✓ Independent creative professionals
✓ Small studio client handovers
✓ Bounded final-file releases
— Regulated-data suitability certification
— Legal acceptance or retention advice
— Specialist video proofing
— Household photo archives
Translate the task into access
Write the required action before selecting a permission: submit an input, retrieve a final export, change a working file or manage collaborators. These are not interchangeable. General least-privilege guidance supports keeping access proportionate, but it does not choose the correct product configuration for your client. Inspect the real controls and the scope to which they apply.
Watch inherited scope
A permission on a parent folder may apply to material below it. Check the contents and existing sharing arrangement before inviting someone. A narrowly named folder can still contain an unrelated subfolder or an older release. Prefer a clearly bounded project or release location when that makes the permitted scope easier to understand and verify.
Do not use credentials as a shortcut
A collaborator should use a supported access route, not the owner’s password or recovery code. If a service cannot provide the role you need, that is a limitation to evaluate. Broader credentials can expose unrelated files and account settings. This guide does not recommend bypassing client policies or weakening protections to avoid an inconvenient invitation process.
A fictional role boundary
An illustrator needs a client’s reference images but the client does not need to see drafts. A collection request fits that direction. Later, an assistant may need limited access to a working set, and the client receives a separate final package. Keeping those roles distinct makes the exchange easier to explain and reduces accidental exposure without pretending that a folder label alone enforces security.
Put the decision into practice
Review the participant, permitted action, folder scope and expected end point together. Checking only the participant’s name misses overly broad access. Checking only the folder name misses inherited material. The useful result is an understandable responsibility boundary that can be reviewed when the project or people change.
Where the safety evidence stops
This guide draws on NCSC: using SaaS securely, pCloud file requests, pCloud folder invitations. Merchant-controlled records describe the provider’s own capabilities, terms or standards; they do not independently validate those claims. Other cited records provide additional context. A different publisher or a research, regulatory or certification label does not by itself establish independence, relevance or product validation.
Verify any current price, plan limit, label direction, compatibility rule, or commercial term that would materially change the decision. The dated source ledger shows the underlying records so this conclusion can be checked and updated.
Sources used for this page
These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.
- NCSC: using SaaS securely — Research study · ncsc.gov.uk · Publisher independence not verified · checked 2026-09-29
- pCloud file requests — Merchant documentation · help.pcloud.com · Merchant-controlled · checked 2026-09-29
- pCloud folder invitations — Merchant documentation · help.pcloud.com · Merchant-controlled · checked 2026-09-29