How to Share Videos Securely With Clients So Links Stop Getting Forwarded
Most advice on sharing client videos securely focuses on the wrong thing. Here is how I stop draft cuts travelling past the approval team, using passwords, revoking and who-watched data.
Client video review links are, to be very honest, guarded against the wrong enemy in most advice on how to share videos securely with clients, right, because it treats a leak like somebody breaking in from outside. In my agency the leak has basically always been the lovely client contact who likes the cut so much that they forward the link to their manager, the partner brand and sometimes a friend whose taste they trust.
So you read guide after guide telling you to pick a platform with encryption, set a strong password and call it a day, and I'm not against any of that. The catch here is that a password only protects a link until the client pastes it into the same email thread they forward, right, and then your unreleased campaign cut is sitting in inboxes you've never heard of, three weeks before launch.
In this post I want to walk through how I actually handle a client forwarded video link, from inside a video editing agency and a personal branding agency where unreleased cuts go out every single day. It comes down to a few layers stacked on each other, starting with a password that never travels with the link and ending with a revoke button we press without feeling guilty about it.
Why client review links get forwarded
The first thing I had to accept is that the client contact who receives your link is very rarely the person who actually approves the video, right. They're usually a brand manager or a marketing coordinator in the middle of a chain, and their job that day is to get the cut in front of the people above and around them as fast as possible. So when they forward your link they're just doing their job with the tool you handed them, and a review link that opens in a browser with no account and no install is basically designed to be passed along.
I don't want to fix this by adding friction either, because the whole reason clients comment without an account in PlayPause is that every login screen adds another day to the round. The real fix starts earlier, in the brief, where the approval team gets named before a single frame is cut. If you've never written that into your creative brief, add one line for it, right, who reviews, who approves and who only needs to see the final.
I've written about the client approval stages in video production, and links get forwarded most at the stages where the contact isn't sure they're allowed to decide alone, so when you ask the right questions at every review stage, including the dull one about who else needs to see this, you find out who the extra viewers will be before they turn up uninvited.
The real risk of an unreleased cut travelling
I'm pretty sure most producers underestimate what goes wrong when a draft travels, because they picture the video ending up on the internet, and the far more common damage is quieter, right. A rough cut with placeholder music and an unapproved claim lands with a partner brand, somebody there forms an opinion of your work from a version you'd never have shown them, and now your agency's name sits on a draft that was never meant to leave the room.
Then there's the feedback problem, which in my experience hurts more than the leak itself. Once a link is loose you get notes from people outside the approval chain, a regional head who wants a different product shot, a sales lead who wants the price bigger, and so on, and every note looks as official as the real approver's. With teams spread across cities the way remote work has made normal, a link dropped into a busy team chat can collect a whole pile of opinions overnight.
Unreleased cuts usually travel because a helpful client contact passes the link along, so plan your sharing around that person rather than an imaginary hacker.
And at the end of the day there's the launch itself, because an ad your client's own customers see three weeks early and half finished is a very very expensive mistake for a campaign planned around a reveal.
Password protected links for sensitive cuts
So the first layer is simple and every PlayPause plan has it, which is password-protected links, and I use them for anything that hasn't launched yet, right, campaign cuts, product reveals, anything with a name or a number on screen that isn't public. The client still opens the link in a browser with no account, watching a streaming copy while your original file stays untouched in the workspace, and the only change for them is one extra field for the password. I honestly can't remember a client pushing back on it, because it quietly tells them you take their unreleased material seriously.
The catch here is how you send the password, and this is the bit most guides skip. The habit I drill into my producers is link by email and password through a different channel, WhatsApp or a call, so that forwarding the email alone forwards a door without a key. It sounds like a small thing, but trust me on any level, a password that arrives in the same email as the link is just decoration.
I've laid out the exact clicks in password protecting a review link, and if you run an ad agency with several brands in flight, our page on password-protected links for ad agencies is written for exactly that situation.
Spotting unexpected viewers
A password slows a forward down, but it can't stop somebody who holds both pieces from passing them on, which is why the second layer matters so much, right. PlayPause has who-watched analytics that show you who watched, when they watched and which city they watched from, so when a link travels you usually find out from the data long before you find out from an awkward email.
For instance, say you sent the first cut to three people at a client's office in Mumbai, and the next morning the analytics show two views from Mumbai and one from the city where their distribution partner sits, right, that's your signal the link has moved. Or a name you've never seen appears in the comment thread with a note about the logo, and if you send every comment to a Slack channel you'll spot that name the moment it posts, you see what I mean here.
Most forwards are well meant, so I never answer one with an angry email, and you can see how these controls sit together on our sharing and security page. That visibility is also really really useful when you later need to show what was watched and approved, which I covered in how agencies prove client approval.
A password slows a forward down, but only knowing who watched tells you the link has already travelled.
Revoking a video review link instantly
The third layer is the one that actually ends the problem, and that's instant link revoking, which again every plan has, right. You open the share settings, revoke the link, and from that second anyone clicking the old URL gets nothing, whether it's in a partner's inbox or a team chat you'll never see. The project, the versions and the notes stay exactly where they were in your workspace, and you send a fresh link only to the people who should have it.
