Monday to Friday. That is a realistic window for getting a well-organised room live, provided one thing is true: the documents already exist in a folder somewhere. If they do not, start with our due diligence checklist and come back when you have them.
This guide is written for the person who will actually do the work, often a CFO, a founder or a junior at the adviser. It assumes you have already chosen a provider; if not, our shortlisting guide will get you there in a week.
What do you need in hand before day one?
Four things, and none of them are software.
- A document set. At least the first-round pack, ideally most of the full diligence set, in one place.
- A process timeline. When the room opens to bidders, when round two starts, the expected signing date.
- A list of outside parties. Bidder firms, their advisers, and who leads each team.
- Two named administrators. One primary, one backup. A room with a single admin stalls when that person is on a plane.
What does each of the five days involve?
Day 1: Build the index and configure the room
Create the room, set the name, branding and time zone, and switch on mandatory two-factor sign-in. Build the folder tree as a numbered index matching the buyer's request list. Add your internal team as administrators and contributors.
Day 2: Upload and check
Convert scans to searchable PDF, apply a consistent file naming pattern, and bulk upload folder by folder. Check every folder against the index, remove duplicates and drafts, and confirm nothing is uploaded that belongs in a later wave.
Day 3: Create permission groups
Make one group per bidder and one per adviser type. Set folder access for each group: hidden, view only, print or download. Turn on dynamic watermarks for all outside groups. Preview the room as each group.
Day 4: Set Q&A rules and do a dry run
Decide question categories, routing to internal experts, approval rules and whether answers are shared across bidders. Invite a colleague as a mock bidder, have them ask three questions, download a file and try to open a hidden folder.
Day 5: Invite and watch
Send invitations with the rules of the room, an NDA reminder and a support contact. Check the activity log by the end of the day to confirm everyone has logged in and nobody is seeing a folder they should not.
That is the skeleton. The rest of this guide fills in the decisions that trip people up.
A five-day setup plan, and what it costs in admin time
How long will each task take for your room size?
Administrators always underestimate upload and checking. These are typical hours of hands-on work, assuming documents are already collected and in reasonable shape.
| Task | 200 files (fundraise) | 500 files (small sale) | 2,500 files (mid-market) | 10,000 files (large auction) |
|---|---|---|---|---|
| Index and room configuration | 1 hour | 2 hours | 4 hours | 1 to 2 days |
| Conversion and naming | 2 hours | 4 hours | 2 days | 1 week, often outsourced |
| Upload and checking | 2 hours | 5 hours | 3 days | 1 to 2 weeks |
| Permission groups and preview | 1 hour | 2 hours | 4 hours | 1 day |
| Q&A setup and dry run | 1 hour | 2 hours | 4 hours | 1 day |
| Invitations and first check | 30 minutes | 1 hour | 3 hours | 1 day |
| Total admin time | About 7 to 8 hours | About 12 to 20 hours | About 6 to 8 days | 2 to 4 weeks |
So the five-day plan comfortably fits rooms up to a few thousand files. Beyond that, you either add people, use the provider’s onboarding service, or start earlier.
How should you structure the index on day one?
Number everything. A two-level numbered scheme such as 1 Corporate, 1.1 Constitutional documents, 1.2 Board minutes, lets buyers’ advisers cite documents precisely in their questions and reports. Our index template gives a full scheme you can copy.
Three rules make day two easier:
- Keep top-level folders to between eight and twelve.
- Do not go deeper than three levels; reviewers get lost.
- Add a “To follow” note file in any folder still waiting on documents, rather than leaving it empty.
How should permission groups be set up on day three?
This is where most of the risk sits. The principle is simple: permissions attach to groups, and each outside party gets its own group, even if two bidders currently have identical rights. When rounds change, you edit groups instead of individuals.
| Group | Wave 1 folders | Wave 2 folders | Wave 3 folders | Q&A | Download |
|---|---|---|---|---|---|
| Internal admins | Full control | Full control | Full control | Manage | Yes |
| Internal contributors | Upload | Upload | Upload, own folders | Answer | Yes |
| Bidder A, deal team | View | Hidden until round 2 | Hidden | Ask | No |
| Bidder A, legal advisers | View | Hidden until round 2 | Hidden | Ask | Protected PDF only |
| Bidder B, deal team | View | Hidden until round 2 | Hidden | Ask | No |
| Clean team, preferred bidder | Not applicable | Not applicable | View | Ask | No |
| Lender or insurer | Hidden | Selected folders | Hidden | No | No |
Use the room’s “view as” or preview feature to check each group. Look for leaks in folder names, too: a folder called “Project Falcon, Acme Corp pricing” tells a bidder something even if it is locked.
