The One-Link Work Sample Portfolio for Non-Portfolio Roles
You will assemble three to five sanitized work samples into one shareable link that backs your resume claims without exposing confidential data or building a website.
Key takeaways
- Every portfolio guide written for a specific application lands at 3 to 6 samples; the 10 to 20 counts describe a standing showcase, not a targeted apply.
- Work-sample tests predict job performance at r = .54 in Schmidt and Hunter (1998), versus .18 for years of experience and .10 for education, so a sample supplies the strongest resume-independent signal.
- The dangerous confidentiality leak is invisible: hidden rows, hidden sheets, author names, and revision history travel with a spreadsheet even after you black out the cells on screen.
- In Refolk's index there are 312,715 Operations Managers and roughly 65,000 each of Data and Financial Analysts in the US, so a sanitized sample is one of the few signals that separates you from a very deep pool.
- The hard part of hosting is a 15-minute permissions test, not design: open the link in a logged-out window and confirm view-only access with no login.
- A black box drawn over PDF text leaves the text selectable underneath; only a true Sanitize operation removes it, so test by trying to copy-paste the redacted region.
If your work is spreadsheets, decks, models, and processes rather than visuals, you have probably skipped the portfolio question entirely. Existing guides are written for designers or steer you into an AI website builder, and neither fits an analyst, operations manager, finance professional, marketer, or PM. This guide is an evidence-selection and sanitization procedure: it starts from work you have already done and ends at one shareable link you can drop into an application, without exposing confidential material and without building a website.
The job here is narrow and finishable. You will pick three to five artifacts, strip the confidential and the invisible out of them, frame each on a page a reviewer can read in under a minute, host them behind one URL, and prove that URL opens for an outsider. That is the whole deliverable.
Why a work sample matters more in a non-portfolio field
A sanitized work sample is a cheap stand-in for the single strongest signal a hiring process can collect, and most of your competitors never supply it. In the Schmidt and Hunter (1998) meta-analysis, work-sample tests predict job performance at operational validity r = .54, while years of experience predict at roughly .18 and education at roughly .10. The resume leans on the two weakest predictors in that study. A sample lets you hand over the strongest one before anyone asks.
The rarity is the point. Employers who use samples typically request them only from their top three or four candidates, and only a minority of organizations use the method at all. Offering a defensible, pre-sanitized sample unprompted does two things at once: it gives the reviewer the high-validity signal early, and it signals that you understand what actually predicts performance.
Supply scale is the other half of the argument. In Refolk's index of professional profiles, the non-creative roles that rarely use portfolios are exactly the deep pools where a differentiator earns its keep.
How deep is the pool you are competing in
| Role | Profiles (US) | vs Data Analyst |
|---|---|---|
| Operations Manager | 312,715 | 4.79x |
| Data Analyst | 65,231 | 1.00x |
| Financial Analyst | 65,165 | 1.00x |
Source: role counts from Refolk's index [OURS]; the "vs" column is derived as role count divided by the Data Analyst count.
With more than 300,000 Operations Managers and roughly 65,000 each of Data and Financial Analysts in the US index, a resume alone is one of tens of thousands. A sample is one of the few resume-independent things that moves you out of the pile.
Where you apply changes the math. The same title competes against a far thinner pool in the UK.
| Market | Profiles | US multiple |
|---|---|---|
| United States | 65,231 | 3.99x |
| United Kingdom | 16,357 | 1.00x |
Source: counts from Refolk's index [OURS]; the multiple is derived as US divided by UK.
The UK pool for Data Analyst is close to four times thinner than the US pool, so the marginal value of a strong sample rises where supply is scarce. The artifact is worth building anywhere; it is worth building most where fewer peers bother.
How many samples, and which ones
Three to five, chosen for relevance to the specific job, starting and ending with your strongest work. The guidance that says ten to twenty is describing a standing showcase you maintain over a career. Every source framed around an actual application converges much tighter.
The split in the advice is not a contradiction; it is two different jobs.
- Standing showcase: 10 to 15, even 10 to 20 samples, to represent breadth over time. This is a personal site you tend, not an application attachment.
