Skip to content
NewTop 10 AI-powered data rooms for October 2026 Read the list
Security and control

Dynamic Watermarking and Granular Access Controls in Data Rooms

Dynamic watermarks deter leaks; granular permissions prevent them. A practical guide to both, with a setup sequence and the questions to put to any data room vendor.

By Top Data Rooms editorsPublished 8 min read
Summarize this article

A dynamic watermark is an overlay a data room adds to a document each time someone opens, prints or downloads it, carrying details that identify that specific viewer. Granular access controls are the settings that decide, folder by folder and file by file, what each user or group is allowed to do.

The two work as a pair. Permissions keep documents away from the wrong people. Watermarks make sure that anyone who does see a document knows it can be traced back to them. One is a lock; the other is a camera above the door.

How does a dynamic watermark work?

The word “dynamic” is the important part. A static watermark is baked into the file once, usually as “Confidential” across the page. Everyone sees the same mark, so a leaked copy tells you nothing about who leaked it.

A dynamic watermark is generated per view. When a bidder’s associate opens the customer contracts at 22:14 on a Tuesday, the room renders the page with their name, email address, IP address or timestamp, depending on what the admin configured. When their colleague opens the same file a minute later, the mark is different.

What happens when a watermarked file is opened

1

Request

A signed-in user clicks a document in a folder they are allowed to see.

2

Permission check

The room confirms their group may view, print or download this file.

3

Stamp

The watermark is drawn with that user details and the current time.

4

Log

The view, and any print or download, is written to the audit trail.

The watermark and the audit log record the same event, so a leaked page can be matched to a person and a moment.
topdatarooms.net
Generic sequence. Exact fields and behaviour vary by vendor; ask for a demo of the watermark settings.

Good watermark settings to look for:

  • Choice of fields. Name, email, company, IP address, date and time.
  • Placement and opacity. Diagonal across the page is harder to crop out than a footer line.
  • Applies to every output. On-screen viewing, printing and downloaded copies should all carry the mark.
  • Per-folder rules. Heavy marks on financial and HR folders, lighter ones on public material.

What does “granular” access control actually mean?

It means the room lets you set permissions at a fine level along three dimensions: who (individual users or groups), where (the whole room, a folder, a single file) and what (the action allowed).

Here is the ladder of actions most data rooms offer, from most to least restrictive:

Permission levelWhat the user can doTypical use
No accessFolder is invisible to themClean team material, other bidders’ Q&A
Restricted viewOn-screen viewing only, often with copy and screenshot deterrentsPricing, customer contracts, key IP
ViewOpen and read in the browser viewerMost diligence material in early rounds
View and printPrint watermarked copiesLegal advisers reviewing long agreements
Download (protected)Download a copy that stays under document rights controlFinal-round bidders and their counsel
Download (original)Download the file without controlsSeller’s own team and trusted advisers
Upload or editAdd or replace documentsSeller deal team, data room admins

Not every vendor names these levels the same way, and some combine them. The test is simple: can you give one group “view only” on a folder while another group can download it, and can you change that in seconds when a bidder drops out?

Which data rooms list these controls?

Watermarking is now table stakes. Document rights, redaction, two-factor login and single sign-on are where the field splits. The counts below come straight from our facts file and update when it changes.

How many of the 18 tracked providers list each control

Dynamic watermarking 18 of 18

Ansarada, Box, CapLinked, Citrix ShareFile, Datasite, DealRoom, Digify, DocSend, Drooms, Ellty, Firmex, iDeals, Intralinks, Onehub, SecureDocs, ShareVault, SmartRoom, Venue by DFIN

Document rights (view, print, download) 15 of 18

Ansarada, CapLinked, Citrix ShareFile, Datasite, DealRoom, Digify, Drooms, Ellty, Firmex, iDeals, Intralinks, SecureDocs, ShareVault, SmartRoom, Venue by DFIN

Two-step login 14 of 18

Ansarada, Box, CapLinked, Citrix ShareFile, Datasite, DealRoom, Drooms, Ellty, Firmex, iDeals, Intralinks, Onehub, SecureDocs, SmartRoom

Redaction 7 of 18

Datasite, Drooms, Firmex, iDeals, Intralinks, SmartRoom, Venue by DFIN

Single sign-on 7 of 18

Ansarada, Box, Citrix ShareFile, Datasite, iDeals, Intralinks, ShareVault

Watermarks are universal. Document rights, redaction and SSO are what separate a deal-grade room from a file share.
topdatarooms.net
Source: Top Data Rooms facts file, features field. A missing listing means not listed, not necessarily unavailable; ask the vendor.

