Back to BlogData Rooms

How to Set Up a Data Room: Step-by-Step (Web and CLI)

Mage
Mage TeamLegal AI Experts
|
·11 min read

Key Takeaways

  • The software half of setup takes an afternoon. Collecting the documents takes one to three weeks, so start the request list before you create the room.
  • Do not hand-build folders in a browser. Either mirror the request list on disk and push the tree up, or upload everything and let the room organize and number it.
  • Permission by recipient, not by password. One link per person, scoped to the whole room, one folder, or a single document, with printing gated separately from download.
  • A flagged gap beats a silent hole. Mark a document you cannot produce as missing, name an owner, and give a date. Buyers find the hole either way.
  • If your files already sit in an organized folder tree, the command line path is two commands and mirrors that tree exactly, which beats dragging 5,000 files into a browser.

How do you set up a data room? Create the room, get every document into it, let it organize and index itself, then invite viewers one at a time with the permissions each one needs. The software half of that takes an afternoon. Collecting the documents takes one to three weeks, and that is the half that decides whether the room is any good.

Most guides to this question describe only the second half: define your purpose, build folders, configure settings, bulk upload, set permissions, invite users, turn on tracking. That sequence is accurate. It is also not where the time goes. This guide runs the whole path in order, browser first, then the command line for teams whose documents already sit in a structured folder tree on disk. If you are still deciding whether you need a dedicated room at all, start with what a virtual data room is and come back.

How long does setting up a data room actually take?

Three phases, and only one of them is software.

Collection: one to three weeks. The documents are not in one place. The cap table lives with finance, the offer letters with HR, the customer agreements in a CRM and in three inboxes, the lease with whoever signed it. Every one of those handoffs is a person who has a day job. This is the phase every setup guide skips and every deal team underestimates.

Population and structure: an afternoon. Uploading, classifying, organizing, and indexing is the fastest part of the process now, whether you drag files into a browser or push a directory from a terminal.

Review and first invite: half a day. Reading what landed, deciding what is genuinely missing, and issuing the first scoped links.

The failure mode is running these in sequence. Start collection the day you decide to run a process, and create the room the same day, so documents can land as they arrive instead of piling up in a shared drive waiting for a big-bang upload.

What do you do before you upload anything?

Three decisions, all of them made away from the software.

Start from the request list, not from a folder template. The list is the thing you will be graded against, so it should drive collection. A financing and a sale ask for different things: an investor's counsel wants the corporate stack, the cap table, and the commercial agreements that support the story; an acquirer's counsel wants everything the investor wants plus the liabilities. A Mage data room carries a readiness checklist keyed to the room's transaction type, so a fundraising room grades itself against what a venture investor's counsel requests and a sale room against what an acquirer's counsel requests. If you are raising, our investor data room checklist is the list to work from.

Assign an owner to every workstream. Corporate and cap table, commercial contracts, people and benefits, IP, tax, financing, real estate, litigation. Write a name next to each one, not a department. The single most common reason a room sits at eighty percent for two weeks is that nobody actually asked the person who has the files.

Decide your disclosure tiers now. Most sale processes run at least two. Stage one is what a bidder sees before a shortlist: financials, corporate structure, redacted or summary-level commercial terms. Stage two opens after you have narrowed the field: full customer agreements, employee-level compensation, IP assignments, litigation files. Deciding the split before you populate is easy. Deciding it after you have already sent links is not.

How do you decide folder structure before you have the documents?

You do not, and you should stop trying. Hand-building an empty folder tree in a browser is guesswork about documents you have not seen, and it is the reason so many rooms end up with a half-empty "Other" folder and three places a stock purchase agreement could reasonably live.

Two approaches actually work.

Mirror a structure that already exists. If your files sit in an organized directory on a machine or a shared drive, that tree is a real structure that survived contact with the documents. Push it up as it stands and adjust afterward.

Upload everything, then let the room structure itself. Mage organizes a room in one pass: a single agent chooses the folder structure and places every document, which is what keeps folder naming consistent across the whole room instead of drifting as documents trickle in. Every folder and every filed document then gets a stable dotted index number (1, 1.2, 1.2.3) in the Index column, and the index exports to XLSX for the deal file. One limit worth knowing before you send anything: a document sitting outside any folder is deliberately left unnumbered until it is filed, so an unsorted pile is visibly unsorted rather than quietly numbered into the index.

