Welcome to the NZRT Wiki Podcast. Today we’re looking at Nextcloud File Sharing and Links.
If you’ve ever needed to get a document to a client quickly, or make sure only the right people inside your organisation can see a sensitive file, then this is the episode for you. Nextcloud gives you a surprisingly fine level of control over who sees what, how long they can see it, and what they can actually do with it once they have access.
Let’s start with the four main ways you can share something in Nextcloud.
The first is a user or group share. This is your standard internal share where you’re giving a specific person or a team direct access. Think of it as internal team collaboration — the people you share with log in and see the file in their own Nextcloud account.
The second type is a public link. This is what you’d use for external sharing, like sending something to a client or making a file available for download without the recipient needing a Nextcloud account. Public links can be protected with a password and given an expiry date so they don’t stay active forever.
The third type is called a federated share. This one’s a bit more advanced — it lets you share files across completely separate Nextcloud instances. So if a partner organisation runs their own Nextcloud server, you can share directly with them without emailing attachments back and forth.
And the fourth type is resharing. This is where someone you’ve shared a file with can then share it on to someone else — a kind of delegation of access. This can be useful but it’s worth being aware of when you allow it, since it means your original share can spread further than you intended.
Now, when you create a public link, there are several settings you can configure. Imagine you click the share button in Nextcloud and choose to create a link. What you’re looking at is a panel that lets you set an expiry date — by default, seven days from creation. You can also set a password so that only someone with that password can open the link. You control the permissions, which by default are set to view only, meaning the recipient can look at the file but not edit it. And you can choose to notify someone by email so they get the link sent directly to them. A key best practice here: if you’re sharing a sensitive document, consider disabling the download option entirely and keeping it in view-only mode. That way the recipient can read it but can’t save a local copy.
Now let’s talk about how different teams at NZRT actually use these sharing features in practice.
For the sales side of things, the agent known as cas uses public links when sharing contracts with clients. Those links are set with a thirty-day expiry, which gives clients enough time to review without leaving links active indefinitely.
Finance, handled by fin, takes a much more restricted approach. Invoices and financial documents are shared only via direct user shares — no public links at all. That keeps sensitive financial data inside the system and away from the open web.
Human resources, managed by han, goes one step further for things like payroll data. Those shares use end-to-end encryption, which means the content is encrypted on your device before it even reaches the server. Only the intended recipient can decrypt and read it.
And then there’s ema, who manages document retention. Rather than letting old shared files pile up forever, ema applies retention policies that automatically delete documents after ninety days. This is a really useful practice for keeping the file system clean and making sure old shared links don’t become a security risk down the line.
Stepping back and looking at the bigger picture for NZRT as a whole: the goal of all this is to make sure the right things are accessible to the right people, for exactly as long as they need to be. Dolibarr invoices and HR records stay locked down through user-only or encrypted shares. At the same time, external parties like clients and vendors can still get what they need through time-limited public links that expire automatically.
If you want to go deeper on any of this, there are three related topics worth exploring in the wiki. The Files App covers how to navigate and manage your files day to day. The Encryption page goes into detail on how end-to-end encryption works and when to use it. And the Permissions and Sharing page gives you the full breakdown of what each permission level actually allows a recipient to do.
That’s it for this episode of the NZRT Wiki Podcast. Thanks for listening.