A few things stand out. Box, Onehub and DocSend list watermarks but not document rights in our facts, which fits their roots in general file sharing and document tracking. Redaction is listed by only seven providers, mostly the long-established M&A rooms. Ellty lists watermarking, document rights and two-factor login but not native redaction or single sign-on, so teams that need either should plan for it.

For a side-by-side of every checklist item, the feature checker lets you filter all 18 providers.

How should you design permission groups?

Start with people, not folders. List every party that will touch the room, then group them by what they need to see.

A typical sell-side auction might end up with these groups:

GroupSeesRightsWatermark
Seller deal teamEverythingUpload, download originalLight
Seller advisersEverything except board minutes on the saleDownload protectedFull
Bidder A, B, C (one group each)Phase 1 foldersView onlyFull, with IP
Bidder A counselPhase 1 plus legal folderView and printFull
Clean teamPricing and customer foldersRestricted viewFull, with timestamp
Final bidderPhase 2 foldersDownload protectedFull

Notice that bidders sit in separate groups. That lets you open a folder to one bidder without touching the others, and it keeps each bidder’s Q&A private.

How to set up watermarks and permissions before go-live

  1. 1
    Map the parties

    List every organisation and role that needs access, including advisers on both sides and any clean team.

  2. 2
    Create groups, not individual rules

    Build one permission group per role or bidder. Individual exceptions become impossible to audit later.

  3. 3
    Build the folder index

    Structure folders by sensitivity as well as by topic, so that the most sensitive material sits in folders you can lock as a block.

  4. 4
    Set rights per folder and group

    Assign view, print or download at folder level. Default to the most restrictive level and open up deliberately.

  5. 5
    Configure watermarks

    Choose the fields (name, email, time, IP) and apply them to viewing, printing and downloads. Use heavier marks on sensitive folders.

  6. 6
    Check as a test user

    Use the room preview or a dummy account in each group to confirm what that group actually sees before inviting anyone.

  7. 7
    Turn on two-factor login

    Require it for every external user, and enable single sign-on for internal users where the vendor supports it.

Where do audit trails fit in?

Audit trails close the loop. Every provider we track lists one, and they matter for two reasons.

The first is evidence. If a page does leak, the watermark tells you whose copy it was, and the audit trail tells you when they opened it, what else they looked at and whether they printed or downloaded it.

The second is insight. Activity reports show which bidders are reading the financial model and which have not opened the room in a week. Sell-side advisers use that to judge interest long before indicative bids arrive.

Ask whether audit logs can be exported, how long they are retained after the room closes, and whether they record permission changes as well as document views. That last point is easy to miss; you want a record of who opened a folder to whom.

What mistakes undo good access controls?

Most leaks in a well-configured room come from process, not software.

  • Granting download “just for now”. Temporary rights tend to become permanent. Set a calendar reminder or use an expiry date if the room supports one.
  • Shared logins. One login for a whole bidder team destroys the value of watermarks and audit logs. Insist on named users.
  • Uploading originals with hidden data. Track changes, comments and spreadsheet tabs survive upload. Clean files first, or use redaction where the vendor offers it.
  • Forgetting to revoke. When a bidder drops out, remove the group the same day. Our most secure list gives weight to the controls that make this quick.
Related top list Top 10 most secure virtual data rooms Ranked mostly on data protection, with extra credit for ISO 27001, HIPAA, redaction and document rights control. 1Ellty2iDeals3Datasite See the full list →

How do you compare vendors on control?

Ask each vendor on your shortlist to show, in a demo, the exact flow above: create a group, set view only on a folder, apply a watermark, open a file as that user, then show the audit entry. It takes ten minutes and reveals more than any feature sheet. Our ranking method explains how we weigh these protections against usability and cost.

Frequently asked questions

What is dynamic watermarking in a data room?

It is a watermark generated each time a document is viewed, printed or downloaded, showing details of that specific user such as name, email, IP address and time. Because each copy is unique, a leaked page can be traced to the person who opened it.

Can a watermark stop someone from leaking a document?

No. It deters leaks by making them traceable. Prevention comes from permissions: view-only access, restricted download rights and removing access promptly when it is no longer needed.

What is the difference between watermarking and document rights management?

Watermarking marks a document with the viewer identity. Document rights management controls what the viewer can do with it, such as whether they can print or download, and in some rooms whether a downloaded copy can be opened later.

Do all virtual data rooms offer granular permissions?

Most deal-focused rooms do, but the level of detail varies. Check whether you can set rights per folder and per file, for groups rather than only individuals, and whether changes take effect immediately.

Should every external user have two-factor login?

Yes, as a sensible default. Of the 18 providers we track, 14 list two-factor login. If a vendor does not list it, ask how it protects accounts against stolen passwords.