Email Requirement for Shared Links
Controlling recipient identity verification at the point of shared microapp access
1. Purpose & Scope
This article documents the Email Requirement for Shared Links feature released in Tiled v60.0.0. It describes the control mechanism, configuration procedures, and audit implications for organizations requiring evidence that shared content access was gated to identified recipients.
Scope: All Tiled customers using the microapp sharing workflow. Applicable to Library Administrators and content owners with sharing permissions.
2. Control Objective
The control objective is to restrict access to shared microapps to identifiable recipients by collecting an email address prior to content rendering. This mechanism supports the principle of least privilege, provides an audit trail of access events, and enables downstream engagement analytics attributed to verified email identifiers.
3. Feature Description
Administrators and content owners can require viewers to provide their email address before a shared microapp is accessible. This gate is configurable at two levels:
- Per microapp — applied to all share links generated from that microapp.
- Per share — applied to a specific share link instance, regardless of the microapp default setting.
|
Note: Email addresses collected through this gate are not verified (e.g., via confirmation email) in this release. Verification controls are planned for a future release. For SOC 2 evidence purposes, this control demonstrates an access identification mechanism, not a strong authentication control. |
4. Configuration Procedures
4.1 Enable Email Requirement Per Microapp
- Navigate to the Tiled Hub and locate the target microapp.
- Open the microapp Settings panel.
- Under Sharing, toggle Require email address to On.
- Click Save. All future share links generated for this microapp will present the email gate to recipients.
4.2 Enable Email Requirement Per Share
- From the microapp, click Share.
- In the share configuration dialog, locate the Require email option.
- Enable the toggle before generating or copying the share link.
- Distribute the link. Recipients accessing it will be prompted for their email before viewing content.
5. User Roles & Access Requirements
|
Library Administrator |
Can configure email requirement at the microapp level and the per-share level. |
|
Content Owner / Editor |
Can enable email requirement at the per-share level when creating a share link. |
|
Recipient (Viewer) |
Must provide a valid email address to gain access when the gate is active. |
|
Auditor / Compliance |
Can review access events via Engagement analytics to verify gate enforcement. |
6. Audit Evidence & Logging
When the email gate is active, the following evidence artifacts are generated and available for audit purposes:
- Recipient email addresses are recorded at the point of access and surfaced in the microapp Engagement dashboard.
- The Engagement > My Activity panel surfaces the notification: 'A microapp has been opened by someone other than the original recipient,' along with the collected email, when an unrecognized address accesses a share.
- Session timestamps are captured for each gated access event, supporting time-bound audit trails.
|
Note: For SOC 2 Type II audit periods, retain engagement export records on a schedule aligned with your evidence collection cadence. Tiled does not automatically archive historical engagement data beyond platform retention defaults. |
7. Related Controls
- KB-v60-02 — In-App Notification Center (notifications triggered when email gate is satisfied by a new recipient)
- KB-v60-03 — Engagement Insights: HubSpot Integration (collected emails can be dispatched as session data to CRM)
- Password-Protected Share Links (Bug Fix, KB-v60-08) — complementary access control layer
9. Change History
|
v1.0 — May 5, 2026 |
Initial article. Feature shipped in Tiled v60.0.0 (TD-6722). |