External documents
Bring a PDF you did not author into the governance record, and put it under the same versioning, review and access control as an authored document.
Not everything you have to control is something you wrote. Supplier terms, a certificate, a regulator's notice, a signed contract, a manual from a vendor — you did not author the content and you must not change it, but it still has to sit in the record with an owner, a version and an approval behind it. That is an external document.
An external document is a file Alchex controls rather than text Alchex edits. Everything else about it — owner, reference code, versions, review, activity log, archive — works exactly as it does for an authored document.
Adding one
Drag a PDF onto the Governance page. Word and Markdown files convert into editable documents; a PDF becomes an external document instead. You can drop up to 20 files at once, each up to 25 MB.
An external document's type is External, and that is the whole of it. There is no type picker on the record and none in the import queue, because a record either is a file you control or a document you wrote, and nothing in between is a useful distinction to make about a file somebody else issued. It shows the same word in the Governance list and on the record page, so "show me everything we didn't author" is one Type filter away. The row keeps its PDF badge, because what a thing is and what format it arrived in are different facts.
Its code says External too. A file uploaded from now on is coded EXT-{TEAM}-NNN, from the same per-team counter every other record draws from. Until 2026-08-09 it took the catch-all DOC- instead, so the row read External while its identifier claimed something else — the one place in the Governance list where the Type column and the code disagreed. Records uploaded before that keep the code they were given: a code is an address, published with the file at its first version and possibly already quoted in an audit, and re-issuing addresses to tidy a column is not a trade Alchex makes. If you would rather a specific old record carried an EXT- code, ask — it is a deliberate decision per record, not a sweep.
Spreadsheets take a different road entirely: an .xlsx or .csv becomes a register rather than a document, because a spreadsheet is already a table of records. Nothing on this page applies to those — they are not files under version control, they are rows.
In the import queue a PDF is labelled Becomes an External document where other files offer a type picker. Choose Import. There is no metadata dialog. Alchex creates the document immediately with sensible defaults:
| Field | Default |
|---|---|
| Title | The file name, without .pdf, trimmed to 120 characters if it is longer — click it in the path at the top of the record to rename it, the same way you rename any other document |
| Owner | You |
| Reference code | Minted automatically — EXT-{TEAM}-NNN |
| Status | Published as v1 — see There is no draft |
Uploading needs Author rights or higher on the team; the app refuses with Author role or higher required to upload documents. See Permissions.
Alchex checks the bytes, not the file extension. A renamed file that is not really a PDF is rejected with Not a valid PDF file, and anything over the size limit is refused before it is stored.
Your workspace's storage limit applies here too. An upload that would take you past it is refused before the file is stored, with a message saying the workspace is out of storage — so a refused upload costs you nothing and leaves your usage where it was. Deleting files gives the space back, and the storage meter on the billing screen shows where you stand. See Seats and licences.
The file is fixed, and provable
At upload Alchex records a SHA-256 fingerprint of the exact bytes and stores the file once, never overwriting it. The details panel shows:
- Type — External
- Version — which edition is in force, and the one the next publish will mint
- File — the file size and the first characters of the fingerprint, with Replace file beneath it
That fingerprint is the integrity anchor for every later approval of that version. It is what lets you say, years later, that the file an approver signed off is byte-for-byte the file readers are downloading.
Reading it
Instead of the editor, an external document opens a reader that fills the page. There is no card or frame around it — the document is the screen. The controls float over the paper in a single bar at the bottom: the page number, Zoom out / Zoom in, Fit width, and Focus mode, which takes the reader fullscreen so nothing but the page is left. Press Esc to come back.
The details panel is closed until you ask for it — use the panel button in the top right — so reading is the default and the metadata is the interruption, rather than the other way round.
Nothing sits above the document: the record's name is the last step of the path in the top bar, and clicking it there renames it in place — the same gesture as on an authored document.
If the file is slow to arrive you will see Loading file…; if something goes wrong, Could not load the file with a Retry.
Viewing links are short-lived by design — they expire after a few minutes, and the app quietly fetches a fresh one rather than handing out a permanent URL.
Review and publishing
External documents do not go through draft → submit → approve → publish; the upload is the publish (see There is no draft). What follows applies only to the review you can still ask for voluntarily on a record that has not published yet.
Three differences are worth knowing:
- The approver reviews the file, not a text diff. The approval screen shows the document itself. Where a version supersedes an earlier file, it names that file and its fingerprint, so the decision is recorded against a specific replacement.
