A dynamic watermark is an overlay a data room adds to a document each time someone opens, prints or downloads it, carrying details that identify that specific viewer. Granular access controls are the settings that decide, folder by folder and file by file, what each user or group is allowed to do.
The two work as a pair. Permissions keep documents away from the wrong people. Watermarks make sure that anyone who does see a document knows it can be traced back to them. One is a lock; the other is a camera above the door.
How does a dynamic watermark work?
The word “dynamic” is the important part. A static watermark is baked into the file once, usually as “Confidential” across the page. Everyone sees the same mark, so a leaked copy tells you nothing about who leaked it.
A dynamic watermark is generated per view. When a bidder’s associate opens the customer contracts at 22:14 on a Tuesday, the room renders the page with their name, email address, IP address or timestamp, depending on what the admin configured. When their colleague opens the same file a minute later, the mark is different.
What happens when a watermarked file is opened
Request
A signed-in user clicks a document in a folder they are allowed to see.
Permission check
The room confirms their group may view, print or download this file.
Stamp
The watermark is drawn with that user details and the current time.
Log
The view, and any print or download, is written to the audit trail.
Good watermark settings to look for:
- Choice of fields. Name, email, company, IP address, date and time.
- Placement and opacity. Diagonal across the page is harder to crop out than a footer line.
- Applies to every output. On-screen viewing, printing and downloaded copies should all carry the mark.
- Per-folder rules. Heavy marks on financial and HR folders, lighter ones on public material.
What does “granular” access control actually mean?
It means the room lets you set permissions at a fine level along three dimensions: who (individual users or groups), where (the whole room, a folder, a single file) and what (the action allowed).
Here is the ladder of actions most data rooms offer, from most to least restrictive:
| Permission level | What the user can do | Typical use |
|---|---|---|
| No access | Folder is invisible to them | Clean team material, other bidders’ Q&A |
| Restricted view | On-screen viewing only, often with copy and screenshot deterrents | Pricing, customer contracts, key IP |
| View | Open and read in the browser viewer | Most diligence material in early rounds |
| View and print | Print watermarked copies | Legal advisers reviewing long agreements |
| Download (protected) | Download a copy that stays under document rights control | Final-round bidders and their counsel |
| Download (original) | Download the file without controls | Seller’s own team and trusted advisers |
| Upload or edit | Add or replace documents | Seller deal team, data room admins |
Not every vendor names these levels the same way, and some combine them. The test is simple: can you give one group “view only” on a folder while another group can download it, and can you change that in seconds when a bidder drops out?
Which data rooms list these controls?
Watermarking is now table stakes. Document rights, redaction, two-factor login and single sign-on are where the field splits. The counts below come straight from our facts file and update when it changes.
How many of the 18 tracked providers list each control
Ansarada, Box, CapLinked, Citrix ShareFile, Datasite, DealRoom, Digify, DocSend, Drooms, Ellty, Firmex, iDeals, Intralinks, Onehub, SecureDocs, ShareVault, SmartRoom, Venue by DFIN
Ansarada, CapLinked, Citrix ShareFile, Datasite, DealRoom, Digify, Drooms, Ellty, Firmex, iDeals, Intralinks, SecureDocs, ShareVault, SmartRoom, Venue by DFIN
Ansarada, Box, CapLinked, Citrix ShareFile, Datasite, DealRoom, Drooms, Ellty, Firmex, iDeals, Intralinks, Onehub, SecureDocs, SmartRoom
Datasite, Drooms, Firmex, iDeals, Intralinks, SmartRoom, Venue by DFIN
Ansarada, Box, Citrix ShareFile, Datasite, iDeals, Intralinks, ShareVault
A few things stand out. Box, Onehub and DocSend list watermarks but not document rights in our facts, which fits their roots in general file sharing and document tracking. Redaction is listed by only seven providers, mostly the long-established M&A rooms. Ellty lists watermarking, document rights and two-factor login but not native redaction or single sign-on, so teams that need either should plan for it.
For a side-by-side of every checklist item, the feature checker lets you filter all 18 providers.
How should you design permission groups?
