Access, sharing, and sign in for Evidence Hub

Evidence Hub controls secure access, sharing, and sign-in. Users can discover records, request access, and share deep links based on permissions. Diligent One users sign in with Diligent One Platform credentials, while non-Diligent One users authenticate using email one-time passcodes.

Requesting access to a record

Request access to open the full contents of a discoverable record, or to obtain submitted responses or attached evidence.

  1. Open the record from search, list view, or a deep link.

  2. Select Request Access.

  3. Wait for the owner to approve or decline the request.

After approval, the user can open the record and is typically granted read-only access. Download still depends on the record's download rules.

Tip

If access is granted but Downloadable is off, expect preview-only access to files.

Troubleshooting access outcomes

What the user sees Likely cause What to check next
Record appears in list, but content is blocked Discover allowed, read not allowed Request access from owner, then verify record-level role.
Access denied panel (for Admins only) No read permission for that record Confirm record assignment, then label restrictions.
File preview works, but download is blocked Read allowed, download blocked Check Downloadable and downloadable label mapping.
Order Check
1 Confirm app-level role.
2 Confirm record-level assignment.
3 Confirm record-level and label-level configuration, including discoverable and downloadable settings, record status, and any label restrictions.

Deep links and shared links

A deep link is the stable URL for an Evidence Record. Owners can share the link with users who already have access.

Who can open a deep link

A user who already has access can open the record through the link after authentication. A user without access might be taken to the list view to request access when the record is discoverable, or see an access denied message when they are not allowed to open it.

When a user selects a deep link, Evidence Hub asks for the email address the request was sent to, then routes the user by identity.

  • If the email matches an assigned Diligent One user, the user continues to platform sign-in and, after authentication, reaches the records they can access.

  • If the email matches an assigned non-Diligent One user, Evidence Hub sends a one-time passcode (OTP) to that address. After the user enters the code, the list view opens showing the records they can access, and the linked record opens according to their access.

  • If the entered email does not match the assigned address, Evidence Hub displays You are not authorized to access this link.

Troubleshooting deep link access

Scenario What happens
Internal user opens a link assigned to a different user Access is denied regardless of the user's role.
External user enters the wrong email address Access is denied even if the user has other records.
User has discover-only access to the record Metadata-only view is shown with an option to request access.
Record has been deleted after the link was shared The user sees a message indicating the record is inactive or removed.
User is authenticated but has no assignment or discover access Access is denied. Contact the record owner to request an assignment.

Warning

Copying a deep link does not bypass permissions. Authentication, record-level access, and discoverability and downloadability rules still apply.

Signing in as an Diligent One user

Internal users sign in with Diligent One Platform authentication. This applies to owners, respondents, reviewers, and viewers who have platform accounts.

Opening a record from the portal

  1. From the Platform home page (www.diligentoneplatform.com), select the Evidence Hub app to open it.If you are already in Diligent One, you can use the left-hand navigation menu to switch to the Evidence Hub app.

  2. Open the record from the list view or a deep link.

Opening a record from an email link

  1. Open the link in the email.

  2. Sign in with your platform credentials if you are not already signed in.

  3. Continue to the assigned record if the link belongs to you.

When an owner sends a record to an internal Diligent One recipient, the recipient receives an email link.

  • If the recipient is signed in and assigned to the record, the link opens the record in the view for their role. A viewer opens it read-only.

  • If the recipient is not signed in, the link goes to platform sign-in first, then opens the assigned record.

  • If a signed-in internal user who is not assigned to the record opens the link, Evidence Hub displays You are not authorized to access this link.

Tip

An internal link is assignment-aware. If the signed-in user is not the intended person, access is denied.

Signing in as a non-Diligent One user

Non-Diligent One users sign in with email one-time passcode (OTP) authentication. This applies to non-Diligent One respondents, non-Diligent One alternate respondents, and non-Diligent One viewers when they are allowed.

Completing the email OTP flow

  1. Open the link in the email invitation or notification.

  2. Enter the email address where you received the request.

  3. Wait for the OTP code to arrive by email.

  4. Enter the OTP code.

  5. After verification succeeds, the list view opens showing every record you can access, and you open the record you need from there.

Note

A non-Diligent One user who reaches a deep link and is already registered sees the full list of records they have access to, not only the linked record. If the entered email is not a registered assigned address, Evidence Hub shows an authorization error.

OTP expiry and retry rules

  • The code is valid for 15 minutes.

  • The code is single-use.

  • To get another code, use the link again.

  • After three unsuccessful OTP attempts, Evidence Hub blocks the email address and the originating IP address from the link for one hour.

Note

OTP verification grants session-based access, but record-level permissions still determine what the user can do after sign in.

Blocked or unauthorized access

Users can be blocked from access in the following situations.

Situation Expected result
Correct internal user opens an assigned link Record opens after sign in, if needed.
Wrong internal user opens an assigned link Access is denied.
Correct external user enters the assigned email and OTP Record opens after verification.
External user enters the wrong email Access is denied.
OTP is expired or already used A new code is required.

Warning

Secure access is intentionally strict. Links are not transferable, and OTP or sign-in success does not override assignment or record permissions.