- There is no change summary. Authored documents get an added / removed / modified block count. For a file, that number would be meaningless, so Alchex does not invent one.
- Nobody is asked whether the change was editorial or material. Authored documents carry that declaration, because their author knows whether they fixed a typo or changed a policy. You cannot fix a typo in a PDF somebody else issued — either the bytes are identical or they published a new edition. So the version is minted, not chosen.
There is no draft
An external document has no draft, because you did not write it. There is nothing for a draft to be a working copy of — the file was finished before it reached you.
So uploading publishes it. The record is v1 from the moment it arrives, and readers can see it. Replacing the file publishes the next edition the same way. There is no separate approval step, and nothing asks you to review your own upload.
That means the gate is the upload, not a second signature: bringing an external document in needs Author rights or higher, and whoever can bring one in can put it in front of readers. What makes it controlled is the record around it — who uploaded each edition and when, the fingerprint of every one, and the fact that no edition is ever overwritten or lost.
If you need a second pair of eyes on a supplier document before your organisation relies on it, that judgement belongs to the control or procedure that cites it — not to a publish button on a file whose author was never you.
Who can download which version
- The edition in force is available to anyone who can read the document — the published one, or, if a record somehow carries no published edition, the file it was born with. A reader is never left with nothing to download.
- Any earlier edition, and a replacement waiting for approval, additionally require Author rights. A plain reader who tries gets Only the version in force is available to you.
So a superseded file cannot be mistaken for the one in force by someone reading in good faith.
Replacing the file
When the issuer puts out a new edition, choose Replace file in the details panel and pick the new PDF. The record keeps everything that made it a record — its reference code, its owner, its approvals, its history. Only the file changes. (A voluntary review open on the record does not block this: the replacement lands as the next edition, while the reviewer keeps deciding on the file that was submitted.)
A new upload is a new edition, and you are never asked for a version number. An external document's version reads the same way as every other record's — v1, v2, v3 — but it only ever takes whole steps, because a file has no editorial half-step. Alchex mints the next one for you. One replacement is one step: the upload and the edition it publishes are a single act, so the count moves by exactly one however the file arrives. (Documents uploaded before August 2026 may show whole-number labels such as v2 in their history; those stay as issued, and the next replacement continues the count in the current form — v2 is followed by v3.)
Two things happen that are worth expecting:
- Uploading the same file again is refused. Alchex compares the fingerprint, not the filename, so re-uploading the PDF you already have gets This is the same file that is already here. Nothing to replace. It mints no version and records nothing, because nothing happened.
- Readers keep the published edition. A replacement lands in the draft. Until it is approved and published, everyone reading the document — and every download link — still resolves to the edition in force. Replacing is also refused while a review is pending — the submitter's own included: nobody swaps the file out from under an approver mid-decision. Withdraw the review to replace, then submit again.
Every edition's bytes are kept. Files are written once and never overwritten, so "what was in force last March" stays answerable, byte-for-byte.
The swap is named in the activity log as Replaced the file, against the edition it landed in — not as a general content edit. The line carries both fingerprints, the one that arrived and the one it replaced.
The editions live in one place: Version history, docked on the document's right edge. It lists every edition — its label, whether it is in force or superseded, who published it and when — plus the uploads behind them, including any that were replaced before they ever published, and every row carries a Download for that edition's exact bytes. The reader on the page always shows the edition in force; an earlier edition is retrieved through its Download rather than swapped into the reader, so the file on screen can never be mistaken for anything but the live one.
Replacing needs Author rights or higher — the same rung as uploading in the first place. If the document has been archived, restore it first.
Citing one
An external document is referenced exactly like a policy or a procedure: press / in any document, choose Mention, and pick External documents in the picker's rail. The chip that lands reads the record's name, resolves live, and carries the same aliveness dot every other reference does — archive the record and every sentence citing it goes red instead of quietly looking fine.
This is the only way a file gets into a document, and that is deliberate. The reference picker used to be able to import a file from your machine straight into the document you were writing. That file belonged to that one document: no owner, no code, no version, no approval, and no way to cite it from anywhere else. It looked like document control and was not. A file you want to point at goes here first — where it gets an owner, an EXT- code, editions and a fingerprint — and is then cited from every document that needs it. See References.
Related
- References — citing one from inside a document.
- Creating documents — the other path, for content you write yourself.
- Exporting documents — getting the original file back out.
- Version history — every uploaded file, in order.