M16

File Management & Secure Data Rooms

Enterprise file management with granular access control — and purpose-built secure data rooms for M&A due diligence.

API workflow reference →
Repository setup

Create a repository, scoped to the team using it.

Name it, pick its posture (general collaboration or secure data room), and lock down which file types can be uploaded. Everything a repository needs is decided at creation — not patched later.

  • General or secure-data-room posture chosen once at creation
  • Allowed file types — 36 MIME types across 6 groups, toggled individually or by group
  • Purpose captured with the repository so the reason travels with the data
Sharing

Sharing that separates viewing, editing, and everything in between.

Drill into any folder, share a file with named people, and pick the exact combination of permissions. View, download, edit, rename, delete, and share are separate grants — not one "access" switch.

  • Per-action grants: view, download, edit, rename, delete, share
  • Owner, editor, and viewer states always visible on the share dialog
  • "Anyone with link" sharing for low-sensitivity general items — data rooms are always named-access only
Secure data rooms

A repository with legal weight from the moment it's created.

Creating a secure data room requires reviewing and accepting a binding NDA — purpose, confidentiality, access, audit, legal effect. Acceptance is recorded. Every action inside the room is logged from that moment on.

  • Binding data-room NDA acknowledged at creation, per repository
  • Access is always named — no anonymous share links
  • Every view, download, change, share, and disclosure event logged from day one
Party wizard

Adding a party takes a three-step wizard, not a spreadsheet import.

Each buyer, investor, or lender is a party — an account plus its people. The add-party wizard captures the account (search or create, with party type), the people (directory search or invite by email), and confirms at Phase 1 with no folder grants.

  • Three-step wizard: account, people, confirm at Phase 1
  • People added by directory search or email invite
  • New parties start at Phase 1 with no folder grants — you decide what unlocks and when
Staged disclosure

Reveal folders by phase, with a preview of what unlocks.

Data rooms don't grant everything at once. Advance a party to a new phase and the system shows exactly which folders and how many documents unlock — before you confirm. Gated folders are absent from a party's view; nothing greyed-out to reverse-engineer.

  • Folder-level phase gates enforce staged disclosure
  • Advance one party or bulk-advance across parties, both with concrete unlock preview
  • "View as party" to see the data room exactly as they see it
Deal-team differentiator

Every question answered on the record.

Data rooms need more than a shared folder — they need a structured conversation. The Q&A workflow routes buyer questions to the deal team, tracks internal drafts, and publishes answers with audience controls. Nothing gets lost in email; nothing gets answered twice.

  • Parties ask questions against any document they can see; documents carry canonical index numbers (e.g. 2.1).
  • The deal team works a triage queue: assignment, internal drafts invisible to parties, then a publish step with an audience choice (one party or all).
  • Threads can be withheld on publish; withdrawn threads stay in the record and the closing binder.
  • Parties see only their own threads plus answers published to all — with an honest "awaiting answer" state even while internal drafts exist.

One module, two postures. Everyday file collaboration and locked-down deal rooms share one interface, one permission model, and one audit trail. General file management handles day-to-day storage and sharing across teams; secure data rooms extend the same foundation with binding NDAs, party-level access, staged disclosure, and a structured Q&A workflow that keeps every question and answer on the record.

Capabilities

  • Repositories per team, project, or deal with per-repository allowed file types (36 MIME types across 6 groups)
  • Folder trees with drill-down, breadcrumbs, list/grid views, search, starred items, multi-select, bulk operations, trash with restore
  • File versioning, replace, restore, and per-item activity history
  • Per-action sharing permissions: view, download, edit, rename, delete, share — with a live effective-permission view
  • "Anyone with link" public sharing for files and folders in general repositories
  • File and folder locks, legal holds, and per-repository watermark policies
  • Secure data rooms with binding NDA acceptance at creation and per-visitor
  • Parties as first-class access units (company + people) with a three-step add-party wizard
  • Staged disclosure — folders gated by minimum phase; "view as party" to preview any perspective; bulk advance with unlock preview
  • Structured Q&A workflow with triage queue, internal drafts, audience-controlled publish, withheld/withdrawn thread retention
  • Deal-wide document index, closing binder export, and full audit history of every view, download, change, share, disclosure event, and Q&A action

Benefits

  • Handles day-to-day collaboration and locked-down deals in one module — one interface, one permission model, one audit trail
  • Prevents overexposure with phase gates and per-action grants — no more "reply all" mistakes on sensitive files
  • Produces a defensible audit trail for regulated transactions and post-close disputes
  • Cuts the M&A closing loop by replacing the buyer-question email chain with an on-the-record queue

Flow of work

  1. 01Create a repository or data room
  2. 02Configure allowed file types and (for deal rooms) an NDA
  3. 03Upload files, organize into folders, apply locks or watermarks as needed
  4. 04Add parties or share with individual users
  5. 05Advance disclosure phases as trust builds
  6. 06Route buyer questions through the Q&A triage queue
  7. 07Publish answers to one party or all — with a permanent record

