Offer letters, compensation side letters, background-check packets, and payroll exports are not “just PDFs.” They are employee PII and employment terms that get forwarded to personal Gmail, screenshotted into group chats, and left in shared Drive folders after the hire closes.
This playbook shows how HR and People Ops can share sensitive employment documents with sealed links—without turning email or a forever folder into the HR data room. It is not a repeat of our accountant/counsel or agency client-room guides; the audience and risk pattern are different.
What goes wrong with common HR sharing habits
1. Offer PDFs as email attachments
Attachments clone into every recipient mailbox, phone, and backup. You cannot revoke an attachment. Pattern and fix: stop emailing sensitive attachments.
2. “HR shared Drive” that never expires
A shared folder for “this quarter’s hires” becomes a standing dump of offers, IDs, and payroll CSVs. When a recruiter leaves, access cleanup is manual and late. Pair sealed packets with offboarding revoke habits—including internal role changes.
3. Chat uploads for “quick sends”
WhatsApp, iMessage, and Slack are where urgency wins. They are not document vaults. Keep coordination in chat; keep the file in a sealed link (messaging ≠ vault, Slack/Teams ≠ vault).
4. Password-protected ZIP theater
Zipping a payroll export and putting the password in the next message adds friction without a clean revoke story. See ZIP vs encrypted vault.
Which HR packets belong in a sealed vault
- Offer letters and compensation exhibits
- Signed employment agreements and amendment packets
- Identity / right-to-work scans when you must send them outside the HRIS
- Payroll or benefits extracts shared with brokers or auditors
- Investigation or performance packets with a defined review window
Keep low-sensitivity logistics (interview scheduling, public job posts) in email and the ATS. Escalate when a leak would harm a person or the company.
A converting HR sealed-share workflow
- Finalize the packet in your HRIS or internal drive—do not co-author inside the outbound share.
- Upload into a zero-knowledge vault so encryption happens in the browser before the bytes leave the device.
- Create a sealed link with a short expiry (often 48–72 hours for offers; shorter for identity scans). Policy ideas: share expiry for security teams.
- Send the link from your ATS or email. Optionally require a share password delivered out of band—not in the same SMS as the link.
- Revoke on accept, decline, or no-show. Do not leave candidate PII openable “just in case.”
What Compliance Locker changes for People Ops
Compliance Locker gives HR a sealed packet lane: client-side encryption, expiring links, revoke, and activity when someone asks who opened the offer file. It does not replace your HRIS or legal review. Start on pricing or read security.