Go back

How access controls solves for sensitive videos visible to anyone with the link

A video gets created, contains something genuinely sensitive, an internal roadmap discussion, a customer’s specific account details, unreleased pricing, and gets shared the same way any other video would be: a link, generated and sent, technically accessible to anyone who has it, whether or not that link was ever meant to reach them. This works fine as long as the link stays exactly where it was intended. It stops working the moment it doesn’t, forwarded by someone who didn’t realize the content was sensitive, indexed by a search engine, or simply shared more broadly than the original sender anticipated.

A link that works for anyone who has it, with no further restriction, relies entirely on the link itself staying private, which is a much weaker guarantee than it sounds like. Links get forwarded, copied into shared documents, pasted into group chats, and occasionally indexed by search engines if a platform doesn’t specifically prevent it. None of this requires anyone to act maliciously, a well-intentioned forward to a colleague who wasn’t part of the original intended audience is enough to move sensitive content outside its intended boundary, with the platform itself having no way to prevent or even detect that it happened.

This becomes a concrete governance problem specifically because “anyone with the link” isn’t a defined, controllable audience. A security review asking who can currently view a piece of sensitive content deserves a specific, bounded answer, not “anyone who’s received the link through any of the paths it might have traveled since it was first shared.”

What real access controls actually need to provide

Viewer-level restriction, not just link obscurity. Real access control means the platform can verify who’s actually viewing a piece of content, restricting it to specific people, domains, or authenticated accounts, rather than relying on the link itself being the only barrier between the content and anyone who happens to obtain it.

Sensible defaults for new content. Sensitive content should default to a restricted setting, requiring a deliberate action to make it more broadly accessible, rather than defaulting to open link access that then needs to be manually tightened after the fact.

Revocable access after the fact. If a link has already been shared more broadly than intended, there needs to be a way to revoke access or restrict a previously open link, rather than the content remaining permanently accessible to anyone who obtained it before the mistake was caught.

Visibility into who’s actually accessing restricted content. Beyond just restricting access, a genuinely useful system provides some visibility into who has viewed a piece of sensitive content, supporting both routine oversight and any investigation if something needs to be traced back.

Velo supports this directly: access controls sit alongside shared workspaces, libraries, brand rules, and governance features as part of managing video creation and distribution, giving teams a way to restrict who can actually view specific content rather than relying on link privacy alone.

Why “security through obscurity” fails predictably, not randomly

It’s worth naming the underlying assumption link-only sharing depends on: that a sufficiently random, hard-to-guess link functions as adequate protection on its own. This approach, often called security through obscurity, has a long, well-documented history of failing in predictable ways across many types of systems, not because the links themselves get guessed, but because they get shared, copied, and forwarded by people who had legitimate access and simply didn’t realize the content warranted more careful handling. The failure mode isn’t a sophisticated attack, it’s an ordinary, well-intentioned human being helpful in a way that moves content outside its intended boundary. This is worth explaining plainly when making the case for access controls, since the risk isn’t hypothetical or exotic, it’s the completely normal way people already behave with links they receive.

What tends to get classified as sensitive too late

A recurring pattern worth watching for is content that wasn’t originally considered sensitive at the time of creation, but became so later, an early product concept video that referenced competitive positioning, a training recording that happened to include a screen glimpse of internal tooling, a customer walkthrough that incidentally showed another customer’s data in the background. Content classification tends to happen, if at all, at the moment of creation, based on what someone was thinking about at the time, and rarely gets revisited as circumstances change. This is worth building into a periodic review process rather than assuming a one-time classification at creation is sufficient for the life of the content.

What this looks like in practice

Consider a Knowledge Management team maintaining internal reference content that includes some genuinely sensitive material, details about an unreleased product change, internal process documentation referencing confidential information. Under link-only sharing, this content is exactly as protected as any other video, meaning its actual sensitivity has no bearing on who can technically access it if the link ends up somewhere unintended. With real access controls, sensitive content can be restricted to specific people or a defined group, with that restriction actually enforced by the platform rather than depending entirely on the link staying private through nothing more than good luck and careful handling.

For IT and Cybersecurity, access controls also support a defensible answer to a question that comes up in nearly every security review: can you confirm that sensitive content is only accessible to people who are supposed to see it. Link-only sharing provides no real basis for that confirmation. Enforced access controls do.

What to check before assuming access controls are actually protecting sensitive content

Is restriction enforced at the platform level, or does it rely entirely on link secrecy? This is the fundamental distinction, and it’s worth testing directly: share a restricted piece of content’s link with an account that shouldn’t have access and confirm the platform actually blocks it.

Does new content default to restricted, or open? A platform that defaults every new piece of content to open link access, requiring manual restriction afterward, tends to produce the exact exposure risk access controls are meant to prevent.

Can access be revoked after a link has already been shared? Confirm this specifically, since it’s the capability that matters most once a mistake has already happened and content has been shared more broadly than intended.

A link that works for anyone who has it is not real access control, no matter how unlikely it seems that the wrong person will ever obtain it. Restrict sensitive content deliberately, and verify that restriction is actually enforced before trusting it to protect anything that matters.

Try Velo for free · See how it works


About the author

Ritu Parakh is Growth Lead at Velo, the AI video messaging platform that turns a screen recording, a deck, or a URL into a polished, narrated video - and an editable written doc. She writes about video for demos, onboarding, training, and enablement. Connect on LinkedIn

Access controls let Knowledge Management restrict sensitive reference material to only the people who should see it, rather than relying on a link's obscurity as the only real protection.

Access controls give IT and Cybersecurity an enforceable, reviewable way to restrict who can view specific content, supporting both data protection requirements and a defensible answer during any security review.

Classify content by sensitivity, apply restricted viewing permissions to anything containing internal, customer, or otherwise sensitive information, and default new content to a restricted setting rather than open access.

Confirm the platform supports genuine viewer-level restrictions, not just link obscurity, and audit existing content for anything sensitive that's currently accessible to anyone with the link rather than a defined, restricted audience.

Bring the video layer to your product team