Attachments: Share the Right File Without Sharing Too Much
Question: How can a service team attach documents or images to an operational record without accidentally exposing private or irrelevant information?
Decide whether a file is needed
Before uploading, ask three questions:
- What decision or action will this file support?
- Which record should own it — lead, customer, job, estimate, invoice, task, or work order?
- Can the same point be recorded safely as a short note instead?
A file should add evidence or clarity. It should not become a shortcut for sharing a full screen, a customer list, a private message thread, or confidential paperwork.
The pre-upload review
Open the file and inspect the whole visible area, not only the part you intend to reference. Remove or redact:
- names, phone numbers, email addresses, home addresses, GPS or map detail;
- job, invoice, account, tenant, client, or tracking identifiers;
- prices, balances, payment data, signatures, or bank information;
- passwords, tokens, API keys, access codes, internal URLs, or browser tabs;
- private photos, unrelated people, and unsupported performance claims.
If you cannot make the file safe with a clear crop or redaction, do not upload it. Write a generic explanation and ask the authorized owner to use the approved secure channel.
Attach with useful context
Every approved attachment needs a short explanation:
- what it depicts or contains;
- which record or stage it belongs to;
- what the reviewer should verify;
- who owns the next action; and
- whether it is an example, a template, or a verified record.
Example: “Generic equipment-condition reference image; technician to verify the actual condition on site.” This is safer than treating the image as proof of a completed inspection.
A simple naming pattern
Use names that describe the function, not the customer:
“service-photo-reference-before-review”
“generic-maintenance-checklist-template”
“approved-work-order-layout-example”
Avoid names that contain customer names, addresses, personal initials, invoice numbers, or internal project codes.
What to do after upload
- Open the attachment as a viewer would.
- Check the rendered crop, filename, and surrounding record.
- Verify the attachment is linked to the intended item.
- Add or update the next action.
- Remove the attachment through the approved process if you find sensitive information.
For record history, see Audit Log: Review Changes Before You Rely on Them. For internal handoffs, see Internal Handoffs: Keep Team Chat Useful and Safe.
Boundaries
This checklist reduces obvious sharing risks; it does not guarantee complete redaction, access control, file retention, legal compliance, authorization, or that a file is valid evidence. Follow your organization’s approved privacy, security, and retention process.