A client needs the final drawings, a supplier needs a specification, and your team wants to send a link quickly. The business question is simple: how do you give the right person access without exposing the rest of the project?

For a routine client handover, start with a dedicated folder containing only approved material, a link restricted to named recipients, and a planned access review. The checklist below is a proposed operating procedure for UAE SMEs using SharePoint or OneDrive; your administrator should adapt it to the organisation's actual policies.

Illustration: AI-generated concept of restricted client file sharing, not a Microsoft interface or an ITZ client project. Technical sources reviewed on 3 October 2026.

Choose the access boundary before the link

Imagine a fit-out business handing over a final specification. Put the approved specification in a client-delivery area. Keep internal cost estimates, supplier negotiations and other clients' files elsewhere. Give the folder an owner who can answer what belongs there and when access should end.

A link is not a substitute for reviewing existing permissions. Someone might already have access through site membership, a group or an earlier invitation. Check the item's access details before assuming that a newly restricted link makes the content private.

Understand what each link type does

Microsoft explains the differences between sharing links: an Anyone link can be used without authentication by whoever obtains it; an organisation link is for users inside the organisation; a Specific people link requires the intended recipient to authenticate. Forwarding a Specific people link does not give an unlisted person access through that link.

  • Named client handover: use Specific people and verify the recipient's exact address through your established contact channel.
  • Broad internal reference: an organisation link may suit information intended for the whole workforce, but it is inappropriate for a restricted internal file.
  • Already authorised colleague: a People with existing access link points them to content without granting new permissions, as described in Microsoft's link-setting guidance.
  • Public brochure: consider an approved public publishing location. Do not mix deliberately public material with confidential client records.

Run a six-step handover check

  1. Approve the contents. Open every file you intend to share. Remove working copies, comments or embedded information that should not leave the business. Confirm the version is final enough for the recipient's task.
  2. Inspect the scope. Sharing a folder exposes its accessible contents, including material added later. Prefer the smallest practical sharing boundary and document who may add files.
  3. Select the recipient and permission. Use view access when the client only needs to read. Grant editing only where collaboration requires it; avoid changing a site's membership merely to deliver one document.
  4. Check the real recipient experience. Use an approved external test account with a harmless test file. Confirm that the invited account can open it and an unrelated account cannot. A test as the site owner does not prove external access works correctly.
  5. Record ownership and review date. Note the folder, approved recipients, purpose and responsible employee in a small handover register. Use a calendar review when automatic expiry is unavailable.
  6. Close the access deliberately. At project closure, review the relevant links and permissions, remove access that is no longer required, and test again. Removing one link does not remove separate grants.

If sharing is blocked, investigate the policy

Do not respond to an access error by switching the whole tenant to unrestricted sharing. Microsoft's administration guidance describes organisation and site settings: a site can be more restrictive than the organisation, and OneDrive cannot be more permissive than SharePoint. Guest invitation and domain restrictions can also affect the outcome.

Send IT the site or folder address, recipient domain, intended permission and exact error. Exclude confidential file contents unless needed through an approved support channel. Ask the administrator to determine whether the problem is a wrong signed-in account, a missing permission or an intentional policy restriction.

Know what access removal cannot undo

View access should not be described as a universal no-download guarantee. Available restrictions depend on the file, link and tenant configuration. Even where downloading is restricted, recipients may still capture information they can see. Previously downloaded copies cannot be recalled simply by deleting a sharing link.

For sensitive handovers, decide first whether the recipient should receive the information at all. Then discuss suitable controls with IT and the data owner. Keep the review tied to the project's business purpose rather than treating an enabled setting as proof of safety.

Make safe handovers repeatable

Use a short template: approved files, named recipients, view or edit, access owner, review date and test result. Include these responsibilities in the employee offboarding process so shared areas do not lose their business owner when someone leaves.

Need help reviewing client collaboration? Explore ITZ's Microsoft 365 services and request a sharing-permissions review. Describe the number of teams, how you exchange files and the recurring access problem; do not send passwords or confidential documents in the enquiry.