Skip to content
All insights

How to Share Board Papers Securely with Directors (2026)

On this page
  1. Why board papers deserve special handling
  2. What secure board paper sharing looks like
  3. Where board papers sit in the governance record
  4. How 99 Data Rooms handles board papers
  5. Circulate your next board pack securely, for free
  6. Sources

To share board papers securely, send each director a gated, tracked link to the pack rather than an email attachment: require a verified identity to open it, keep one live version everyone reads from, log who opened what, and revoke access the moment a director leaves the board. Board papers are among the most sensitive documents a company produces. They can contain draft strategy, financial results before they are public, legal advice, personnel matters and acquisition plans, and they go to a group of people who are often outside your day-to-day systems, using personal devices and personal email. Emailing the pack around is the norm and it is exactly the wrong habit. This guide explains how to circulate board papers with proper control. It is general information, not legal advice.

The recurring scene: a company secretary or founder assembles a pack the night before a meeting, attaches a large PDF to an email, and sends it to the board. From that moment the pack exists as uncontrolled copies on multiple devices, some of them personal laptops and phones, with no expiry, no read visibility and no way to pull it back if a director resigns or a document turns out to be wrong. The papers sit alongside the formal record of decisions, so it is worth understanding how the pack relates to the board minutes and any board resolution that follows, which we cover separately.

Why board papers deserve special handling

Three features make board papers riskier than routine documents.

The content is exceptionally sensitive and often price-sensitive. Draft accounts, an acquisition under consideration, a redundancy plan or legal advice can all cause real damage if they leak, and for listed or soon-to-be-listed companies some of it may be inside information. The audience, meanwhile, is dispersed: non-executive directors in particular often have no company laptop, use personal email, and sit on several boards, so your pack lands in a personal inbox next to everyone else's. And the membership of the board changes: directors join and resign, and when someone steps down you need their access to historic and future papers to stop, cleanly and provably.

Attachments fail all three tests. They cannot be recalled, they give you no record of who opened them, and they scatter sensitive material across devices you do not control. A non-executive director's obligations, including the duty to declare interests and to avoid conflicts, make careful information handling part of good governance rather than mere hygiene; we set out the role in what is a non-executive director agreement. Getting the mechanics of sharing right supports directors in meeting those duties rather than working against them.

What secure board paper sharing looks like

Good practice comes down to four disciplines.

Named, verified access. Each director gets their own gated link, and opening the pack requires a verified email and ideally a one-time code, so access is tied to a named individual rather than a forwardable URL. If a link is passed on, the recipient still has to pass the gate. This also means your access log reflects real people. Our gating and access-control feature page explains the mechanics.

One live version. Board packs are notorious for last-minute changes: a revised paper arrives at nine the night before. Rather than sending "version two, use this one", you keep a single link and swap the file behind it, so every director always opens the current pack and nobody debates from a superseded paper. You keep a private history of what changed.

Read visibility. It is genuinely useful, and sometimes governance-relevant, to know whether directors have opened the pack before the meeting. Page-level analytics show whether each named director actually opened the papers and roughly what they engaged with, which helps the chair chase anyone who has not looked and lets the secretary confirm circulation.

Clean offboarding. When a director resigns or is not reappointed, one click revokes their access to the room, so they can no longer reach future or archived papers. This is far more reliable than hoping they delete the emails, and it leaves an audit record of when access ended.

Where board papers sit in the governance record

Board papers are the inputs to a meeting; the minutes and any resolutions are the outputs. Keeping them together in one controlled place, rather than scattered across inboxes and shared drives, makes the whole record easier to manage and to defend if it is ever questioned. The pack informs the discussion, the board minutes record what was discussed and decided, and where a formal decision is needed a board resolution captures it. If you are unsure which instrument does which job, our explainer on board minutes versus board resolutions draws the line clearly.

Holding all of this in a single room per board, or per meeting, means access control, version control and the audit trail apply consistently. A director who joins gets access to the room; a director who leaves loses it; the historic packs and their reading records stay intact and retrievable. That is a far cleaner governance posture than a trail of emailed PDFs nobody can fully account for.

How 99 Data Rooms handles board papers

99 Data Rooms lets a company secretary or founder run the whole cycle in one place. You create a room for the board, upload the pack, and share it as tracked, revocable links, one per director. Before anyone opens the papers you can require a verified email and a one-time code, and on the Business tier you can require an NDA to be accepted first, so the pack only opens for the named directors you intend. You can read more on our virtual data rooms feature page.

When a paper changes at the last minute, file swap updates the file behind the existing link, so every director opens the current pack and you keep a private version history. Page-by-page analytics show whether each director has opened the papers, with the clear split between a verified viewer and a raw visit, explained in visits versus verified, so the chair can nudge anyone who has not read them. On the Business tier, dynamic watermarking stamps each view with the director's identity, a sensible deterrent for genuinely sensitive packs. When a director leaves the board, one click revokes their access, and the 24-month audit trail records when it ended. Because the minutes and resolutions can live in the same room, the inputs and outputs of each meeting stay together and controlled.

The honest note we apply to every security feature: these controls are about deterrence, visibility and recall, not a guarantee that a determined person can never copy a page. What they do is make the controlled channel the default and give you a defensible record of circulation and access. The wider platform is in beta and improving fast, but the board-pack loop works today.

Circulate your next board pack securely, for free

You can gate, version, track and revoke board papers inside 99 Data Rooms, keeping the minutes and resolutions in the same room. The free tier is a real tier, not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, build a room for your board, and send your next pack as controlled links.

Sources

Questions, answered
How should board papers be sent to directors?

Send each director a gated, tracked link to the pack rather than an email attachment. Require a verified identity to open it, keep one live version via file swap, log who has read it, and revoke access when a director leaves. That is how to share board papers securely and keep a defensible record.

How do I handle a director who resigns mid-term?

Revoke their access to the board room with one click, so they can no longer reach future or archived papers. This is more reliable than asking them to delete emailed PDFs, and it records the date access ended, which supports clean governance.

Can I tell whether directors have read the pack before the meeting?

Yes, with page-by-page analytics you can see whether each named director opened the papers and roughly what they engaged with, distinguishing a verified viewer from a raw visit. This helps the chair chase anyone who has not looked before the meeting starts.

What about last-minute changes to a paper?

Use file swap: upload the revised paper behind the existing link so every director opens the current pack, and keep a private history of what changed. Nobody debates from a superseded version, and you avoid the "use this one instead" email.

Should board papers, minutes and resolutions be kept together?

Keeping the inputs (papers) and outputs (minutes and any resolution) in one controlled room makes the governance record consistent and defensible. See board minutes versus board resolutions for which instrument records what.

Keep reading