The three capabilities closed the gap that had blocked SFS from running the client's transaction rooms, and the contract closed before their existing VDR vendor's renewal.
Evolving Secure File Sharing toward a Virtual Data Room solution
I led the design of three interconnected features that helped Diligent win major enterprise clients and expand Secure File Sharing into high-value, confidential transaction use cases.
Data-room controls SFS can now package and position as a standalone VDR proposition for future enterprise clients.
A legal access gate, room-wide update notifications, and concealed identities, designed to work together under a hard deadline.
A file-sharing tool being pushed into data-room territory it was never built for
A board platform, repurposed for high-stakes transactions
Diligent Secure File Sharing (SFS, recently renamed Diligent Data Room) is a secure collaboration tool used by executives, board admins, and partners to store board materials and exchange confidential files. Enterprise clients — like the aircraft-leasing company at the centre of this case study — had begun repurposing it for the riskier workflows typical of Virtual Data Rooms, running multiple transaction rooms with granular, per-participant restrictions.
The product lacked three critical, deal-breaker capabilities
Three things were essential to confidentiality, compliance, and trust in sensitive transactions, and SFS had none of them: no legal consent or NDA gate before granting access, no automatic notifications when content changed, and no way to hide participant identities in a shared room. Without them, the client's confidential deals couldn't run on the product at all.
Win the deal now, then open a new market
Deliver the essential features within a tight deadline to meet the client's immediate needs, enable Sales to package and position them as a standalone offering for future clients, and keep the design scalable, usable, and flexible for similar enterprise use cases — all within roughly three months.
- With shifting priorities and a hard deadline to confirm whether SFS could meet the client's needs before their renewal, we had roughly six weeks to deliver discovery, requirements, and prototypes, forcing rapid decisions and aggressive scope cuts.
- Communication was fragmented, with limited access to key users and slow feedback cycles. Each meeting had to focus on the essentials, with follow-ups handled over email.
- Internally, there was no clear strategic plan for VDR expansion. Delivering these features without one risked short-term fixes rather than a cohesive, scalable solution.
Who these data rooms are built for
A global leader in aircraft leasing and aviation asset management, the client buys, leases, and sells aircraft fleets for airlines, investors, and other lessors. Each transaction — from asset valuation to contract negotiation — means reviewing large volumes of sensitive data: maintenance records, compliance certificates, financial reports. Legal, financial, and technical teams collaborate under strict confidentiality and audit requirements. Their need for a secure, structured environment to manage these high-stakes exchanges directly shaped the work in this project.
Board admin / legal
Board admin or legal
Corporate Secretary · Legal Ops Manager · Project lead
Focused on compliance, accuracy, and control. They manage sensitive transactions, set up secure data rooms, and make sure every participant operates under the right permissions and legal frameworks — experts in confidentiality and workflow who still keep collaboration smooth during complex deals.
Collaborators
Collaborators
Analysts · Legal counsel · Advisers · Auditors
Internal collaborators — financial analysts, strategic planners, legal counsel — prepare, review, and validate documents. External collaborators — investment analysts, legal advisers, auditors — access the client's materials under strict confidentiality. Both value efficiency, data integrity, and a system that protects their activity while giving quick, accurate access within the room's disclosure rules.
IT Administrator
IT Administrator
System Admin · IT Compliance · Information Security
Pragmatic and risk-aware, responsible for system stability, security, and compliance. They need solutions that integrate seamlessly with existing policies and provide clear auditability, without overcomplicating configuration or maintenance.
Designing for confidentiality and control
The client required a legal gate that every user must pass before entering a data room. Based on their example, the Terms & Conditions text served as a confidentiality and non-disclosure statement — outlining obligations to protect proprietary project information, prohibiting sharing or copying data, and acknowledging the legal consequences of a breach. The goal was a legal-consent experience that ensures compliance while staying quick and intuitive for users.
For data room managers
Requirements
- Add a T&C consent configuration option during setup.
- Support updating and reactivating agreements.
- Allow activation or deactivation at any time.
We placed this feature within the Policies section of Data Room Management, alongside the other administrative safety restrictions. Initially the PM expected a short text input, but the client's example turned out to be a multi-paragraph legal document — so, to support scalability and prevent formatting issues, we switched to PDF upload rather than inline editing.
I also advocated for an optional preview mode, so Data Room Managers could review how the consent screen appears to end users before publishing — critical, since managers can't switch roles to test the collaborator view.