Subfeatures

  • Repository create/update
  • Clone repository
  • Archive & restore
  • Repository transfer
  • Allowed MIME types (36 across 6 groups)
  • Watermark policy
  • NDA save/accept
  • Folder create/rename/move
  • File upload/version/replace
  • Bulk delete/download/move/restore
  • Trash with restore
  • Search files & folders
  • Star item
  • Per-action share grants
  • "Anyone with link" share
  • File & folder locks
  • Legal holds
  • Party wizard (account, people, confirm)
  • Party members management
  • View as party
  • Folder phase gates
  • Bulk advance parties
  • Document index (canonical numbering)
  • Q&A ask/assign/draft/publish
  • Withheld & withdrawn Q&A retention
  • Closing binder export
  • Repository activity feed & export
  • Storage usage per repository
  • Repository templates
  • Public share-link resolve
Source surfaces (technical reference)

Internal code areas in the licensed Full-Stack codebase that back this module.

  • ApiRepository (top-level ops)
  • ApiRepositoryFile (file lifecycle, versioning, sharing, locking, watermarking)
  • ApiRepositoryFolder (folder lifecycle, permissions, sharing)
  • ApiRepositoryParty (party + party-member)
  • ApiRepositoryQA (question-and-answer workflow)
  • ApiPublicShareLink (unauthenticated share-link resolution)
  • Background repository job workers (bulk download, closing export, activity export)
Feature matrix

General file management vs. Secure data rooms, side by side.

General file management ships as the everyday-collaboration posture; secure data rooms layer party-level access, staged disclosure, NDAs, and Q&A on the same foundation.

CapabilityGeneral file managementSecure data rooms
Folders, versions, trash, starred, searchYesYes
Per-action sharing (view / download / edit / rename / delete / share)YesYes
Allowed file types per repository (36 MIME types, grouped)YesYes
File & folder locks + legal holdsYesYes
"Anyone with link" sharingYesNo — access is always named
Binding NDA at creationYes
Parties (company-level access)Yes
Staged disclosure (phase gates on folders)Yes
"View as" a partyYes
Structured Q&A with publish controlsYes
Closing binder exportYes
Audit historyPer-item activityEvery event, deal-wide
In the stack

Where it lives. What it exposes.

A quick visual of how File Management & Secure Data Rooms participates across the CleenUI stack, alongside the named operations it adds to the API surface.

M16 · architecture
Frontend
React · TailwindCSS · 60+ components
Repository listFolder tree navigatorFile details panelShare dialog (per-action)Party wizardDisclosure phase managerView-as-party switchQ&A triage queue
API
C# Web API · production-ready · role-aware
Repository CRUDFile upload/versionFolder opsPer-action share grantsParty CRUDPhase advanceQ&A workflow
Database
AzureSQL · 300+ tables · 700+ procedures
RepositoriesFilesFileVersionsFoldersSharesPartiesPartyMembersPhaseGatesQaThreadsRepositoryActivity
Async Services and Batch Jobs
WebJobs & Functions · queue-backed
File ingestion workerBulk operation dispatcherClosing binder exporterAudit log writerQ&A notification dispatcher
All four layers ship together as the Full-Stack license. M16 blocks are highlighted.
API operations

Named operations on this surface

30
Try these in Postman
  • POSTRepository create/update/repository/create-update
  • POSTClone repository/repository/clone-repository
  • POSTArchive & restore/repository/archive-restore
  • POSTRepository transfer/repository/transfer
  • POSTAllowed MIME types (36 across 6 groups)/repository/allowed-mime-types-36-across-6-groups
  • POSTWatermark policy/repository/watermark-policy
  • POSTNDA save/accept/repository/nda-save-accept
  • POSTFolder create/rename/move/repository/folder-create-rename-move
  • POSTFile upload/version/replace/repository/file-upload-version-replace
  • POSTBulk delete/download/move/restore/repository/bulk-delete-download-move-restore
  • POSTTrash with restore/repository/trash-with-restore
  • POSTSearch files & folders/repository/search-files-folders
  • POSTStar item/repository/star-item
  • POSTPer-action share grants/repository/per-action-share-grants
  • POST"Anyone with link" share/repository/anyone-with-link-share
  • POSTFile & folder locks/repository/file-folder-locks
  • POSTLegal holds/repository/legal-holds
  • POSTParty wizard (account, people, confirm)/repository/party-wizard-account-people-confirm
  • POSTParty members management/repository/party-members-management
  • POSTView as party/repository/view-as-party
  • POSTFolder phase gates/repository/folder-phase-gates
  • POSTBulk advance parties/repository/bulk-advance-parties
  • POSTDocument index (canonical numbering)/repository/document-index-canonical-numbering
  • POSTQ&A ask/assign/draft/publish/repository/q-a-ask-assign-draft-publish
  • POSTWithheld & withdrawn Q&A retention/repository/withheld-withdrawn-q-a-retention
  • POSTClosing binder export/repository/closing-binder-export
  • POSTRepository activity feed & export/repository/activity-feed-export
  • POSTStorage usage per repository/repository/storage-usage-per-repository
  • POSTRepository templates/repository/templates
  • POSTPublic share-link resolve/repository/public-share-link-resolve

Each operation maps to an endpoint in the licensed C# Web API surface.