Before inviting anyone, export the permission summary and have a second person check it against the table above. It takes ten minutes. A folder left open to every bidder can take months to explain.
Which security settings should be switched on by default?
Turn these on before any outside user is invited:
- Mandatory two-factor authentication. US federal identity guidance in NIST SP 800-63B treats multi-factor sign-in as the baseline for sensitive access.
- Dynamic watermarks on view, print and download, showing user name, email and time.
- Download off by default, then enable it per group where genuinely needed.
- Access expiry set to the expected end of each round.
- Notifications to admins when a new user first logs in.
If personal data is in the room, keep it to what each group needs at that stage. Under the GDPR’s data minimisation principle, set out in Article 5, sharing more than necessary is itself a compliance problem, and the UK ICO’s data sharing guidance gives practical examples.
Our guide to security features that stop leaks explains what each setting protects against.
What should the Q&A rules say?
Decide on day four, not when the first question arrives:
- Categories. Match them to your top-level index folders so questions route automatically.
- Routing. Name the internal expert for each category, plus a backup.
- Approval. Every answer approved by deal counsel or the lead adviser before release.
- Visibility. Whether answers go only to the asking bidder or to all bidders. Most sellers keep them private, but publish answers that correct a document to everyone.
- Limits. Some processes cap questions per bidder per day to keep the team sane.
- Turnaround. A target response time, usually 48 hours for standard questions.
What should the invitation say on day five?
Short, clear and a little formal. Something like this:
You have been invited to the Project Falcon data room. Access is subject to the confidentiality agreement your firm signed. Two-factor sign-in is required. All documents are watermarked with your name. Please send questions through the Q&A module only, not by email. Round one closes on the date in the process letter. For access problems, contact the room administrator listed in the welcome note.
Attach nothing, and do not include a list of other parties. Once invitations are out, check the activity log at the end of the day. Anyone who has not logged in by day two usually needs a nudge or has a spam filter problem.
Haven't picked a provider yet? Get a shortlist matched to your deal type, room size and timeline in under two minutes.
Take the quizWhat usually goes wrong in the first week?
The same handful of problems come up again and again:
- Invitations caught in spam. Corporate filters at banks and funds are strict. Ask each lead to whitelist the provider’s domain.
- A bidder’s adviser added to the wrong group. Usually because two firms share a name. Double-check email domains.
- Draft documents uploaded. Files named “v3 FINAL comments” signal disorganisation. Purge before invitations.
- Scanned PDFs that are not searchable. Reviewers cannot find anything. Run text recognition before upload.
- No one watching Q&A over the weekend. Bidders work weekends during a process. Agree cover.
What changes if you are raising money rather than selling?
The five-day plan compresses. A fundraise usually has one data room shared with several investors who are not competing with each other for the same asset, so most of the bidder-separation work disappears.
In practice: one investor group with view rights is often enough, with a second group for the lead investor and its counsel once a term sheet is signed. Download can stay on for standard corporate documents, though it is worth keeping the cap table and customer contracts view-only. Q&A tends to happen on calls rather than in the room, so a simple question log may replace the full workflow.
What does not change is the index and the dry run. Investors notice a tidy, numbered room, and a five-minute check as a mock investor still catches the folder that was meant to stay hidden. Our fundraising use case lists what investors usually expect to find.
How do you keep the room tidy once it is live?
Set a weekly routine. Every Monday, check the index against new uploads, review who has logged in, disable anyone who has left a bidder team, and archive superseded documents into a clearly labelled folder rather than deleting them. When the deal closes, export the full archive including the audit trail before you shut anything down.
Frequently asked questions
Can I set up a data room in one day?
For a small fundraise with fewer than 200 well-organised files, yes. For a sale with multiple bidders, give yourself at least three days so you can test permissions properly.
Should the seller or the adviser set up the room?
Often the adviser builds the structure and permissions while the seller's team uploads documents. Whoever does it, two people on the seller side should have full admin rights.
How many folders should a data room have?
Eight to twelve top-level folders, no more than three levels deep. Use a numbered index so documents can be cited precisely.
When should I invite bidders?
Only after a dry run with a mock bidder confirms permissions, watermarks and Q&A behave as expected, and the room matches the index.
Do I need the provider's onboarding service?
Not for most rooms under 2,500 files. For very large or heavily scanned rooms, paid onboarding can save a week of admin time.
