Attachments: Share the Right File Without Sharing Too Much

Attachments: Share the Right File Without Sharing Too Much

Question: How can a service team attach documents or images to an operational record without accidentally exposing private or irrelevant information?

Decide whether a file is needed

Before uploading, ask three questions:

  1. What decision or action will this file support?
  2. Which record should own it — lead, customer, job, estimate, invoice, task, or work order?
  3. Can the same point be recorded safely as a short note instead?

A file should add evidence or clarity. It should not become a shortcut for sharing a full screen, a customer list, a private message thread, or confidential paperwork.

The pre-upload review

Open the file and inspect the whole visible area, not only the part you intend to reference. Remove or redact:

  • names, phone numbers, email addresses, home addresses, GPS or map detail;
  • job, invoice, account, tenant, client, or tracking identifiers;
  • prices, balances, payment data, signatures, or bank information;
  • passwords, tokens, API keys, access codes, internal URLs, or browser tabs;
  • private photos, unrelated people, and unsupported performance claims.

If you cannot make the file safe with a clear crop or redaction, do not upload it. Write a generic explanation and ask the authorized owner to use the approved secure channel.

Attach with useful context

Every approved attachment needs a short explanation:

  • what it depicts or contains;
  • which record or stage it belongs to;
  • what the reviewer should verify;
  • who owns the next action; and
  • whether it is an example, a template, or a verified record.

Example: “Generic equipment-condition reference image; technician to verify the actual condition on site.” This is safer than treating the image as proof of a completed inspection.

A simple naming pattern

Use names that describe the function, not the customer:

“service-photo-reference-before-review”
“generic-maintenance-checklist-template”
“approved-work-order-layout-example”

Avoid names that contain customer names, addresses, personal initials, invoice numbers, or internal project codes.

What to do after upload

  1. Open the attachment as a viewer would.
  2. Check the rendered crop, filename, and surrounding record.
  3. Verify the attachment is linked to the intended item.
  4. Add or update the next action.
  5. Remove the attachment through the approved process if you find sensitive information.

For record history, see Audit Log: Review Changes Before You Rely on Them. For internal handoffs, see Internal Handoffs: Keep Team Chat Useful and Safe.

Boundaries

This checklist reduces obvious sharing risks; it does not guarantee complete redaction, access control, file retention, legal compliance, authorization, or that a file is valid evidence. Follow your organization’s approved privacy, security, and retention process.