Start with people, not folders. List every party that will touch the room, then group them by what they need to see.
A typical sell-side auction might end up with these groups:
| Group | Sees | Rights | Watermark |
|---|---|---|---|
| Seller deal team | Everything | Upload, download original | Light |
| Seller advisers | Everything except board minutes on the sale | Download protected | Full |
| Bidder A, B, C (one group each) | Phase 1 folders | View only | Full, with IP |
| Bidder A counsel | Phase 1 plus legal folder | View and print | Full |
| Clean team | Pricing and customer folders | Restricted view | Full, with timestamp |
| Final bidder | Phase 2 folders | Download protected | Full |
Notice that bidders sit in separate groups. That lets you open a folder to one bidder without touching the others, and it keeps each bidder’s Q&A private.
How to set up watermarks and permissions before go-live
- 1Map the parties
List every organisation and role that needs access, including advisers on both sides and any clean team.
- 2Create groups, not individual rules
Build one permission group per role or bidder. Individual exceptions become impossible to audit later.
- 3Build the folder index
Structure folders by sensitivity as well as by topic, so that the most sensitive material sits in folders you can lock as a block.
- 4Set rights per folder and group
Assign view, print or download at folder level. Default to the most restrictive level and open up deliberately.
- 5Configure watermarks
Choose the fields (name, email, time, IP) and apply them to viewing, printing and downloads. Use heavier marks on sensitive folders.
- 6Check as a test user
Use the room preview or a dummy account in each group to confirm what that group actually sees before inviting anyone.
- 7Turn on two-factor login
Require it for every external user, and enable single sign-on for internal users where the vendor supports it.
Where do audit trails fit in?
Audit trails close the loop. Every provider we track lists one, and they matter for two reasons.
The first is evidence. If a page does leak, the watermark tells you whose copy it was, and the audit trail tells you when they opened it, what else they looked at and whether they printed or downloaded it.
The second is insight. Activity reports show which bidders are reading the financial model and which have not opened the room in a week. Sell-side advisers use that to judge interest long before indicative bids arrive.
Ask whether audit logs can be exported, how long they are retained after the room closes, and whether they record permission changes as well as document views. That last point is easy to miss; you want a record of who opened a folder to whom.
What mistakes undo good access controls?
Most leaks in a well-configured room come from process, not software.
- Granting download “just for now”. Temporary rights tend to become permanent. Set a calendar reminder or use an expiry date if the room supports one.
- Shared logins. One login for a whole bidder team destroys the value of watermarks and audit logs. Insist on named users.
- Uploading originals with hidden data. Track changes, comments and spreadsheet tabs survive upload. Clean files first, or use redaction where the vendor offers it.
- Forgetting to revoke. When a bidder drops out, remove the group the same day. Our most secure list gives weight to the controls that make this quick.
How do you compare vendors on control?
Ask each vendor on your shortlist to show, in a demo, the exact flow above: create a group, set view only on a folder, apply a watermark, open a file as that user, then show the audit entry. It takes ten minutes and reveals more than any feature sheet. Our ranking method explains how we weigh these protections against usability and cost.
Frequently asked questions
What is dynamic watermarking in a data room?
It is a watermark generated each time a document is viewed, printed or downloaded, showing details of that specific user such as name, email, IP address and time. Because each copy is unique, a leaked page can be traced to the person who opened it.
Can a watermark stop someone from leaking a document?
No. It deters leaks by making them traceable. Prevention comes from permissions: view-only access, restricted download rights and removing access promptly when it is no longer needed.
What is the difference between watermarking and document rights management?
Watermarking marks a document with the viewer identity. Document rights management controls what the viewer can do with it, such as whether they can print or download, and in some rooms whether a downloaded copy can be opened later.
Do all virtual data rooms offer granular permissions?
Most deal-focused rooms do, but the level of detail varies. Check whether you can set rights per folder and per file, for groups rather than only individuals, and whether changes take effect immediately.
Should every external user have two-factor login?
Yes, as a sensible default. Of the 18 providers we track, 14 list two-factor login. If a vendor does not list it, ask how it protects accounts against stolen passwords.