State of M&A Data Rooms — Q2 2026 Read the report →

Permission & Security Settings

Configure who opens your Peony data room and what they can see. Choose Email access or Link access, stack the security controls per group, and set per-folder permissions.

Last updated July 22, 2026

Peony gates every data room at two levels: who can open it (access mode) and what they can do inside (security controls + folder-level permissions). You configure all of it per group — a named audience like "Series A investors" or "Buyer: Acme Corp."

For maximum control, use Email access with individual emails. For speed, use Link access with email gating. Either way, the same security controls apply.

Where This Lives

Open any data room and click the Permissions tab in the left sidebar. That's the one screen for the whole room: a Groups list on the left (each with a per-group toggle, a Copy access link shortcut, and a Create new group button), and the selected group's settings on the right.

Permissions tab with the Groups sidebar and the group wizard on step 1, Visitors, with Email access selected

To create or edit a group you step through a short wizard:

  • Visitors (step 1) — the audience: group name, access mode, and who's in it.
  • Document permissions (step 2) — the per-folder and per-file access table for that group.

You can also share a whole room in one click from the Share securely button in the top bar — it spins up a default group and drops you into the same wizard.

One word "Settings", two surfaces. The Permissions tab covers everything on this page. The per-room Settings tab (cover image, logo, index documents, notifications) and your workspace settings (bottom-left of the home screen — billing, admins, org name) are separate. When a support answer says "Settings", check which one it means.

Two Access Modes

On the Visitors step you pick the access mode:

You enter each allowed email (or domain). Only those recipients receive an invitation email; everyone else is blocked by default. Use this for fundraising, M&A, diligence — any time you need a clean audit trail of who got the invite.

Peony generates one share link for the group. You send it via any channel; anyone with the URL attempts access. Use this for high-volume distribution — paid newsletters, open investor updates, conference attendees — and layer email gating on top so you still know who opened it.

Rule of thumb: If you know the recipients, use Email access. If you don't, use Link access with email gating on.

Switching modes drops the emails you typed. We don't recommend flipping one group between Email access and Link access — toggling the mode can clear the viewer emails you'd already entered. If you need both, create a second group instead of re-using one. A proper fix is on the roadmap.

The Security Controls (Both Modes)

Inside a group you'll see the Security control panel. The set of cards is dynamic — Email-gated access appears only in Link access mode, and AI document Q&A appears only for AI-enabled folders — but the core controls are the same in both modes. Each is independent; toggle what you need.

  • Password protection — optional shared password, sent out-of-band (Signal, phone).
  • Expiry — auto-revoke access on a date you pick.
  • Dynamic watermark — viewer email + IP overlaid on every page. Data Room tier and up. See Dynamic Watermarks.
  • One-click NDA — upload a PDF for acknowledgment or select a template for e-signature. See NDA Gates.
  • Screenshot protection — blocks desktop captures and logs attempts. Advanced screenshot protection (Screenshield) is Data Room tier and up. See Screenshot Protection.
  • Access questions — custom questions the viewer answers before entry (e.g. "Which fund are you from?"). Data Room tier and up.
  • AI document Q&A — allow or disable in-room AI search for this group (shown for AI-enabled folders). Advanced AI answering is paid-only, so trial and Free users see a degraded experience.
  • Appearance — a group-specific theme plus an optional welcome message. Custom logo, colors, and welcome message are Business tier and up; a custom domain requires Data Room tier. See Custom Branding. (The room's cover image is a separate control — the Show cover image card on the per-room Settings tab, noted in the callout above — not part of the group's Appearance card.)

Why a higher-tier feature triggers an upgrade prompt. If you set a plain Expiry or password on Business and still get an upgrade pop-up, it's almost always a higher-tier feature that's also switched on — usually Dynamic watermark (Data Room tier). Controls that flash a purple or orange badge are higher-tier. Turn the higher-tier control off and the rest of your settings save on Business.

Granular Folder & File Permissions

Open the group's Document permissions step (wizard step 2). It lets you set No access / View / Download / Upload for every folder and file in the room — per group. For the full walkthrough of that table — what each of the four levels grants, how per-file overrides work, and how to revoke — see Granular Access Control.

