Appearance
Configure security
Use Settings > Security & Access to apply form-wide access, anti-abuse, file-access, and geographic controls.
Example: protect a partner-only upload form
- Open Settings > Security & Access.
- Keep Captcha enabled unless there is a reviewed reason to disable it. Choose the checkbox mode only when that is the approved experience and the reCAPTCHA account configuration supports it.
- Enable Authentication required when every respondent must be authenticated; test the unauthenticated and authorized paths.
- Configure Password protection only when there is an approved password distribution and rotation process.
- Choose the submitted-file access policy. If using password-protected file access, set and securely retain the password through the provided password action; do not document or share the password in the form.
- Configure allowed or forbidden countries only when the restriction is legally or operationally required. Test from a permitted and a blocked location where feasible.
- Decide whether Allow PDF submit is needed, then test it before production.
- Review any form-sharing configuration with the people who own access decisions.
Expected result
Access controls reflect an approved policy, do not accidentally block legitimate respondents, and are tested separately from ordinary field validation.