View-only documents
Let visitors read a document in the browser while the download button, zips and the raw file URL are disabled. Honest deterrence — pairs with watermarking. AI tier.
Some documents should be read, not kept: a draft policy under consultation, a tender document, an embargoed report. Mark a document view-only and visitors read it in their browser — while downloading is switched off.
FileDeck AI tier — included in all AI plans. See pricing
Make a document view-only
- Edit the document (Documents → All Documents).
- In the Document file box, tick View-only (disable downloading).
- Update.
What changes:
- The library button reads View and opens the document in a new browser tab.
- The download route refuses with a clear message, and the document is left out of zip downloads.
- The file moves into FileDeck’s deny-all protected vault, so its raw uploads URL stops working — otherwise "disabled" would be one guessed URL away.
- The preview lightbox keeps working — it streams through the same access-checked route.
Access rules still apply on top: a view-only document in a role-restricted category is only viewable by those roles.
What still downloads (by design)
Signed share links you mint from the editor still download the file — a link you created deliberately carries its own authorisation and expiry, consistent with how signed links behave everywhere else in FileDeck.
Honest framing: deterrence, not DRM
A browser that can display a file has received its bytes; a determined visitor can still save them, and no plugin can truthfully promise otherwise. View-only removes the easy path — and paired with PDF watermarking, the copy on their screen already carries their name, so anything that leaks is attributable. If a document must not reach someone at all, that’s a job for access control, not view-only.
Notes
- Works for any file type the browser can display; it’s most useful for PDFs and images. Types the browser can’t render will still end up saved by the browser — view-only is best combined with PDF-shaped content.
- Views through the view route are recorded in the activity log as
viewevents. - Lead capture, when enabled, applies to viewing too — flagging a document view-only never switches off the "leave your details" gate.
Still stuck? Email [email protected].