Client files

Client files are documents held against a client record — PDFs, Word documents, text files and similar. They live in Secure Files on the client screen, and are encrypted when uploaded and decrypted when downloaded.

Why this matters

Correspondence, referrals and consent forms are usually the documents most likely to end up on a shared drive or in an inbox, where nobody can say afterwards who opened them. Holding them against the client record instead means access is granted per user, every upload, download and deletion is recorded in an audit log, and the files are encrypted at rest.

Before you start

Access to client files is granted per user and is separate from your other permissions. A user who can edit a client record does not automatically get access to that client’s files.

Access is also specific to client files. It is granted separately from other document storage locations in Diarybook, such as the Documents area of an appointment type — so a user who can upload documents to an appointment type does not necessarily have any access to client files.

The first time you open documents in a session, you are asked to enter your password again. This happens once per session, not once per file.

Who can do what

Client file permissions are set per user in the Users area, on User List.

PermissionAllows
Can View FilesSeeing the file list and downloading files from a client record.
Can Upload New FilesUploading files to a client record.
Can Delete FilesPermanently deleting files from a client record.

A user can hold any combination of the three. Someone who uploads referral letters but must never remove them is given Can Upload New Files without Can Delete Files.

Steps

Upload a file

  1. Open the client record and select Secure Files .
  2. Enter your password if you are prompted. Diarybook asks once per session before granting access to documents.
  3. Click Upload.
  4. Browse to the file or files and select them. The files are encrypted as they upload.

Download files

  1. Open the client record and select Secure Files.
  2. Tick one or more files in the list.
  3. Click Download. The files are decrypted as they download.

Delete a file

  1. Tick the file in the list.
  2. Click Delete.
  3. Read the confirmation, which names every file you are about to remove, and confirm.

Deleting is permanent. The Deleted screen in the Clients area recovers deleted client records only — it does not hold deleted files, and there is no other route to get one back.

Storage

An account starts with 5 GB of file storage. When an account reaches its limit, uploads are blocked until either extra storage is subscribed to or existing files are removed. Additional storage can be purchased — see pricing.

Audit log

Every upload, download and deletion is recorded, including who performed it and when. The record is held in Log on the client screen, and is kept for the lifetime of the client record.

This is what makes client files defensible under a data protection request: you can show not only what was held against a record but who accessed it and when.

What to watch for

You are asked for your password when you did not expect it

Documents require you to confirm your password once per session. It is not a sign that your session has expired, and it applies to every user regardless of permission level.

A user can open a client record but sees nothing in Secure Files

Client file access is granted separately from client record access. Check that the user has Can View Files on User List — permission to another document area, such as appointment type documents, does not carry over.

A user can upload but not remove a file they uploaded in error

Can Upload New Files and Can Delete Files are separate permissions. Someone with the first but not the second can add a file and cannot take it back; a user who holds Can Delete Files has to remove it for them.

Uploads stop working

The account has reached its 5 GB storage limit. Uploads stay blocked until someone subscribes to extra storage or removes files that are no longer needed — and removing files is permanent, so check before deleting to make room.