Share Links: Give Auditors and Banks a Window, Not a Copy
Rexfin's share links send auditors and lenders a read-only, tokenized view where every number still drills to its source, with no export and no separate login.
By The Rexfin team
An auditor asks for access to your numbers. A lender’s credit team wants to see the trend before renewal. The usual answer is a spreadsheet extract, an emailed PDF, or a login you have to provision and later remember to revoke. All three have the same problem: once the file leaves your system, it stops being your system’s version of the truth. Rexfin’s share links are built to avoid that handoff entirely.
A link, not an export
Creating a share link produces a tokenized URL: a long, random string that resolves to a standalone, read-only view of the company. It reuses the same statement, trend, and segment components a logged-in user would see, with the same click-to-source behavior intact: an auditor can open the provenance drawer on any figure and land on the exact page it came from, with the PDF re-hashed to confirm it hasn’t been altered since it was filed. What they cannot do is anything that would let the view drift from the source. What-if scenarios, unaudited plan data, exports, and any owner-facing navigation are all absent from the shared view. There is one banner, stating the worst audit grade across everything shown, never a blanket “audited” claim papering over a mix of statuses.
That last point is deliberate. If a shared view mixes an audited annual filing with an unaudited interim, the banner names the weaker of the two. An auditor should never have to guess which parts of what they’re looking at actually carry an audit opinion.
What happens on the other end
Every open is logged, per section, with a timestamp. The owner gets a panel showing who viewed what and when, plus the ability to revoke the link at any moment, and revocation is immediate and idempotent, so hitting revoke twice doesn’t error out or half-work. A revoked, expired, or simply invalid token all render the same thing on the outside: one plain, uniform “not found.” There’s no way to probe a link and learn whether it used to work, is expired, or was never valid at all; that distinction only shows up inside the owner’s own panel, never to whoever’s holding the link.
The document library underneath a shared view is exactly what was in scope when the link was created; nothing about the shared session lets a recipient reach beyond it. And because every view is written to the same event log that tracks everything else in the workspace, a share link’s activity is part of the audit trail, not a side channel outside it.
The honest boundary
Worth saying plainly: possessing the link is the access. There’s no separate login step layered on top, so anyone who has the URL can open the view until it’s revoked or expires. That’s the tradeoff that makes it frictionless for an outside party who shouldn’t need an account just to look at a set of numbers for a week, but it means the link itself deserves the same care you’d give a password. Set an expiry when you can, and treat revoke as a normal part of closing out an engagement, not a break-glass action.
This is not a replacement for full identity-gated access with role-based permissions: that’s what internal team accounts are for. Share links solve a narrower problem: getting a verified, current view in front of someone outside your workspace without turning it into a static file that goes stale the moment your numbers change.
Who this is for
CFOs sending a board pack preview to a director who wants to poke at the underlying trend before the meeting. Finance teams responding to an audit request without exporting a working paper that then needs its own version control. Anyone renewing a facility who’d rather point a lender at a live, cited view than attach a PDF and hope nobody asks a question the PDF can’t answer.
To see a share link created and drilled into live, book a demo. For more of the product tour, visit the pillar hub.
Part of Rexfin Product Tour: Every Number Traceable