Tier note. View / Download link-level defaults are available on lower tiers. Granular per-folder and per-file permissions — and the Upload level — are Data Room tier ($52/admin/mo) and up. That's the plan you need when different parties must each see a different subset of the same room.

Typical M&A pattern: give Tier-1 buyers View on the full tree plus Download on the teaser, but No access on customer lists until LOI. Use the slider under each row to choose the level. Children inherit the parent folder's setting unless you override them.

New folders default to visible for every group. When you add a folder, it inherits access from all existing groups — you toggle it off per group manually. There's no per-room "new folders default to No access" setting yet (it's on the roadmap; permissioning is a heavy DB change). If you need hard separation, split the content into a separate data room instead.

Blocking downloads: two different controls

There are two distinct download controls, and support tickets often confuse them:

  • The per-folder Download level (in the Document permissions table above) sets whether a group can download a specific folder or file. Drop a file to View or No access to stop that group downloading it.
  • The Allow downloads toggle (in the link's settings) is a room-wide download switch. On Free it shows a Requires Business plan badge — turning downloads off (download prevention) is a Business-tier feature.

To stop investors downloading, say, your SAFEs: refresh the room, then set those files to View in the Document permissions table for that group.

Groups: The Permission Container

Groups are Peony's unit of permissioning. Each group has its own security stack, visitor list, and folder permissions. A group's visitor list can be anything from one person to dozens — you decide.

Create a new group whenever an audience needs different permissions from another — different NDA, different watermark, different folders visible. Different VCs, different buyer firms, different LPs typically each get their own group. This gives you:

  • Independent security settings (NDA on for one, off for another)
  • Separate analytics per group
  • Clean revocation (kill a group without touching the others)

If two audiences should see the exact same thing under the exact same rules, one group holding both sets of emails is fine.

How many groups when several parties bid? Invitees never see who else is invited — same group or separate. Rule of thumb: with fewer than 8-10 counterparties, give each its own group for granular control; beyond that, group by stage (early / mid / late diligence).

Groups don't cross rooms. A group lives inside one data room. The same audience must be re-created in each room — there's no cross-room group reuse.

Rename a group that still shows the template name

Group and link names are edited on the Visitors step, not in Settings. Open the group, change the name there, and Save (bottom right). The visitor-facing room name is edited the same way.

Sharing a Tailored Version With One Person

A group's link can be sent to one recipient or to fifty — it's not limited. But if you want one specific person to get their own version (say, a buyer who should see an earlier data snapshot, or an investor who gets one extra folder), create a new group dedicated to them. You can tune that group's security and folder access without touching anyone else's.

Domain Gating

In Email access, the People with access input on the Visitors step accepts either a full email (investor@fund.com) or a bare domain (fund.com). Enter a domain and anyone with an address at that domain can accept the invite. Domain gating (entering a bare domain rather than individual emails) is a Data Room tier and up feature — on Free or Business, adding a domain returns the toast "Domain-restricted access requires a Data Room plan". Individual emails work on every plan.

Useful for enterprise diligence where the buyer's deal team is large and not fully named yet. For higher security, stick to individual emails — everyone not listed is blocked by default, and you keep a per-person audit trail.

Custom invite email (Deal Team). For Email access (invite-only) groups, Deal Team admins can switch on a Custom invite email in the group's Visitors settings and edit the invitation's subject, logo, and body with a live preview. See Custom Branding.

Switch the group to Link access and one more card appears in the Security control panel: Email-gated access. Click it to open the Require email dialog:

Require email dialog showing toggles for Require viewer info, Verify email, Allow list, and Block list

  • Require viewer info — viewer must enter an email before the room loads. This is what captures names when analytics would otherwise show "anonymous". Available on every plan, including Free.
  • Verify email — Peony sends a one-time code to prove the viewer owns the address. Business tier and up.
  • Allow list — only listed emails proceed past the gate. Business tier and up.
  • Block list — listed emails are rejected; everyone else proceeds. Business tier and up.

Best practice for link-shared rooms: turn on the Allow list so a forwarded link can't be opened by anyone you didn't intend.