If you're wondering how to revoke video share link access without making the client feel punished, I frame it as purely operational, something like we've tightened access on this cut before launch, here's your new link and password. Clients take that well because the new link lands within a minute and nobody on the approval team loses a day.
I also revoke on a schedule, so when a stage closes, say the first cut is approved and we move to MV2, the old link gets revoked and the new version goes out on a fresh link, right, because a link that stays live after its job is done is only waiting for somebody to dig it out of an old thread. The same logic applies when people leave the client's team or yours, which is its own topic in revoking access when someone leaves.
A drive link that stays live in every inbox it ever touched
One click revokes the link and a fresh one goes only to the approval team
Setting link lifetimes by project
The quiet layer, and the one people forget, is how long a link lives by default, because a link that expires on its own protects you on the days you forget to revoke it, right. On PlayPause the share link lifetime depends on your plan, so on Creator links last 30 days and the files expire, on Agency links last 90 days, and on Enterprise links never expire. I'd pick based on the projects you actually run rather than only the price.
For a creator or a small team turning around short-form cuts every week, 30 days is honestly plenty, because nobody should be reviewing a reel a month after it went live, and the expiry does your cleanup for you. For an agency running campaigns where legal review alone can take weeks, 90 days fits much better, because you don't want a link dying in the middle of a slow approval. There's more on how expiry works on our expiring share links page.
Enterprise is a slightly different conversation, because links that never expire suit brands using the workspace as a long-term library, which means revoking at the end of every stage becomes your main control. Enterprise also adds a custom share domain like review.yourbrand.com and white-label, and SAML single sign-on for your team is coming in February 2027 and isn't available yet.
A secure client video sharing policy clients will actually follow
All of these controls work much better when the client knows the rules before the first link arrives, so we put a short sharing policy into kickoff, right. The heart of it is one sentence we say on the kickoff call, that each link is for the named approvers, and if anyone else needs to see the cut the client just tells us and we send that person their own link. Clients actually like this, because it saves them the awkwardness of asking permission.
The reason that sentence matters so much is that separate links mean separate passwords, separate lines in the who-watched analytics and the option to revoke one person's access without touching anybody else's, does that make sense, right. On Agency and above we also write the policy into the client's brand playbook in PlayPause, and since a playbook can be shared as a no-login page, the client's own team can read the rules without us repeating them every project.
What one campaign send looks like in practice
Take a fairly typical job in my agency, a 30-second launch spot where the brief names three approvers on the client side, say the brand manager, their marketing head and somebody from legal. MV1 goes into the client project, we create one password-protected link for those three people, the link goes out by email and the password goes on WhatsApp, and the next morning the producer checks who watched and from which cities. If their sales head turns up wanting a look, they get their own link with their own password rather than riding on the brand manager's, right. When MV1 is signed off we revoke that link, stack MV2 on the same card and send a fresh link to the same people, so by launch day there's one live link and we know everyone who ever opened the cut.
For in-house teams the same idea scales, and our piece on an in-house video team workflow shows where review links sit between intake and approval, because the simplest way to restrict video access is to make forwarding unnecessary.
- Name the approvers in the creative brief
- Password protect every unreleased cut
- Send passwords on a separate channel
- Give extra viewers their own link
- Check who watched after every send
- Revoke old links when a stage closes
Frequently asked questions
Can I stop a client from forwarding a video review link?
To be very honest, no tool can stop somebody copying a URL and pasting it into an email, and anyone promising that is overselling, right. What you can do is make the forward useless without the password, see who opened it through who-watched analytics, and revoke the link the moment it travels. Then you reissue a fresh one to the approval team, which gives you most of the protection an unreleased cut actually needs.
Do clients need an account to open a password protected link?
No, and that's the whole point of how we built it. The client opens one link in any browser, types the password you sent separately, and then comments on the exact frame, draws on the frame if they want, and replies in threads, all without creating an account or installing anything. The password is the only extra step, so you keep the protection without slowing the round down.
How long do PlayPause share links stay live?
On Creator, share links last 30 days and the files expire, on Agency they last 90 days, and on Enterprise they never expire, so there you lean on revoking instead. Every plan lets you revoke a link instantly whenever you like, so the lifetime is really a safety net for the days you forget.
What should I do when an unexpected viewer shows up in the analytics?
Don't panic and don't accuse anyone, because most forwards are well meant. I ask the client contact a friendly question about who else is reviewing, then either bring that person into the approval team with their own link and password, or revoke the old link and send a fresh one to the named approvers. Either way the cut stays under your control and the relationship stays intact.
If forwarded links have been keeping you up before a launch, have a look at the plans on our pricing page, because every one of them includes password-protected links, instant revoking and who-watched analytics, and you can run your next unreleased cut through the 7-day free trial before you decide anything.
So yeah. That's my way of saying it.
Saumyajit co-founded PlayPause after years watching review and approval quietly eat creative teams' deadlines. He writes about the workflow side of video, feedback, versioning, and getting to a clean sign-off.
Related resources
Keep reading
Bring your team into one review space
Centralize feedback, lock approvals, and deliver faster, start free today.
Sign Up for Free