Google Drive Sharing Permissions: A Security Checklist
Google Drive sharing is brilliant for collaboration and treacherous for security, for the same reason: it is effortless. A few clicks turn a private document into a public link, an external grant, or a domain-wide share — and those few clicks are made thousands of times a year across an organization, by people who are trying to get work done, not weighing data risk.
This is a checklist you can run on a schedule to find and fix the exposures that accumulate. It moves from the highest-risk patterns to the more subtle ones.
Understand the sharing levels first
Drive exposes a small set of sharing modes, and knowing them precisely makes the review faster:
- Restricted — only explicitly named people can open the file. This is the safe default.
- Specific people — named individuals or groups, internal or external.
- Anyone in your organization with the link — domain-wide. Everyone in your Workspace can open it if they have the URL.
- Anyone with the link — public. Anyone on the internet who obtains the link can open it, no sign-in required.
- Published to the web — public and intended for indexing.
On top of the *who*, there is the *what*: Viewer, Commenter, or Editor. An external Editor on a sensitive folder is a very different risk than an external Viewer on a single document.
The checklist
1. Public links on sensitive content
Find every file set to "Anyone with the link" or published to the web. For each, ask whether the content is genuinely meant to be public. Marketing assets and public docs are fine; anything with customer data, financials, credentials, or internal strategy is not. Public links are the single most common serious exposure in Drive because they are reachable by anyone, forwardable, and often outlive their purpose by years.
2. External sharing of sensitive folders
Identify files and folders shared with addresses outside your domain. External sharing is legitimate — partners and contractors need access — but it should be deliberate and current. Watch especially for:
- External Editors and owners (an external owner controls the file).
- Personal email addresses (gmail.com, outlook.com) where a corporate address was expected.
- Shares to former partners or finished projects that were never revoked.
3. Domain-wide ("anyone in the organization") shares
"Anyone in the org with the link" is appropriate for a handbook and dangerous for HR, finance, legal, or security folders. Review domain-wide shares and downgrade anything sensitive to named access.
4. Over-ownership and broken inheritance
A single over-shared *parent* folder exposes everything beneath it. Look for folders with broad sharing that contain sensitive subfolders, and for files whose sharing was changed to break inheritance in ways that widened access. Concentrating sensitive content under tightly controlled parents pays off here.
5. Stale access
Access granted for a reason that no longer exists is pure risk. Review long-standing external grants, access held by people who changed roles, and shares tied to completed projects. A grant from 2023 that nobody remembers is a finding, not a feature.
6. Shared drives (Team Drives)
Shared drives have their own membership and sharing model. Review shared-drive membership for external members, check the drive-level sharing restrictions, and confirm a manager is assigned so the drive is not orphaned. A misconfigured shared drive exposes an entire workspace of content at once.
7. Service accounts and non-human access
Service accounts and automation often hold Drive access that no human review ever looks at. Include them: an over-privileged service account is as much an exposure as an over-shared folder.
Set defaults so the problem does not regrow
A review fixes the past; defaults shape the future. In the Admin console:
- Restrict sharing outside the domain to a trusted-domain allow-list where your workflow permits.
- Set link-sharing defaults to the most restrictive option your users can tolerate.
- Disable "publish to the web" unless you have a specific need.
- Warn users when they share externally, so the action is conscious.
Defaults govern new shares only — which is why the review and the defaults work together, not in isolation.
Why this is hard to do by hand
The checklist is simple. Running it across a real organization is not. Drive can hold millions of files, sharing changes daily, and the risky shares are a small fraction hidden among the legitimate ones. Manual review does not scale, so in practice it slips, and exposure accumulates in the gaps.
This is where continuous scanning changes the economics. Instead of a quarterly heroic effort, an automated posture tool enumerates every share, applies the checklist for you, ranks findings by real risk, and re-checks on every change — so the public link created this morning is flagged this afternoon, not next quarter. It is one piece of broader Google Workspace security, and it connects directly to external sharing risk.
A quick triage for when you find a lot
The first time most teams run this review, the result is overwhelming: hundreds or thousands of shares, many of them fine, some of them not. Resist the urge to fix everything at once. Triage instead:
- Public + sensitive first. Files set to "anyone with the link" that contain customer data, financials, credentials, or internal strategy. These are the genuine emergencies — fix them today.
- External Editors/owners on sensitive content next. High privilege plus outside party plus sensitive data is the next tier.
- Domain-wide shares on sensitive folders. Downgrade to named access.
- Stale external grants. Revoke what is plainly finished or forgotten.
- Everything else, on a schedule. The long tail of low-risk shares gets handled in the recurring review, not the fire drill.
This ordering matters because attention is finite. Fixing one truly public financial document beats tidying a hundred harmless internal shares.
Build habits, not just a one-time cleanup
The review fixes the past; habits keep the future clean:
- Share with named people, not links, by default for anything non-public.
- Prefer Viewer over Editor unless editing is genuinely required.
- Use shared drives with restrictions for team content, rather than personal-owned folders that vanish when someone leaves.
- Revisit on every joiner/mover/leaver — role changes and departures are when access quietly goes stale.
None of this is exotic; it is simply making the secure choice the default choice. Over months, those defaults are the difference between a Drive you can reason about and one nobody fully understands.
Where the checklist connects to the bigger picture
Drive sharing does not exist in isolation. The same exposures show up in adjacent reviews, and treating them together is more effective than handling each in a silo. Public and external Drive shares are the core of your external sharing risk. The third-party apps with Drive access are their own exposure, covered in auditing OAuth apps. And the whole thing rolls up into your broader Google Workspace security posture and any risk assessment you report to leadership. Running this checklist is one of the highest-leverage pieces of that larger program, because Drive is where the organization's knowledge — and therefore its exposure — concentrates.
8200.dev runs this checklist continuously across your Drive — public links, external and domain-wide shares, over-ownership, stale access, and shared-drive exposure — and explains each finding in plain language. See what we check.
Want the checklist run on your Drive automatically? Start your free security audit and get a prioritized list of your riskiest Google Drive shares in minutes.
Related articles
- Google Workspace Security: The Complete Guide for IT Admins (2026)
A practical, end-to-end guide to securing Google Workspace: identity, Drive sharing, OAuth apps, admin settings, and the monitoring that keeps it all in check.
- How to Audit Third-Party OAuth Apps in Google Workspace
A step-by-step method for finding, assessing, and cleaning up the OAuth applications connected to your Google Workspace — the shadow IT hiding in plain sight.
- SOC 2 Compliance for Google Workspace: What You Need to Know
How Google Workspace fits into a SOC 2 program: which Trust Services Criteria apply, what evidence auditors expect, and how to prepare without the scramble.