This is the question most teams get wrong:

Email accessLink access + Email gate ON
Who receives the invitation email?Only the emails you listNobody — you send the URL yourself
Default behavior for unlisted emailsBlockedAllowed (unless on block list)
Audit trail of inviteesYes, you listed themNo — you only see who opened
Best forDeals with named counterpartiesBroad distribution (newsletters, teaser decks)

Both capture the viewer's email for watermarks and analytics. The difference is the default: Email access denies everyone but the list. Link access allows everyone but the block list. Note that in Email access mode Peony emails each recipient an invitation; in Link access mode no one is notified — you send the link yourself.

For anything sensitive, use Email access. Use Link access only when reach matters more than a clean list.

Removing or Reviewing Access

  • Email access: open the room's Permissions tab, then the group's Visitors step. Hover a granted email and click the x to remove it. Save (bottom right).
  • Link access: open Email-gated access, then Edit block list to reject an email, or manage the Allow list to control exactly who's permitted.

A name in the Visitors list doesn't always mean active access. The Visitors list keeps historical activity across every link to the room, so a revoked person can still show in the history. If you see unexpected or anonymous entries you can't explain, contact support with the link — an anonymous entry often traces back to an old open-access test link.

Saving Your Changes

Hit Save (bottom right) after editing a group's Visitors or Security settings — the most common "my changes disappeared" cause is not clicking Save. Added emails trigger invitation emails immediately. Toggle changes apply the next time any viewer opens the room.

Common Mistakes

  • Reusing one group for every audience. You lose per-group analytics and one viewer's revocation affects the rest. Create a group per audience.
  • Link access without email gating. Anyone with the URL walks in. At minimum toggle Require viewer info (and Verify email on Business+).
  • NDA on, but configured on the wrong group. NDA gates are per-group. Toggle it on the group you're actually about to share.
  • Ignoring folder permissions. Security controls don't limit which files the group sees. Use the Document permissions table to hide folders per group.
  • Leaving downloads on while expecting the watermark to hold. Pair watermarks with the file set to View in the Document permissions table.

Common Questions

Which mode is more secure, Email access or Link access? Email access. Its default is deny-all-except-listed, so nobody outside your list sees the room even if the URL leaks. Link access with email gating approximates this but requires you to maintain a block list rather than a trusted list.

Can I switch modes after I've already shared? Yes, but do it carefully — switching a group's mode can wipe the viewer emails you already entered. Change it on the Visitors step and Save. If you need both modes, create a second group instead. Any active link keeps working under the new rules on the next open.

Do the security controls behave the same way in both modes? Yes — password, expiry, watermark, NDA, screenshot protection, access questions, AI Q&A, and appearance apply identically in both modes. Link access just adds Email-gated access as an extra card.

How do I stop investors downloading specific files (they can view but not save)? Open the group's Document permissions step and set those files to View or No access. Granular per-file permissions are Data Room tier and up. Refresh the room after changing them.

How do I capture visitor names when analytics show "anonymous"? Use Link access, open Email-gated access, and turn on Require viewer info so every viewer enters an email before the room loads. Add Verify email (Business+) if you want to confirm they own the address.

Why do I get an upgrade pop-up when I only set an expiry date? The prompt is triggered by a higher-tier feature that's also enabled, not the expiry. It's usually Dynamic watermark (Data Room tier). Controls with a purple or orange badge are higher-tier — turn that one off and your expiry saves on Business.

How do I turn AI Q&A on or off for visitors? In the group's Security control panel, toggle AI document Q&A off. Advanced AI answering is paid-only, so trial and Free users get a limited experience.

Do viewers need a Peony account? No. Viewers never sign up. They enter their email at the gate, verify the one-time code if enabled, and read the room in the browser. Viewer access is free and unlimited on every plan.

What happens if someone forwards my link to a colleague? In Email access, the colleague is blocked unless you added them. In Link access with the allow/block list configured, the colleague must pass it; if they're not blocked, they proceed and appear in analytics under their own email.

Can I watermark differently per group? Yes. Watermark is a per-group setting in the Security control panel (Data Room tier and up). Turn it on for external buyers, off for your internal team group.

Can I share a group's link with multiple people? Yes. A group's visitor list or share link can go to one person or to dozens. Groups exist to separate audiences that need different permissions — not to cap how many viewers one group holds.

Can I reuse the same group across two data rooms? No. Groups are scoped to a single data room, so you re-create the audience in each room.

Next Steps