Source: https://vaultcrmhelp.veeva.com/doc/Content/CRM_topics/Multichannel/ApprovedEmail/SendAE/SecureMessage.htm

## Sending Secure Messages via Approved Email

To ensure sensitive content remains secure and is not forwarded to unauthorized recipients, end users can send Approved Emails containing secure links, requiring HCPs to sign into a customer’s My Engage Portal using VeevaID in order to view the content. This allows customers to provide a branded experience for viewing sensitive content, track HCP engagement with the content, and ensure the content is not combined with content from other organizations.

**Who can use this feature?**

* Content Admin Users — Browser
* [Creating Secure Messaging Templates](#Saving)
* End Users — Browser, iPad, iPhone
* [Sending Secure Messages](#Sending)
* HCPs — Browser
* [Viewing Secure Messages](#Viewing)
* Users require an Approved Email license

### Configuring Secure Messaging via Approved Email for

[![Closed](../../../../../Skins/Default/Stylesheets/Images/transparent.gif)Integration Users](#)

To configure this feature:

1. Ensure [Configuring Approved Email Admins and Integration Users](../ConfiguringAE/AEConfigAdmins.htm) is complete.
2. Navigate to **Admin > Users & Groups > Permission Sets**.
3. Select the appropriate permission set for the Approved Email Integration User.
4. Select the **Application** tab.
5. Navigate to **Vault Owner Actions > All Object Records**.
6. Enable **All Object Record Read** access.
7. Select the **Objects** tab.
8. Grant the following permissions:

   | Object | Object Permission | Object Types | Fields | Field Permission |
   | --- | --- | --- | --- | --- |
   | account\_\_v | R | All applicable object types | assigned\_engage\_portal\_\_v | Read |
   | approved\_email\_settings\_\_v | R | n/a | enable\_secure\_messaging\_\_v | Read |
   | approved\_document\_\_v | R | secure\_message\_notification\_template\_\_v | * is\_secure\_message\_\_v * notification\_template\_\_v * notification\_template\_status\_\_v | Edit |
   | engage\_portal\_\_v | R | n/a | * id * engage\_portal\_status\_\_v | Read |
   | sent\_email\_\_v | R | All applicable object types | secure\_message\_notification\_content\_url\_\_v | Edit |
   | secure\_message\_notification\_template\_\_v | Read |
   | user\_sys | R | n/a | * id * status\_\_v * first\_name\_\_sys * last\_name\_\_sys * name\_\_v * email\_\_v * title\_\_v | Read |
   | user\_detail\_\_v | R | user\_detail\_\_v | * id * digital\_business\_card\_display\_name\_\_v * digital\_business\_card\_first\_name\_\_v * digital\_business\_card\_last\_name\_\_v * digital\_business\_card\_email\_\_v * digital\_business\_card\_phone\_\_v * digital\_business\_card\_photo\_url\_\_v * digital\_business\_card\_title\_\_v * user\_\_v | Read |
9. Navigate to **Business Admin > Objects > Approved Email Settings**.
10. Select the appropriate **Approved Email Settings** record for the integration user.
11. Select the **Enable Secure Messaging** Approved Email Setting checkbox.

[![Closed](../../../../../Skins/Default/Stylesheets/Images/transparent.gif)End Users](#)

To configure this feature:

1. Ensure the following are configured:

* [Configuring Approved Email](../InitialConfig/ConfiguringAE.htm)
* [My Engage Portal](../../Engage/MyEngagePortal.htm)

1. Complete portal setup, as detailed in [My Engage Portal](../../Engage/MyEngagePortal.htm):
2. Create and deploy a portal with the Inbox feature enabled
3. Assign the appropriate accounts to the portal
4. Navigate to **Admin > Users & Groups > Permission Sets**.
5. Select the appropriate permission set.
6. Select the **Objects** tab.
7. Grant the following permissions:

   | Object | Object Permission | Object Types | Fields | Field Permission |
   | --- | --- | --- | --- | --- |
   | account\_\_v | CRE | All applicable object types | * assigned\_engage\_portal\_\_v * assigned\_engage\_portal\_domain\_\_v | Read (optional) |
   | approved\_email\_settings\_\_v | R | n/a | enable\_secure\_messaging\_\_v | Read |
   | approved\_document\_\_v | R | secure\_message\_notification\_template\_\_v | * is\_secure\_message\_\_v * notification\_template\_\_v * notification\_template\_status\_\_v | Read |
   | email\_activity\_\_v | RE | secure\_message\_notification\_activity\_\_v | All fields | Read (optional) |
   | sent\_email\_\_v | RE | n/a | secure\_message\_notification\_template\_\_v | Edit |
   | * notification\_clicked\_\_v * notification\_click\_count\_\_v * notification\_last\_click\_date\_\_v * notification\_opened\_\_v * notification\_open\_count\_\_v * notification\_last\_open\_date\_\_v | Read (optional) |
8. Navigate to **Business Admin > Objects > Approved Email Settings**.
9. Select the appropriate **Approved Email Settings** record.
10. Select the **Enable Secure Messaging** Approved Email Setting checkbox for end users who need access to secure messaging.

If end users who are not enabled for secure messaging are aligned to secure message email templates, ensure those end users are also granted the permissions outlined above. This enables Vault CRM to filter out secure message email templates so the end user does not accidentally try to send them.