For naming conventions, tier design, and what a reviewing partner is actually looking for when they open the tree, see how to organize a data room. This guide stays on setup mechanics.

Setting up the room in a browser, step by step

1. Create the room. Mage Data Room is self-serve from the data room product page with no lead form, and it is free for a limited time. Set the transaction type when you create the room, since that selects which readiness checklist the room grades itself against.

2. Get the documents in. Four paths, and you can mix them:

  • Drag in loose files or whole folders. Folder structure comes with them.
  • Drop a ZIP archive, including a ZIP export from another data room.
  • Connect Google Drive, OneDrive, Dropbox, or Box and choose a folder. Imports from SharePoint and Bookface are coming soon.
  • Connect Common Paper to bring in executed agreements as PDFs.

Do not clean up the files first. Getting everything in and sorting afterward is faster than sorting before, and a document you cannot see is a document nobody can gap-check.

3. Let the room classify and organize. Each upload is classified by document type and summarized in a sentence or two. The organizing pass then places everything. Amendments, exhibits, and side letters get linked to the agreement they belong to, which is the relationship a reviewer would otherwise reconstruct by hand.

4. Read the readiness checklist. The room grades itself item by item: present, partial, missing, or not applicable. Partial usually means a multi-document item where something is attached but the set does not look complete, which is exactly the category worth a human minute.

5. Fill the gaps. For anything still outstanding, send a document request to the teammate who owns it. Requests here are internal, aimed at your own team. There is no counterparty portal and no client login, deliberately.

6. Invite the first viewers. Covered next, because it deserves its own section.

How do you permission bidders, advisors, and auditors differently?

By issuing a different link to each of them. Mage mints one personalized link per recipient rather than one shared link everyone passes around, and each link carries the recipient's identity, an optional audience label (investor, third party, advisor, or custom), and its own settings.

The settings that matter for a real process:

  • Scope. A link points at the whole room, one folder and everything nested beneath it, or exactly one document. Folder links are bound to a stable folder id rather than a path, so renaming or moving the folder does not break the link, and a folder that no longer resolves yields nothing rather than falling back to something broader.
  • View or download. Download is off by default. Printing is gated independently, also off by default, because print to PDF is a download wearing a hat.
  • Expiry and revocation. Set an expiry timestamp on the link, and revoke instantly when a bidder drops out. Revocation is read fresh on every request.

That model is what makes staged disclosure practical. Stage one is folder-scoped links to the early bidder set. Stage two is a room-scoped link issued to the shortlist. Because links are per recipient, opening tier two means issuing new links to a subset, not re-permissioning a link that half the market already holds.

Every page a guest views carries a dynamic watermark with their identity, the date, and CONFIDENTIAL. Be clear with yourself about what that does: it is a deterrent and an attribution tool, not an access control. It does not stop anyone from photographing a screen. What it does is guarantee that any page that leaves already carries the name of the person it was served to.

You also get the other side of that: which invitees opened the room, which documents they read, and how far through each one they got, with your own team's page views excluded so internal activity never inflates the signal. Analytics are owner and admin only.

Should NDA gating happen inside the room or before it?

Both, and they answer different questions.

The negotiated NDA governs the relationship and is signed before the process starts. The in-room gate governs the individual open: the specific human who clicked through, on the specific date, before reaching the documents. In Mage the gate is on by default on every link. You can supply your own NDA text, upload an NDA PDF to display at the gate, or use the default template, and you can require a countersigned PDF that captures the accepted terms, the signer, and the audit metadata as a stored record both sides can see.

The distinction to hold onto: a click-through gate is an identification and acknowledgment mechanism. It is not a substitute for counsel negotiating an NDA, and nobody should treat it as one.

What do you do about documents you cannot find?

Flag the gap. Always.

The instinct is to leave the hole quiet and hope the section reads as complete. It does not. Diligence counsel works from a request list, notices that item 4.3 has no response, and now has two questions instead of one: where is the document, and what else is missing that they have not spotted yet.

