Drive, Docs & External Sharing
10 checks · 2 sub-categories
Drive is where your quotes, contracts, payroll and client files live. The default sharing settings in Google Workspace are built for collaboration, not confidentiality — and one 'anyone with the link' file can quietly be indexed, forwarded or handed to a competitor. This section maps exactly how far your files can travel.
Sharing policy
External sharing restricted or whitelisted
We report whether Drive sharing outside the domain is off, allow-listed to trusted domains, or fully open — per organisational unit, not just the default.
- CIS GW 4.1
- SCuBA GWS.DRIVEDOCS
- Privacy Act APP 11
Warning shown when sharing outside the domain
The external-recipient warning is the last human checkpoint before data leaves. We check it is enabled everywhere.
Default link sharing set to restricted
Where the default is 'anyone in the organisation with the link', every new file is over-shared from birth. We check the default and recommend the tightest workable setting.
- CIS GW 4.2
Publishing to the web disabled or controlled
'Publish to the web' makes documents publicly crawlable with no link expiry. We check whether staff can do it.
Access Checker set to recipients only
Access Checker decides whether a user can grant broad access while sharing. Setting it to 'recipients only' prevents accidental link-wide exposure.
Actual exposure and data movement
Publicly accessible files inventory
Beyond policy, we look at reality: which files are shared to 'anyone with the link', how many, and who owns them — sorted so you can fix the worst first.
- Privacy Act APP 11
- NDB scheme
Files shared with personal Gmail and ex-staff addresses
Personal accounts and departed employees are the two share targets most likely to outlast the business relationship. Both are listed.
Ownership transfer and departed-user data
Files owned by suspended or deleted users can become orphaned or lost. We check for unresolved ownership and Vault/Takeout arrangements.
Drive for Desktop and offline access policy
Local sync onto unmanaged personal computers puts company data outside every server-side control. We check whether sync and offline Docs are restricted to managed devices.
Data Loss Prevention rules for Drive
Where the licence supports it, we check whether DLP rules exist for obvious sensitive data — TFNs, credit card numbers, health identifiers — and whether they block or merely audit.
- Privacy Act APP 11
- RACGP (health)
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.