The Authentication required option exists in three different places in TimeTonic. They are three independent settings: ticking one does not tick the others. This is the most frequent cause of a share you believed to be protected and which is not.
Point 1: the shared form view
This is the sharing of a form-type view, the one that lets a third party create a new record: contact request, registration, incident report.
The detailed procedure → Visual form editor (Wysiwyg), Sharing options section · Share your table data
Point 2: the External form field
This is a distinct column type, which generates a link allowing a third party to modify an existing record: confirming an appointment, completing a file, approving a quotation.
The setting is in the Options tab of the field. Once Authentication required is ticked, the form is only accessible to users who have access to that workspace.
Create the field and see all its options → External form
Point 3: the Attachments field
This is the point most often missed. A file attached to a record has its own address, independent of the form that displays it. In the Options tab of the Attachments field, the authentication option requires a TimeTonic sign-in in order to reach the file from a form.
Create the field and see all its options → Attachments
Secure form mode
The three previous points decide who gets access. Secure form mode frames how data entry happens: the user goes through a form, and not through free editing of the table.
It is set from the menu of the table or of the view, with Switch to secure form mode. This is the mode to favour as soon as a view is intended for someone who does not have to handle the structure of the data: a field worker, a client, a service provider.
The detailed procedure → Secure edit mode · View options · Table options
The single-use token
On a field of type External form, the Single-use token option makes the link unusable after the first submission.
This is the protection to favour when you send a form by email to somebody who has no TimeTonic account. A link forwarded to a third party, or found in a mailbox months later, no longer opens anything.
Where to tick the option → External form, Options tab
Cutting off a link that has already circulated
When a share link has travelled beyond its recipient, or when a share no longer has a reason to exist, open the Share window of the view and click Delete the share URL of the view.
The link stops working immediately, for everyone. Sharing the same view again will generate a new address.
The other accesses to cut off → Revoke an access: sessions, API keys, share links, invitations
The verification checklist
Go further
External form
Create the field and set its options.
Go further
Attachments
The column type and all of its options.
Go further
Revoke an access
Sessions, API keys, share links, invitations.