Setting up a data room in five working days

By the BestDataRoom editorial team Published October 9, 2026

Get an AI summary of this page

Monday to Friday. That is a realistic window for getting a well-organised room live, provided one thing is true: the documents already exist in a folder somewhere. If they do not, start with our due diligence checklist and come back when you have them.

This guide is written for the person who will actually do the work, often a CFO, a founder or a junior at the adviser. It assumes you have already chosen a provider; if not, our shortlisting guide will get you there in a week.

What do you need in hand before day one?

Four things, and none of them are software.

  1. A document set. At least the first-round pack, ideally most of the full diligence set, in one place.
  2. A process timeline. When the room opens to bidders, when round two starts, the expected signing date.
  3. A list of outside parties. Bidder firms, their advisers, and who leads each team.
  4. Two named administrators. One primary, one backup. A room with a single admin stalls when that person is on a plane.

What does each of the five days involve?

  1. Day 1: Build the index and configure the room

    Create the room, set the name, branding and time zone, and switch on mandatory two-factor sign-in. Build the folder tree as a numbered index matching the buyer's request list. Add your internal team as administrators and contributors.

  2. Day 2: Upload and check

    Convert scans to searchable PDF, apply a consistent file naming pattern, and bulk upload folder by folder. Check every folder against the index, remove duplicates and drafts, and confirm nothing is uploaded that belongs in a later wave.

  3. Day 3: Create permission groups

    Make one group per bidder and one per adviser type. Set folder access for each group: hidden, view only, print or download. Turn on dynamic watermarks for all outside groups. Preview the room as each group.

  4. Day 4: Set Q&A rules and do a dry run

    Decide question categories, routing to internal experts, approval rules and whether answers are shared across bidders. Invite a colleague as a mock bidder, have them ask three questions, download a file and try to open a hidden folder.

  5. Day 5: Invite and watch

    Send invitations with the rules of the room, an NDA reminder and a support contact. Check the activity log by the end of the day to confirm everyone has logged in and nobody is seeing a folder they should not.

That is the skeleton. The rest of this guide fills in the decisions that trip people up.

A five-day setup plan, and what it costs in admin time

Before day one: documents gathered, a process timeline, the list of outside parties and two named admins.
1 Day 1, Mon
Index and room setup
Name, branding, time zone
Force two-factor sign-in
Numbered folder index
Add internal team
2 Day 2, Tue
Upload and check
Scans to searchable PDF
Consistent file names
Bulk upload by folder
Check against the index
3 Day 3, Wed
Permission groups
One group per bidder
Hidden, view, print or download
Watermarks on
Preview as each group
4 Day 4, Thu
Q&A rules and dry run
Categories and routing
Approval before release
Mock bidder test
5 Day 5, Fri
Invite and watch
Invitations with room rules
NDA reminder, support contact
Check the activity log
Total hands-on admin time by room size
200 files
7 to 8
hours
500 files
12 to 20
hours
2,500 files
6 to 8
days
10,000 files
2 to 4
weeks
bestdataroom.net
Admin hours assume documents are already gathered and in reasonable shape; the five-day plan fits rooms up to a few thousand files. Source: day-by-day steps and time table in this guide.

How long will each task take for your room size?

Administrators always underestimate upload and checking. These are typical hours of hands-on work, assuming documents are already collected and in reasonable shape.

Task200 files (fundraise)500 files (small sale)2,500 files (mid-market)10,000 files (large auction)
Index and room configuration1 hour2 hours4 hours1 to 2 days
Conversion and naming2 hours4 hours2 days1 week, often outsourced
Upload and checking2 hours5 hours3 days1 to 2 weeks
Permission groups and preview1 hour2 hours4 hours1 day
Q&A setup and dry run1 hour2 hours4 hours1 day
Invitations and first check30 minutes1 hour3 hours1 day
Total admin timeAbout 7 to 8 hoursAbout 12 to 20 hoursAbout 6 to 8 days2 to 4 weeks

So the five-day plan comfortably fits rooms up to a few thousand files. Beyond that, you either add people, use the provider’s onboarding service, or start earlier.

How should you structure the index on day one?

Number everything. A two-level numbered scheme such as 1 Corporate, 1.1 Constitutional documents, 1.2 Board minutes, lets buyers’ advisers cite documents precisely in their questions and reports. Our index template gives a full scheme you can copy.

Three rules make day two easier:

  • Keep top-level folders to between eight and twelve.
  • Do not go deeper than three levels; reviewers get lost.
  • Add a “To follow” note file in any folder still waiting on documents, rather than leaving it empty.

How should permission groups be set up on day three?

This is where most of the risk sits. The principle is simple: permissions attach to groups, and each outside party gets its own group, even if two bidders currently have identical rights. When rounds change, you edit groups instead of individuals.

