Verified recipient access.
Email gates tie activity and permissions to a recipient instead of a shared anonymous session.
See secure sharing →Verified identity, scoped access, revocable links, agreements, watermarking and an exportable audit record, inside the room recipients use.

Each control answers a different question: who is opening, what they can reach, how long the link works and what record remains.
Email gates tie activity and permissions to a recipient instead of a shared anonymous session.
See secure sharing →Give each recipient group only the sections assigned to it, with document-level exceptions where needed.
See permissions →End access on a schedule or immediately, without taking down the room for everyone else.
See link controls →Keep the executed agreement tied to the recipient and the room access it unlocked.
See NDA flow →Render verified identity and viewing time onto sensitive page views.
See watermarking →Keep access, verification, agreement, viewing and download events in one room history.
See the audit layer →Custom access groups define what each audience can reach. A section can be open, gated by NDA, request-only or hidden for one group without changing the rest of the room.

A managed link can expire, revoke, rotate or keep resolving to a replacement file. Each change affects the intended credential without forcing a new room on every other recipient.
Set the access window before the link leaves your hands.
Stop one credential immediately while other links keep working.
Replace the credential when its distribution is no longer trusted.
The public viewer keeps protected manifests and assets out of shared caches, uses short-lived asset delivery and marks private room and document routes for no indexing.
Protected manifests and assets use private, no-store response policy.
Page, image and download redirects are issued with a short validity window rather than permanent public paths.
Viewer routes carry noindex rules, and private rooms are not placed in the public sitemap.
Verification, access requests, NDA signatures, document views, downloads and revocation changes remain inspectable in the room. Export the audit record when legal or procurement needs the evidence outside RoundOS.

No. Private room and document routes carry noindex rules and are excluded from the public sitemap.
That credential stops opening the room. Other recipient links remain active unless you change them separately.
No. When email verification is required, a new viewer must verify their own identity before gated material opens.
No. It makes the captured page attributable to a verified recipient and time instead of claiming an impossible screenshot lock.
Yes. The room audit record can be exported for review outside RoundOS.

Identity, scope, expiry and accountability stay part of one recipient path.