← Google Workspace audit scope

Shared Drives

8 checks · 2 sub-categories

Shared Drives are owned by the organisation rather than a person, which is exactly why they get forgotten. A single Shared Drive left open to a contractor from three years ago can expose an entire department's files, and nothing in the standard admin console shouts about it.

Membership and access

  • Shared Drives with external members

    Every Shared Drive containing a member outside your domain is listed, along with their role, so you can decide whether that access is still warranted.

    • Privacy Act APP 11
    • CIS GW 4.4
  • Shared Drives with no manager or a single manager

    Orphaned drives can't be governed, and single-manager drives break when that person leaves. Both patterns are reported.

  • Ex-staff and suspended accounts still holding membership

    Suspended users frequently remain members of Shared Drives. Each is listed with the drives they can still reach if reactivated.

  • Over-broad membership via Groups

    Adding 'all-staff@' as a Shared Drive manager grants far more than intended. We trace effective access through group membership, not just direct grants.

Drive-level controls

  • External member creation restricted by policy

    We check whether the domain permits members outside the organisation to be added to Shared Drives at all, and whether that is set per OU.

  • Download, copy and print restrictions on sensitive drives

    Content restrictions prevent viewers from exporting files. We report which drives carry them and which sensitive drives do not.

  • Non-member file access setting

    Individual files inside a Shared Drive can be shared with people who aren't drive members, bypassing the drive's boundary. We check whether that's allowed.

  • Shared Drive creation permissions

    If any staff member can create Shared Drives, governance drifts quickly. We check who holds creation rights.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.