GroupWave 1 foldersWave 2 foldersWave 3 foldersQ&ADownload
Internal adminsFull controlFull controlFull controlManageYes
Internal contributorsUploadUploadUpload, own foldersAnswerYes
Bidder A, deal teamViewHidden until round 2HiddenAskNo
Bidder A, legal advisersViewHidden until round 2HiddenAskProtected PDF only
Bidder B, deal teamViewHidden until round 2HiddenAskNo
Clean team, preferred bidderNot applicableNot applicableViewAskNo
Lender or insurerHiddenSelected foldersHiddenNoNo

Use the room’s “view as” or preview feature to check each group. Look for leaks in folder names, too: a folder called “Project Falcon, Acme Corp pricing” tells a bidder something even if it is locked.

A small habit that saves deals

Before inviting anyone, export the permission summary and have a second person check it against the table above. It takes ten minutes. A folder left open to every bidder can take months to explain.

Which security settings should be switched on by default?

Turn these on before any outside user is invited:

  • Mandatory two-factor authentication. US federal identity guidance in NIST SP 800-63B treats multi-factor sign-in as the baseline for sensitive access.
  • Dynamic watermarks on view, print and download, showing user name, email and time.
  • Download off by default, then enable it per group where genuinely needed.
  • Access expiry set to the expected end of each round.
  • Notifications to admins when a new user first logs in.

If personal data is in the room, keep it to what each group needs at that stage. Under the GDPR’s data minimisation principle, set out in Article 5, sharing more than necessary is itself a compliance problem, and the UK ICO’s data sharing guidance gives practical examples.

Our guide to security features that stop leaks explains what each setting protects against.

What should the Q&A rules say?

Decide on day four, not when the first question arrives:

  • Categories. Match them to your top-level index folders so questions route automatically.
  • Routing. Name the internal expert for each category, plus a backup.
  • Approval. Every answer approved by deal counsel or the lead adviser before release.
  • Visibility. Whether answers go only to the asking bidder or to all bidders. Most sellers keep them private, but publish answers that correct a document to everyone.
  • Limits. Some processes cap questions per bidder per day to keep the team sane.
  • Turnaround. A target response time, usually 48 hours for standard questions.

What should the invitation say on day five?

Short, clear and a little formal. Something like this:

You have been invited to the Project Falcon data room. Access is subject to the confidentiality agreement your firm signed. Two-factor sign-in is required. All documents are watermarked with your name. Please send questions through the Q&A module only, not by email. Round one closes on the date in the process letter. For access problems, contact the room administrator listed in the welcome note.

Attach nothing, and do not include a list of other parties. Once invitations are out, check the activity log at the end of the day. Anyone who has not logged in by day two usually needs a nudge or has a spam filter problem.

Haven't picked a provider yet? Get a shortlist matched to your deal type, room size and timeline in under two minutes.

Take the quiz

What usually goes wrong in the first week?

The same handful of problems come up again and again:

  1. Invitations caught in spam. Corporate filters at banks and funds are strict. Ask each lead to whitelist the provider’s domain.
  2. A bidder’s adviser added to the wrong group. Usually because two firms share a name. Double-check email domains.
  3. Draft documents uploaded. Files named “v3 FINAL comments” signal disorganisation. Purge before invitations.
  4. Scanned PDFs that are not searchable. Reviewers cannot find anything. Run text recognition before upload.
  5. No one watching Q&A over the weekend. Bidders work weekends during a process. Agree cover.

What changes if you are raising money rather than selling?

The five-day plan compresses. A fundraise usually has one data room shared with several investors who are not competing with each other for the same asset, so most of the bidder-separation work disappears.

In practice: one investor group with view rights is often enough, with a second group for the lead investor and its counsel once a term sheet is signed. Download can stay on for standard corporate documents, though it is worth keeping the cap table and customer contracts view-only. Q&A tends to happen on calls rather than in the room, so a simple question log may replace the full workflow.

What does not change is the index and the dry run. Investors notice a tidy, numbered room, and a five-minute check as a mock investor still catches the folder that was meant to stay hidden. Our fundraising use case lists what investors usually expect to find.

How do you keep the room tidy once it is live?

Set a weekly routine. Every Monday, check the index against new uploads, review who has logged in, disable anyone who has left a bidder team, and archive superseded documents into a clearly labelled folder rather than deleting them. When the deal closes, export the full archive including the audit trail before you shut anything down.

Frequently asked questions

Can I set up a data room in one day?

For a small fundraise with fewer than 200 well-organised files, yes. For a sale with multiple bidders, give yourself at least three days so you can test permissions properly.

Should the seller or the adviser set up the room?

Often the adviser builds the structure and permissions while the seller's team uploads documents. Whoever does it, two people on the seller side should have full admin rights.

How many folders should a data room have?

Eight to twelve top-level folders, no more than three levels deep. Use a numbered index so documents can be cited precisely.

When should I invite bidders?

Only after a dry run with a mock bidder confirms permissions, watermarks and Q&A behave as expected, and the room matches the index.

Do I need the provider's onboarding service?

Not for most rooms under 2,500 files. For very large or heavily scanned rooms, paid onboarding can save a week of admin time.