Most setup guides stop at “upload your files and send the invitations”. That is where the real risk starts. An administrator sees every folder, so a misconfigured permission is invisible from the admin chair. The buyer’s associate sees it at once.
This guide keeps the four setup steps deliberately brief and spends its length on the test that should come between setup and invitation.
Launching a data room: four steps, then a 15-point guest test
Shortlist two rooms, trial both on real files, sign the one your outside parties can use without help.
Number every folder, mirror the request list, park drafts outside the room.
One permission group per outside party, view-only by default, downloads off until asked.
Log in as a dummy guest and work through 15 checks before anyone real is invited.
Access checks
Login, 2FA, NDA gate, group scope, expiry date
Documents checks
Search, previews, watermark, print and download rules, broken files, index numbers
Process checks
Q&A routing, notifications, audit log entry, revoke and restore
What does “functional” mean for a data room?
A functional data room is one where every outside party can find what they are entitled to, cannot reach what they are not, and leaves a record of what they did. Storage alone is not enough; a shared drive stores files too.
Three properties separate the two:
- Scoped access. Each party sees its own slice of the room, set by group, not by hand per file.
- Controlled documents. Watermarks, print and download rules, and the ability to revoke access after a file has been opened.
- A record. An audit trail of logins, views and downloads that you could hand to a lawyer if a dispute arose later.
If your room has all three and an outside reviewer can use it without a call to you, it is functional.
Step 1: How do you pick the platform?
Shortlist two providers, not five. Use the deal type to narrow the field: a company sale needs a structured Q&A module and per-bidder groups, a fundraise needs viewer analytics and speed, a licensing deal needs strong document rights control. Our reviews of every major provider list which of the twelve checklist features each one ships.
Then trial both on real files. A free trial or a demo room with a sample folder tells you almost nothing; upload two hundred of your own documents and invite a colleague as a guest. The platform that your colleague navigates without asking you anything is usually the right one.
Rule of thumb based on provider onboarding documentation and common launch problems.
Settle the commercial terms before you build. Ask what happens at the end of the term: how long the archive is kept, what an export costs, and whether the price changes if the deal runs long. Our pricing guide walks through the models and the questions to ask.
Step 2: How should you structure the index?
Build the folder tree from the request list you expect to receive, not from how your own drive is organized. Number every folder (1 Corporate, 1.1 Constitutional documents, 1.2 Board minutes) so that Q&A questions can reference a location precisely.
Keep three rules:
- No more than three levels deep. Reviewers stop clicking at level four.
- One topic per folder. A folder called “Misc” will be opened by every bidder and answer nobody.
- Drafts stay outside. Upload final, signed or clearly labelled versions only.
| Index choice | Works well when | Causes trouble when |
|---|---|---|
| Numbered by request list | A buyer or investor has sent a list | Requests arrive ad hoc with no list |
| By business function | The company is large with clear departments | Documents span several functions |
| By counterparty phase | Access opens in stages (teaser, phase one, phase two) | Everyone gets the same access at once |
| By entity | Several subsidiaries or assets are in scope | One entity holds almost everything |
Step 3: How do you set permissions without slowing the deal?
Create one group per outside party, plus internal groups for your advisers. Assign permissions to groups, never to individual users, so that a new associate joining a buyer team inherits the right access automatically.
Start strict. View-only, watermarks on, downloads and printing off. Loosen per group only when someone asks and you can name the reason. It is far easier to open a folder later than to explain why a competitor downloaded the customer list.
A detail that catches people
Check what a group sees when a folder is added after the group was created. On some platforms new folders inherit the parent’s permissions; on others they start hidden. Your test in step 4 should include adding a folder after invitations are drafted.
Step 4: What is in the go-live test?
This is the step that most teams skip, and it is the one that matters. Create a dummy guest account in each permission group. Log out of the admin view entirely, log in as the dummy, and work through the list below. Fix anything that fails, then repeat until every check passes.
- 1
Access: five checks
Log in with the guest invitation link; confirm two-factor login is enforced; confirm the NDA or terms screen appears before any document; confirm the guest sees only its group's folders; confirm the access expiry date is set.
- 2
Documents: six checks
Search for a term you know is in a hidden folder and confirm nothing returns; open a PDF, a spreadsheet and a scanned image and confirm each previews; confirm the watermark shows the guest's name and the time; try to print and download and confirm the rules match the group; open any file over 50 MB to check it renders; confirm folder numbers match the index you will send.
- 3
Process: four checks
Submit a test question and confirm it routes to the right internal expert; confirm the notification email arrives and does not leak folder names; confirm the guest's views appear in the audit log; revoke the guest's access, confirm the room closes, then restore it.
- 4
Repeat per group
Run the access and search checks for every permission group, not only the first. Most leaks come from the second or third group created in a hurry.
- 5
Write down the result
Record the date, the groups tested and any fixes. If a dispute ever arises about who could see what, this note and the audit log are your evidence.
The search check deserves emphasis. Search indexes on some platforms are built separately from folder permissions, and a misconfigured index can surface file names, or snippets of text, from folders the guest cannot open. Searching from a guest account is the only reliable way to rule it out.
How long does a launch take?
| Room size | Steps 1 to 3 | Go-live test | Typical first invitation |
|---|---|---|---|
| Under 500 files, one counterparty | Half a day to one day | About one hour | Day 2 |
| 500 to 5,000 files, a few bidders | Two to four days | Two hours | Day 5 |
| 5,000+ files, staged auction | One to two weeks with adviser help | Half a day | Week 2 or 3 |
These are indicative and assume the documents already exist. Gathering missing documents usually takes longer than building the room itself.
What should you do in the first week after launch?
Watch the audit log daily. A bidder that has not logged in by day three may have lost interest or may be struggling with access; either is worth a call. Answer questions within one working day where you can, and publish answers to the whole group when they are not party-specific.
Re-run the search and permission checks whenever you add a group or a large batch of files. The test is not a one-time event; it is a habit.
Not sure which platform to trial first?
Answer five questions about your deal and get three matches from our reviews.
Frequently asked questions
Can I launch a data room myself without an adviser?
Yes. Modern platforms are self-serve, and a single-counterparty room can be live within a day. Advisers help most with the index and the disclosure decisions, not with the software.
How many permission groups should a data room have?
One per outside party plus one per internal adviser team is the usual pattern. A sale with six bidders, a law firm and an accounting firm would typically have eight or nine groups.
Should guests be able to download documents?
Start with downloads off and turn them on per group when there is a reason, such as an accountant who needs to work in a spreadsheet. Watermarking and view-only access cover most review needs.
What is the most common launch mistake?
Testing the room only from the administrator view. Admins see everything, so permission and search errors stay invisible until a guest finds them. Always test from a dummy guest account.
When does billing usually start?
Usually from the day the room is created or the plan is activated, not from the first invitation. Build the room close to when you need it, and check how the provider handles the archive at the end.