [Protect with password] and enter a password (see details below)
- If needed, turn on [Open from the specified step] and select a step (viewers will start from the chosen step, not from the beginning)
- If needed, enter a Comment (for example, "For Company ABC," "For information session," etc. This is saved in the issue history and audit log)
- Click [Issue URL]. The URL is copied to your clipboard and a QR Code is displayed
From [Show print screen] below the QR Code, you can also print in a layout optimized for QR codes.
Issuance requirement: Expiry date or password
At issuance, at least one of the following conditions must be met:
- Set expiration is ON and a date today or later is specified
- Protect with password is ON and a password is entered
A "bare permanent URL" with both OFF cannot be issued. If you turn off the expiry date (creating a no-expiration URL), password protection becomes required.
Protect with password
- Manual entry: You can set any password you want (up to 64 characters)
- Auto-generate: Click the [Auto-generate] button next to the input field to create an 8-character random password with easy-to-distinguish characters (excluding 0/O, 1/l/I, etc.) in one click
- Tell the recipient separately from the URL: For security, we recommend not sending the password via the same channel as the URL (such as the same email). The password is stored hashed with PBKDF2, and the plain text is not stored anywhere the guest (recipient) can directly read
- After issuance, "This URL is password-protected." appears below the URL with the password shown, and you can copy just the password from the copy button
Behavior immediately after issuance
- The URL is automatically copied to your clipboard. Paste it directly into email or chat to share
- The QR Code is displayed on screen. You can use it for on-site scanning at information sessions
- If password protection is ON, don't forget to notify the password through a separate channel
Recipient experience
- Recipients don't need a Dive account or login — they can view the SOP simply by opening the URL
- For password-protected URLs, a [Password-protected] input screen appears immediately after opening. The SOP displays after entering the correct password. Incorrect passwords won't open it
- Once the expiry time (23:59 on the specified date) passes, the URL becomes inaccessible
- A disabled URL cannot be accessed
View and manage issue history
Below the [Share] → [External sharing (no login required)] tab for the same SOP, a history (mini-list) of URLs issued for that SOP is displayed.
- Copy URL: Re-copy the same URL from each row in the history
- Show disabled / expired: Toggle with a switch (default shows only active ones)
- Only me / Entire team toggle: Owners and Team Administrators can also view URLs issued by all team members
- [Edit / Details]: Open the full-featured "Issued external sharing URLs" list from the top right of the mini-list
Issued external sharing URLs list (full-featured)
The full list allows you to:
- Copy URL: Copy an existing URL for re-sharing
- Change expiry date: Select a new date/time to extend or shorten the expiration (password protection is required to make it no-expiration)
- Change password (rotate): Keep the URL but replace the password with a new one. Useful when the recipient changes or if there's a risk of leakage
- Remove password protection: You can only remove password protection for expiring URLs (no-expiration URLs require password since it's the only barrier)
- Disable: Prevent future access from that URL (for accidental issues or ex-partners)
- Re-enable: Reactivate a disabled URL (use with date change if it has expired)
- Filter: Search by SOP name, issuer, or comment; filter by status; toggle between "Only me" and "Entire team" scope
※ The issuer, owner, and team administrator can view the configured password (plain text) from the full list (for internal re-sharing and addressing missed communication). The token that guests (recipients) read directly does not contain plain text—only PBKDF2 hash is stored.
Audit and records
All external sharing URL issuance, disabling, re-enabling, expiry changes, and password changes are logged in the Audit log. This records who, when, which SOP, and what comment was used for issuance and operations, supporting your internal governance and audit requirements.
Tips for best use
- Keep expiry dates short: Set the minimal expiry needed for your use case (default is 7 days)
- Use password for sensitive shares: Protecting with both expiry and password means even a leaked URL cannot be viewed. The trick is sending the password through a separate channel from the URL
- Always password-protect long-lived reused URLs: No-expiration URLs require password protection. Rotating just the password periodically keeps the URL distribution intact while maintaining security
- Comment practice: Including "recipient name" and "purpose" in the issuance comment makes the history list easier to scan
- Disable when purpose ends: Disable URLs after information sessions, contract termination, or whenever they're no longer needed to reduce leakage risk
- Be careful with sensitive SOPs: Anyone knowing the URL can access it. Verify before issuance that the content is really appropriate for external sharing