← Google Workspace audit scope

Drive, Docs & External Sharing

10 checks · 2 sub-categories

Drive is where your quotes, contracts, payroll and client files live. The default sharing settings in Google Workspace are built for collaboration, not confidentiality — and one 'anyone with the link' file can quietly be indexed, forwarded or handed to a competitor. This section maps exactly how far your files can travel.

Sharing policy

  • External sharing restricted or whitelisted

    We report whether Drive sharing outside the domain is off, allow-listed to trusted domains, or fully open — per organisational unit, not just the default.

    • CIS GW 4.1
    • SCuBA GWS.DRIVEDOCS
    • Privacy Act APP 11
  • Warning shown when sharing outside the domain

    The external-recipient warning is the last human checkpoint before data leaves. We check it is enabled everywhere.

  • Default link sharing set to restricted

    Where the default is 'anyone in the organisation with the link', every new file is over-shared from birth. We check the default and recommend the tightest workable setting.

    • CIS GW 4.2
  • Publishing to the web disabled or controlled

    'Publish to the web' makes documents publicly crawlable with no link expiry. We check whether staff can do it.

  • Access Checker set to recipients only

    Access Checker decides whether a user can grant broad access while sharing. Setting it to 'recipients only' prevents accidental link-wide exposure.

Actual exposure and data movement

  • Publicly accessible files inventory

    Beyond policy, we look at reality: which files are shared to 'anyone with the link', how many, and who owns them — sorted so you can fix the worst first.

    • Privacy Act APP 11
    • NDB scheme
  • Files shared with personal Gmail and ex-staff addresses

    Personal accounts and departed employees are the two share targets most likely to outlast the business relationship. Both are listed.

  • Ownership transfer and departed-user data

    Files owned by suspended or deleted users can become orphaned or lost. We check for unresolved ownership and Vault/Takeout arrangements.

  • Drive for Desktop and offline access policy

    Local sync onto unmanaged personal computers puts company data outside every server-side control. We check whether sync and offline Docs are restricted to managed devices.

  • Data Loss Prevention rules for Drive

    Where the licence supports it, we check whether DLP rules exist for obvious sensitive data — TFNs, credit card numbers, health identifiers — and whether they block or merely audit.

    • Privacy Act APP 11
    • RACGP (health)

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.