A labeled gap costs you one line. Mark the item missing with an owner and a date, or mark it not applicable when it genuinely does not apply, which removes it from the readiness score rather than leaving it as a permanent red mark. A room that says "we do not have signed copies of four 2019 offer letters, HR is reconstructing them, expected Friday" reads as a team in control of its own file. A room with four silent blanks reads as something else.

The CLI path: when the files are already organized on disk

If your diligence documents already sit in a structured directory, the browser is the slow option. At 5,000 files across nested folders, drag and drop is a bad interface and everyone using it knows it.

Mage publishes a command line client for the data room. From zero it is two commands:

npx @magelegal/cli login
npx @magelegal/cli upload ./diligence

login opens a browser, you confirm a short code, and the CLI mints its own room-scoped API key that shows up in the room's API key settings. It requires Node.js 20 or newer, and credentials are stored locally at ~/.config/mage/config.json with permissions readable only by you.

upload mirrors the local structure into the room. A directory reproduces its contents beneath it, transfers run in parallel, dotfiles like .DS_Store are skipped, and each document begins processing the moment it arrives rather than after the batch finishes. Push a file into a named folder with --to "Corporate", and the folder is created if it does not exist.

The rest of the surface is what you would expect from a file client: mage ls to list documents by folder, mage mkdir to create a folder, mage readiness to print what is present, partial, and missing, mage download to pull the room or a folder back down with the structure intact, and mage rm to delete, where deleting a folder moves its documents to Unsorted rather than destroying them.

Two things worth stating plainly. The CLI covers the data room only; Mage's diligence platform has no command line surface. And every command accepts --json, which is what makes the same path usable by an AI agent rather than a person. The full command reference lives in our data room CLI guide.

What to check before the first link goes out

Five minutes, in this order:

  1. Nothing stranded. Anything sitting outside a folder is unnumbered and effectively invisible in the index. File it or delete it.
  2. The checklist has been read by a human. Present, partial, missing, not applicable. Partial items are where the surprises live.
  3. Scope, on your own invite. Open the link you are about to send and confirm it shows exactly what you intended and nothing adjacent.
  4. Download and print, deliberately set. Both off unless you have a reason, and the reason should be a named person, not a habit.
  5. Expiry set on anything time-boxed. A link to an auditor for a two-week review should not still be live in March.

Then send. Setup is not a one-time event; a live process adds documents every week, and the point of getting the structure and permissioning right up front is that additions land into a shape that already works.

More on running the room once it is populated, and on the rest of the deal preparation stack, in our data rooms topic hub.

Frequently Asked Questions

How long does it take to set up a data room?

The software is an afternoon. Creating the room, uploading, letting it organize, and issuing the first invites is a few hours of real work. Collecting the documents is one to three weeks for most companies, because the files sit with finance, HR, and sales operations rather than with counsel. Plan the calendar around collection and treat the room itself as the easy part.

What folders should a data room have?

Mirror the request list you were sent rather than a generic template. A typical top level covers corporate and governance, capitalization, financing, material contracts, people and benefits, intellectual property, tax, real estate, and litigation. If you are not sure, upload everything first and let the room organize itself in one pass, then adjust the two or three folders you disagree with.

Do I need an NDA before giving someone data room access?

You need both a negotiated NDA for the process and a gate on the link itself. The signed NDA governs the relationship. The in-room click-through gate identifies the specific human who opened a specific document, which is what you want when a document turns up somewhere it should not. In Mage the NDA gate is on by default on every link, and you can require a countersigned PDF that lands in the audit trail.

Can you upload a whole folder to a data room at once?

Yes. Drag a folder into the browser and its structure comes with it, drop a ZIP archive, or connect a cloud drive and select a folder. If the tree already exists on disk and is large, the command line is faster: one upload command mirrors the local structure into the room and runs the transfers in parallel.

What should you do about a document you cannot find?

Flag it. Mark the checklist item missing, put a name and a date on it, or mark it not applicable if it genuinely does not apply. A labeled gap reads as control of the process. A silent hole in an otherwise complete section reads as concealment, and diligence counsel finds it either way, usually at the worst moment.

data-roomsdata-room-setupdue-diligencefundraisingdeal-preparation

Ready to transform your diligence?

See how Mage can help your legal team work faster and more accurately.

Contact Us

Related Articles