Applying Security Rules in PageTiger
In this video tutorial, you'll learn how Security Rules work in PageTiger, the difference between options like Password Protection, Email Capture, Reader Login and Single Sign-On, and how to choose and apply the right one for your documents.
You Might Also Like
Creating AI-Powered Assessments in PageTiger
Delivering Learning Content to Your LMS
How to Create Your First PageTiger Document
What's been covered:
-
The difference between Basic and Advanced Security Rules, and how to choose the right one for different scenarios.
-
How to create and name a Security Rule from Documents > Settings > Security Rules.
-
How Password Protection, Email Capture, Reader Login, Employee Number, IP Address, Badge and Expected Visitor List options each work.
-
How to combine Security Rules - for example, pairing Password Protection with Email Capture, or Badge rules with Reader Login.
-
How to apply a finished Security Rule to a document, and how this feeds into your analytics and reporting.
Choosing and Applying the Right Security Rule
Whether you're sharing content with employees, customers or external audiences, Security Rules help ensure the right people can access your documents, while giving you the level of protection and tracking you need. Choosing the right Security Rule can improve both security and reporting, while creating a better experience for your readers.
Which Security Rule Should I Use?
Before creating a Security Rule, it's worth thinking about what you're trying to achieve:
-
I need a simple password: Password Protection is a quick, simple way to restrict access, best suited to situations where the audience is trusted.
-
I want to know who has viewed my document: Email Capture helps identify readers and improve reporting, but doesn't verify their identity.
-
I need readers to have verified accounts: Reader Login verifies a reader's email address and lets them create their own secure password, reducing the risk of unauthorised access.
-
Not every reader will have an email address: Employee Number lets readers identify themselves using an employee number or unique identifier instead.
-
My organisation already uses company authentication: Single Sign-On provides a seamless experience using your organisation's existing login system.
-
This document should only be viewed on our network: IP Address restrictions limit access to specific networks or locations.
-
I need readers to complete one stage of training before the next: Badge Security Rules are ideal for gated learning experiences.
-
I only want specific people to access this document: Expected Visitor Lists restrict access to a predefined group of approved readers.
Creating a Security Rule
All Security Rules are managed from one central location: click Documents, then Settings, then Security Rules. Give your rule a clear, descriptive name — a consistent naming convention makes ongoing administration much easier, especially if your account holds several rules.
Under the Details tab, you can also control Disable Search Engines, which determines whether search engines can index your document. All new Security Rules disable search engines by default; for public-facing content you may want to re-enable indexing, but for internal or confidential content it's usually best to leave it disabled.
Password Protection and Email Capture
Password Protection adds a shared password requirement before readers can access a document. Because passwords can be shared between readers, this option isn't recommended for highly confidential information, but works well for low-risk content or situations where you need a quick, easy way to limit access.
Email Capture asks readers to enter an email address before accessing a document, and can be set as required or optional. This is a great option when you want to understand who's engaging with your content, and the information is then associated with their activity for more meaningful reporting. It's worth remembering that Email Capture identifies readers but doesn't authenticate them — readers can still enter an email address that isn't their own.
For extra protection, Password Protection and Email Capture can be combined.
Reader Login and Employee Number
Reader Login authenticates readers using their email address and lets them create their own secure password. It can also be configured to allow or deny access based on specific email addresses or domains, giving you a more secure and accountable way to protect content.
Employee Number requires readers to identify themselves using an employee number before accessing content — particularly useful for organisations that already use employee numbers, or where readers may not have an email address, such as warehouse employees or drivers.
IP Address, Badge and Expected Visitor List
IP Address restrictions limit access to specific networks or locations, useful when content should only be available from a company office or secure network — you may need support from your IT team to identify the correct addresses.
Badge Security Rules restrict access based on whether a reader has been awarded a badge in a previous document, ideal for gated learning and multi-stage training programmes. Because badges need to be awarded to a known reader, Badge rules must be paired with Reader Login, Employee Number or Single Sign-On.
Expected Visitor Lists (EVLs) allow you to define exactly who should have access to a document — only readers on the approved list can gain entry, and multiple lists can be applied to the same Security Rule. This is particularly useful for events, compliance activities or communications intended for a specific audience, and EVLs are designed to work alongside Reader Login, Employee Number or Single Sign-On.
Applying a Security Rule to a Document
Once you've created your Security Rule, open the Document Dashboard, select the Security Rules tab, and choose the appropriate rule from the dropdown list.
Delivering Content to Your LMS with Dynamic SCORM
Once your document is secured, see how to deliver it through your LMS with Dynamic SCORM.
FAQs
What is a Security Rule in PageTiger?
A Security Rule controls who can access a PageTiger document and how they're identified or authenticated before viewing it, ranging from a simple shared password through to verified logins and network restrictions.
What's the difference between Email Capture and Reader Login?
Email Capture asks readers to enter an email address to identify themselves, but doesn't verify it. Reader Login authenticates readers using their email address and a password they create, offering a more secure and accountable option.
Can I combine multiple Security Rule options?
Yes. For example, Password Protection can be combined with Email Capture for extra identification, and Badge Security Rules can be paired with Reader Login, Employee Number or Single Sign-On.
Which Security Rule should I use if not all my readers have an email address?
Employee Number is a good option here, letting readers identify themselves using an employee number or other unique identifier instead of an email address.
How do Badge Security Rules work?
Badge Security Rules restrict access based on whether a reader has already been awarded a badge in a previous document, making them well suited to gated, multi-stage learning journeys.
What is an Expected Visitor List?
An Expected Visitor List (EVL) restricts document access to a predefined group of approved readers, checking their details against the list when they try to access the content.
Will my document be indexed by search engines?
By default, all new Security Rules disable search engine indexing. You can change this under the Details tab of your Security Rule, depending on whether your content is public-facing or internal.
Where do I apply a Security Rule once I've created it?
Open the Document Dashboard, select the Security Rules tab, and choose the relevant rule from the dropdown list.