For collaborators
For collaborators, I designed a clear, minimal consent screen optimised for first-time access. It emphasises readability and trust, provides confirmation feedback on agreement, and includes a link to the full document.
Collaborators can return any time to view or download the version they accepted, directly from the data-room interface.
Keeping fast-moving deals aligned without burying users in email
After room setup, during the "opening" phase, the organisation invites collaborators (buyers, legal teams) and grants them simultaneous access to documents for due diligence or contract review. They had to know when new documents were uploaded or changed — so no one reviewed a stale version — and every change had to leave a mark in the change log for compliance, audit, and litigation. All of it without spamming a room of hundreds, or leaking a masked identity through a notification.
- Admin-controlled notifications at the group level.
- Email summaries listing file updates and uploads (excluding deletions).
- Compliance with member-visibility rules — notifications must respect masked identities.
- Reliable delivery at a limited frequency to avoid spam.
- Every change written to an activity report for audit purposes, regardless of who is notified.
We introduced configurable, group-based notifications that summarise changes and updates, delivered as concise email digests roughly every 15 minutes.
Group-level digest configuration
Digest email summaryMember visibility and concealed identities
This was the most complex challenge: a concealed-member capability that hides specific users or groups from each other within the same data room. In the client's world, competing buyers, investors, and legal advisers often work in the same room during tenders, financing rounds, or asset sales. Some groups must not be able to identify each other — to protect deal integrity, prevent leaks, and stay compliant with regulatory and contractual obligations — while admins keep full visibility and every action stays auditable.
- Manage user visibility by group or at the document level.
- Preserve full transparency for admins while protecting external users.
- Conceal collaborator identifiers (name, email) in activity logs, notifications, comments, and history.
- Keep full compatibility with the existing permissions model.
Ideally these controls would live in organisation settings for self-serve management; under the development constraints, that became a follow-up backlog item.
Communicating states, managing conflicts
In complex projects, users often belong to multiple groups — one with masking enabled, another without. How do you keep data confidential without confusing users or showing inconsistent views? We designed a logic where member details appear only for users in groups where the viewer holds "view" permission, keeping visibility consistent within each group's access roles. Even in overlapping setups, users never see what they shouldn't — and admins can always predict what each role will experience. The interface gives clear feedback: admins can preview permissions, understand dependencies, and verify masking before applying changes, while icons in member and group tables help Data Room Managers read notification and visibility status at a glance.
Overlapping group states
Status icons at a glanceMasking activity while maintaining traceability
For masking to be effective, we removed user identifiers from every member-activity interface while keeping the data traceable — file and folder activity, version history, content views, and change-notification emails. The result: activity stays fully auditable, but individual identities are never exposed to the wrong party.
Masked activity history
Traceable, anonymised recordDemo sessions with the Client
I presented the concepts as interactive Figma prototypes across several demo sessions with the client, Product Manager, Account Manager, and Solution Engineer. With a tight timeline and no direct line to end users, these sessions were the fastest way to validate ideas, align on requirements, and minimise the risk of rework — and the client's active participation and openness to discussion helped us refine priorities and reach shared clarity early. This is stakeholder validation, not usability testing: it confirmed we were building the right things more than it proved the flows were usable, a distinction I kept visible in how much confidence we placed on each decision.
Prototype demo session with the clientClosed, won
All three capabilities shipped as one coherent system inside the roughly three-month window: a PDF-based legal access gate with preview and versioning, group-level update digests wired into the audit log, and a VDR mode that conceals participant identities while keeping every action traceable. Together they enabled a multi-thousand-dollar deal to close with the client.
The work also positioned SFS as a more premium, high-end offering — data-room controls Sales can package as a standalone proposition to support new enterprise sales engagements, rather than a one-off accommodation. And a beautiful thank-you note and flowers arrived from the Account Manager who closed the deal. :)
A thank-you from the Account Manager who closed the dealWhat this project taught me
Being proactive in client communication
Client-side communication was fragmented, with limited access to key users and slow feedback cycles. Once we began demoing the first concepts in Figma, alignment improved — but key stakeholders often missed sessions, which slowed validation. Next time I'd push harder, earlier, to get the right people in the room.
When time is short, early and continuous alignment is a must-have, not a nice-to-have
Next time I'd organise more workshops, especially early in discovery. Not doing so led to on-the-fly adjustments during design and implementation. Structured early sessions would have mapped flows, caught dependencies, resolved design conflicts, and gathered questions more efficiently for client calls.