### Creating Secure Messaging Templates as

[![Closed](../../../../../Skins/Default/Stylesheets/Images/transparent.gif)Content Admins](#)

Content admins can create secure message templates in PromoMats to sync to Vault CRM.

To create a secure message template:

1. Create an **Email Template** document for the email containing the secure link.
2. Select **Secure Message Notification Template** from the Email Template Type picklist.
3. Include the **{{secureMessageLink}}** token in the body of the template HTML. This token must be wrapped in anchor tags in order to generate a clicked [Email Activity](../ReportAE/TrackingActivity.htm). For example: <a href="{{secureMessageLink}}"></a>
4. Create another Email Template document and populate it with the sensitive content to display in the portal.
5. Select **Relationships** in the menu on the right.
6. Add a **Related Secure Message Notification** referencing the Secure Message Notification Template you just created.
7. Approve both Email Templates.

If using [content alignment](../../CLM/ManagingContent/ContentAlignment.htm) for Approved Email, both Email Templates must be aligned to the end users who send the secure message.

After syncing the Approved Email integration, approved\_document\_\_v records are automatically created for the templates with the is\_secure\_message\_\_v field populated appropriately.

### Sending Secure Messages as

[![Closed](../../../../../Skins/Default/Stylesheets/Images/transparent.gif)End Users](#)

End users can send secure messages to HCPs to allow them to access sensitive content in My Engage Portal.

To send a secure message:

1. Navigate to **Approved Email** from one of the following supported entry points:

* Account
* Call
* Email-type Suggestions
* CLM (via the launchApprovedEmail method)
* Medical Inquiry

1. Select an **email template** displaying the secure email icon.
2. Preview the message to ensure the secure message banner displays.
3. Select **Send**.

Secure messages display on [account timelines](../../../Timeline/Config.htm) as Sent Email (Secure Message) entries.

If the selected account is not assigned to a portal or their assigned portal has not been deployed, the email will not be sent. See [Assigning Portals to Accounts](../../Engage/MyEngagePortal.htm#Assignin) and [Deploying Portals](../../Engage/MyEngagePortal.htm#Deployin) for more details.

### Viewing Secure Messages as

[![Closed](../../../../../Skins/Default/Stylesheets/Images/transparent.gif)HCPs](#)

When HCPs are sent a secure message, they can select the link in the notification email to launch the portal in the browser. The branding settings of the portal are determined by the portal assigned to the HCP’s account.

HCPs must verify their identity using VeevaID. The registration process allows them to choose an email and password, which can then be used to access the portal directly going forward.

If the email chosen for VeevaID does not match the account email address to which the secure message was sent, an additional verification step is required. The HCP will receive a confirmation code sent to the account email address to ensure the secure message is not being accessed by an unintended recipient.

After logging in, HCPs can select the Inbox tab in the navigation menu and select the appropriate message to view the sensitive content. In addition to secure messages, the Inbox also includes any Sent Emails that have been successfully delivered from the past 365 days. This provides the HCP with an easy way to review all correspondence received from users for a given Vault in one place.

#### Tracking Secure Message Activity

Email activity records are created for both the secure message notification and the sensitive content in the portal under a single Sent Email record. The following activities are tracked:

| Email Activity Type | Activity | Description |
| --- | --- | --- |
| Secure Message Notification Activity | Delivered (delivered\_\_v) | The secure message notification has been marked as Delivered by Mailgun. |
| Secure Message Notification Activity | Opened (opened\_\_v) | The recipient opened the secure message notification in their email client. Mailgun tracks Opened events based on an image in the email rendering in the recipient's email client, usually a 1x1 pixel transparent image. If the recipient opens the email, the image downloads from the sending server, indicating the email is opened. |
| Secure Message Notification Activity | Clicked (clicked\_\_v) | A link in the notification email is selected, for example, the resolved portal link from {{secureMessageLink}}) |
| Email Activity | Opened (opened\_\_v) | The recipient signed into the portal and viewed the sensitive content. Content must be fully rendered before an activity will be generated. |
| Email Activity | Clicked (clicked\_\_v) | A link in the email is selected. |

The tracking\_source\_\_v field on all Email Activity records generated via Approved Email is set based on the source of the activity. For example:

* Email Activities related to delivery, opens, and clicks for the secure message notification have the source set to mailgun\_\_v
* Email Activities related to opens and clicks for the sensitive content inside of the portal have the source set to my\_engage\_portal\_\_v

Sent Email records split out activities related to the secure message notification from those related to the sensitive content. The following fields automatically roll up information from child Email Activity records for easy reporting on the opens and clicks for the secure message notification:

* notification\_clicked\_\_v
* notification\_click\_count\_\_v
* notification\_last\_click\_date\_\_v
* notification\_opened\_\_v
* notification\_open\_count\_\_v
* notification\_last\_open\_date\_\_v

The following fields automatically roll up information from child Email Activity records related to opens and clicks of the sensitive content inside of the portal:

* clicked\_\_v
* click\_count\_\_v
* last\_click\_date\_\_v
* opened\_\_v
* open\_count\_\_v
* last\_open\_date\_\_v

For more information on tracking, see [Tracking Approved Email Activity](../ReportAE/TrackingActivity.htm).

### Related Topics

[My Engage Portal](../../Engage/MyEngagePortal.htm)

[Email Tab](ApprovedEmailTab.htm)