- Targeted application: 3 to 6 strong samples by one source, 2 to 4 projects by seniority in another, 3 to 4 framed pieces in a non-design guide. For this playbook's single-application use case, 3 to 5 is the operative number.
The selection test is not "is this impressive" but "does this show how I think, and does it map to this role." A financial model you built, a dashboard you shipped, an SOP you wrote, a memo that changed a decision - almost anything you produced that demonstrates reasoning counts. A piece that cannot be tied to a requirement in the posting goes, no matter how proud you are of it.
A portfolio is a sampling, not an archive. Give a general idea without committing a reviewer to hours of reading.
The one-page frame every piece needs
Each sample carries a consistent one-pager so a reviewer never has to reconstruct the context. The frame is problem, your role, tools, outcome, applied the same way to every piece. Consistency is what lets someone skim five artifacts in the time it takes to read one.
Overview: One or two sentences on what the project was and why it existed. My role: The specific thing I did. Not "the team" - what I owned. Timeline: Rough duration or period, e.g. "six weeks" or "one reporting cycle." Tools or systems: The stack, e.g. SQL, Excel, the modeling or BI tool used. Constraints: Anything a reviewer should know, e.g. NDA, so metrics are ranged. Outcome: The measurable result. A metric, a decision changed, feedback received. What I would do differently: One honest line of reflection.
One of these per artifact. Keep it to a single page. Use ranged or relative metrics where absolute figures are restricted.
Two fields carry more weight than the rest. The role line stops a team artifact from reading as borrowed credit; without an explicit "what I did," a shared deck looks like you are claiming someone else's work. The outcome line has to be defensible in an interview, so use ranges you can stand behind rather than a precise percentage you cannot source. "Cut reconciliation time by roughly a third" survives a follow-up question; a suspiciously exact figure invites one you cannot answer.
For confidential cases, the fuller frame adds context, objectives, constraints such as an NDA, your approach, the decisions you made, and lessons learned. The reviewer wants to see the form, template, or checklist you created, not the data it once contained.
The sanitization procedure, start to finish
This is the whole method in order. Each step names how long it takes and what "done" looks like, so you can run it without improvising. The sanitize and host steps are where portfolios in non-creative fields actually fail, so they get the most attention below.
From existing work to one tested link
- Inventory your existing outputPull every deck, spreadsheet, model, process doc, dashboard, and memo you produced into one list. Keep anything that shows how you think. Done when you have 10 to 15 candidate artifacts named in one place. (1 to 2 hrs)
- Select 3 to 5 and cut the restMap each candidate to a target-job requirement and keep the strongest that cover different skills, best piece first and last. Done when you have a shortlist of 3 to 5 tied to the posting. (1 hr)
- Get permission where neededFor client or employer work, ask to show a sanitized version, not the whole file. Done when you have explicit or clearly implied clearance for each piece. (1 to 3 days wait)
- Sanitize each artifact on a copyRemove, replace, or redact PII and proprietary data, then run Document Inspector on Office files and Sanitize Document on PDFs. Work on a copy, since Remove All is partially irreversible. Done when the re-opened cleaned file has no PII, no proprietary data, and no hidden metadata. (30 to 60 min each)
- Write a one-page frame for eachAdd overview, your role, timeline, tools, and an outcome metric. Use ranged metrics where absolute figures are restricted. Done when every piece has problem, role, tools, and a defensible result. (30 min each)
- Assemble into one hostIndex the sanitized files on one Notion page or Google Site, or combine them into one structured PDF deck. Done when every piece is reachable from one URL. (1 to 2 hrs)
- Set and test sharingPublish to web or set Anyone-with-link, make it view-only, optionally set an expiry, then open it in a logged-out incognito window. Done when it loads view-only with no login prompt. (15 min)
- Add the link and keep it currentPut the link on your resume and profile and re-test it the week you apply. Replace stale pieces over time. Done when the link is live and verified fresh. (ongoing)
Sanitizing without leaving a trail
The redaction you can see is the easy half. Remove, replace, or redact every identifiable value a reviewer does not need, because they want the structure of what you built, not the data it once held. Trade secrets, internal financial figures, unreleased product details, and any PII come out.
