Securing PDF Packs and Snapshots
Overview
Brief Connect implements built-in security for generated PDF packs and snapshots to restrict common modification operations. This guide explains how this protection works, what actions are permitted or restricted, and where this security is applied.
It is important to note that while these files are secured against tampering, they are not password-protected for viewing. Anyone with access to the file can open and read it without needing a password.
For the end-user explanation of what PDF packs and snapshots include, how some PDF clients handle downloaded files, and the recommended sharing approach, see Working with PDF Packs and Snapshots.
How Security Works
Brief Connect uses an owner password to secure PDF documents, rather than a user password.
- Owner password: Brief Connect assigns a unique, randomly generated owner password when it creates the document. The owner password enforces the PDF permission restrictions and is not available to users.
- User password: Brief Connect does not set a user password for opening the document. Users can normally open and view the PDF without entering a password.
Some local PDF applications might still report that the file is password protected, prompt for a password, or refuse to open it. Open the file in the SharePoint PDF viewer if this occurs.
The primary goal of this security model is to preserve the PDF as a point-in-time record by restricting common modification operations. SharePoint and record permissions separately control who can access the file.
Permissions and Restrictions
The following table outlines what users can and cannot do with the secured PDF files:
| Permitted Actions | Restricted Actions |
|---|---|
| ✅ View the document | ❌ Edit or modify document content |
| ✅ Print the document (in full quality) | ❌ Add or edit annotations and comments |
| ❌ Copy or extract text and images | |
| ❌ Fill in interactive form fields | |
| ❌ Assemble the document (insert, delete, or rotate pages) |
Scope of Protection
This security protection is automatically applied to all PDF documents generated by Brief Connect, including:
- On-Demand PDF Packs: When a user generates a PDF pack directly from a record.
- Automated Snapshots: When a workflow transition automatically creates a snapshot of a record.
- Bulk Exported PDF Packs: When multiple records are exported as a single PDF pack.
- Signed Documents: When a document is processed through a signing workflow.
Optional: Watermarking
For additional auditing and tracking, Brief Connect also supports optional watermarking on generated PDFs. When enabled via the WatermarkPDF setting, a watermark is added to each page, typically including the name of the user who generated the document and a timestamp. This feature works alongside the security restrictions.
See Enabling PDF Watermarking for instructions on how to configure this feature.