The half that sinks people is invisible. Hidden rows, hidden sheets, author names, revision history, and external data connections all travel with a spreadsheet when you send it. A black-out on screen does nothing about any of them.
Clean-up pass per artifact
- DuplicateCopy the file so the original and its history stay intact.
- Redact visibleRemove or replace PII and proprietary values in the cells and text.
- Strip hiddenRun Document Inspector (Office) or Sanitize Document (PDF) to clear metadata, hidden sheets, and revision history.
- VerifyRe-open the exported copy and try to select or copy redacted regions.
The documented tools are built in. For Office files, use Document Inspector: File, then Info, then Check for Issues, then Inspect Document, then Remove All for the categories you want cleared. For PDFs, Acrobat Pro's Sanitize Document and Remove Hidden Information strip metadata, hidden text, comments, form data, and attachments. A free cross-platform option, exiftool, removes metadata from the command line if you do not have Acrobat.
Getting permission without over-asking
Where work belongs to a client or employer, ask for permission to use a sanitized version as a sample. They may ask you to redact sensitive information, which is exactly what you are doing anyway. Frame the ask narrowly: you want to show the structure of a deliverable with the data removed, not publish anything proprietary. For NDA-bound work that cannot be shown at all, build a shadow version - the same template or process rebuilt with invented data - and label it as such.
Where to host it, and the only hard part
Host it as a single simple link and treat it as a supplement to the resume, not a design project. A free Notion page, a Google Site, or one structured PDF deck all work. For non-creative roles, clarity and ease of access beat anything visual. The genuinely hard part is not building pages; it is getting the sharing permissions right so an outsider can actually open the link.
| Format | Default access | No-login viewing | Link expiry |
|---|---|---|---|
| Notion published page | Private by default | Yes, when published to web | Yes (Plus plan) |
| Google Drive folder | Restricted by default | Yes (view) with Anyone-with-link | Time-limited access available |
| Single PDF deck | N/A (file) | Yes (attach or host anywhere) | Only via host |
Source: Notion sharing help; Stanford Drive guide; NC State OIT (time-limited access); Notion expiry via published guidance.
Both of the page-based hosts start closed. Notion pages are private by default and must be manually published: open Share, General access, and choose Anyone on the web with link; you can set the link to expire via the Link expires dropdown on a paid plan. Google Drive links default to Restricted, so you must switch to Anyone with the link, which lets any viewer open the file without a Google account. Note the documented caveat on Drive: these controls are not foolproof, since editors can copy files and anyone with access can photograph a screen - keep access to view-only and keep genuinely sensitive data out entirely.
How this goes wrong
The failure modes cluster in two places: confidentiality that passes a visual check but not a real one, and sharing settings that block the reviewer or expose the file. Both are catchable before you send. Here is what each looks like and how to test for it.
| Failure mode | What it looks like | How to catch it |
|---|---|---|
| Metadata leak | File looks clean on screen; author name, hidden sheets, and revision history still ship | Run Document Inspector or exiftool, then re-open the exported copy |
| Fake PDF redaction | A black box over text that is still selectable and copy-pastes out | Try to select the covered text; use true Sanitize, not a shape overlay |
| Overbroad sharing | Set to Anyone-at-org (blocks outsiders) or Editor (anyone can alter) | Open the link logged out and confirm external, view-only access |
| Padding past relevance | Fifteen pieces, several unrelated to the role, reads as unfocused | Every piece maps to a target-job requirement or it is cut |
| Confidentiality own-goal | Real figures left in; reviewer concludes you cannot protect privacy | Ask: would the former employer be comfortable seeing this public |
| Missing the "what I did" line | A team artifact with no role statement reads as borrowed credit | Each piece has an explicit contribution line |
Two of these deserve a closer look because they pass the test most people actually run.
The metadata leak is the signature disaster of spreadsheet portfolios. You redact the visible cells, export, and ship a file that still carries the hidden sheet with the raw data, the author field with a colleague's name, or a live external data connection. On screen it looks finished. The only reliable check is to run the inspector and then re-open the clean copy and go looking for what you removed.
Fake PDF redaction is the same trap in a different format. A black rectangle drawn in a PDF tool sits on top of the text, which remains selectable underneath. The analog version of this is reading redacted text by holding the page to the light; the digital version is a copy-paste. A true Sanitize operation removes the underlying content; a shape does not. Test by trying to select the covered region.
Two more are about the link itself, not the files. A link with expiry set too short, or a page you unpublished, dies on a live application - re-test the week you apply. And metric inflation, an unverifiable precise percentage, invites exactly the scrutiny you least want in an interview; use ranges you can defend.
Keeping the link useful over time
Treat the link as a living supplement, replacing stale pieces as your work improves rather than only adding to a pile. A portfolio that grows past five pieces drifts back toward the unfocused showcase you were trying to avoid. The discipline is swap, not stack: when a newer, stronger, better-targeted artifact exists, it replaces the weakest piece in the set.
Re-run two checks on a cadence. Before any application batch, open the link logged out to confirm it still loads and has not expired or been unpublished. And once a quarter or whenever your role changes, re-read each one-pager against the kinds of jobs you are now targeting - a sample that mapped perfectly to one requirement a year ago may map to nothing on your current list.
Before you put the link on an application
- The set is 3 to 5 pieces, each mapped to a requirement in the target job.
- Every piece has a one-pager with overview, role, tools, timeline, and an outcome metric.
- Each piece has an explicit "what I did" line, not just "the team."
- Every outcome metric is a figure or range I can defend in an interview.
- Each file was sanitized on a copy and run through Document Inspector or Acrobat Sanitize.
- I re-opened each cleaned file and confirmed no selectable redactions and no hidden sheets.
- Permission is explicit or clearly implied for any client or employer work.
- The link opened view-only in a logged-out incognito window with no login prompt.
- Link expiry, if set, extends past my active application window.
If you want to see how practitioners in your field present this, look at who already does it. Searching a profile index for people who link sanitized samples shows the frame that reads well and the metrics that survive scrutiny - Refolk runs that kind of search in plain language.
The payoff is proportional to the pool. In a field of tens of thousands of comparable profiles, where the highest-validity signal is used by only a minority of employers and requested only of finalists, a tested, confidential-safe, one-link portfolio is a rare thing to hand over before anyone asks. Building it is a day of focused work. Keeping it current is fifteen minutes before each batch.
Questions job seekers ask
How many work samples should a portfolio for a job application have?
Three to five for a targeted application. Every source framed around a specific job lands in the 3 to 6 range, and one non-design guide recommends 3 to 4 pieces framed as problem, approach, and result. The 10 to 20 counts you see elsewhere describe a standing showcase, not an apply. Reviewers skim in seconds, so volume past five dilutes rather than strengthens. Start and end with your strongest piece.
How do I sanitize a confidential spreadsheet before sharing it?
Work on a copy, remove or replace PII and proprietary values, then run Microsoft Document Inspector via File, Info, Check for Issues, Inspect Document, Remove All. Hidden rows, hidden sheets, author names, revision history, and external data connections all travel with an XLSX otherwise. Document Inspector's Remove All is partially irreversible, which is why you never run it on your only copy. Re-open the exported file to confirm it is clean.
Do I need a website to have a portfolio for a non-creative role?
No. A single simple link to a free Notion page or Google Site works fine, and so does one structured PDF deck. For non-design roles clarity and ease of access matter more than design. The documented difficulty is not aesthetics but access control: Restricted versus Anyone-with-link, view versus edit, and link expiry. That is a 15-minute permissions test, not a build.
Why does a work-sample portfolio help if my field does not use them?
Because it supplies the strongest resume-independent hiring signal voluntarily. Work-sample tests predict job performance at r = .54 in Schmidt and Hunter (1998), versus .18 for years of experience and .10 for education. Most employers only ask their top three or four candidates for samples, so offering a sanitized one unprompted front-runs the weakest signals on your resume and is rare enough to stand out.
What is the most common way people leak confidential data in a portfolio?
Hidden metadata after a visible redaction. The file looks clean on screen, but author names, hidden sheets, and revision history still ship. The PDF equivalent is a black box drawn over selectable text that copy-pastes right out. Both pass a visual check and fail a real one. Run Document Inspector or Acrobat Sanitize, then test by trying to select or copy the redacted region in the exported copy.
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.