Audit Shared Drive Permissions Across Your Org

8apps Team·

Manage shared drives, access levels, external members, the no-manager filter – and the file-level shares inside drives the Admin console page does not list.

"Who owns the Finance shared drive?"

The ticket is short. Finance needs a new starter added to their shared drive and cannot do it, because nobody left in the team is a Manager. The person who created the drive resigned last spring. It is one drive; you suspect there are twenty like it.

Shared Drives solved the ownership problem of My Drive – files belong to the team, not the person – and introduced a membership problem, an external-guest problem and a manager problem instead. Here is how to audit all three from the Admin console, where the console stops, and what covers the rest.

Start at Manage shared drives

Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives. As an admin you see every shared drive in the organisation, member or not. You can add and remove members, change access levels, adjust a drive's sharing settings, set defaults by organisational unit, and delete or restore drives. Google lists it as supported on Business Standard and Plus, Enterprise, Education, Essentials and Nonprofits, with Business Starter "except as noted" – check the page for your edition.

The filters are the audit. Run two the first time you open the page:

– No members – drives with nobody in them, usually left behind by a departed user or a finished project. – No managers – drives with members but nobody who can add members, change settings or delete the drive. This is the Finance ticket, twenty times over.

Work through each list and either assign a Manager or delete the drive. Record which you did and why.

Access levels, and why the manager problem exists

A shared drive has five access levels. Manager does everything, including managing members and sharing settings and deleting the drive. Content manager can view, comment, edit, create and add files, and can share folders unless the drive's settings prevent it, but cannot manage members. Contributor can view, comment, edit, create and share files. Commenter and Viewer are what they sound like.

The line that matters: only Managers – and Workspace admins, from the Admin console – add members. A drive whose only Manager leaves is frozen – nobody can bring anyone in, and nobody notices until a ticket arrives. The opposite failure is as common: everyone made Manager on day one, so anyone can add an external guest or delete the whole thing.

For each important drive, ask two questions. Are there at least two Managers, still employed here? Does anyone hold Manager who only needs Content manager?

External members are not the same as external sharing

Two controls decide whether outsiders can get into a shared drive, set in different places.

The first is organisation-wide: Menu → Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options, where external sharing is Off, limited to allowlisted domains, or On. External users with a Google Account can be shared-drive members; people without one need visitor sharing enabled.

The second is per drive. Each drive has its own settings, including "Allow users outside [your organisation] to access files in shared drives". Google's note is precise: "When unchecked, external users can't have access, even if you allow users to share files outside of your organisation." A drive can be tighter than the domain, never looser.

So a guest on a member list has passed two gates. Go through every drive's member list and pull out any address not on your domain: which drive, what access level, is the engagement still live. Ex-agency staff holding Contributor on a marketing drive is the classic finding, and the subject of the legacy access guide.

The per-drive settings worth checking

Beyond the external-access box, three more per-drive restrictions are worth checking: "Allow people who aren't shared drive members to be added to files", "Allow content managers to share folders", and "Allow viewers and commenters to download, print, and copy files". The first is the one people miss. Left on, a single file inside the drive can be shared with someone who is not a member of it, and that person never appears on the member list.

What the Manage shared drives page does not show

This is where the Admin console stops, stated carefully. The Manage shared drives page lists drives and their members. It does not list the file-level shares inside those drives – individual documents shared with a non-member, an external address or a public link. Those are permissions on files, not memberships of the drive, and the member list has no column for them.

Google's native route to them is the Drive log: Menu → Reporting → Audit and investigation → Drive log events, filtered on the Visibility change attribute – it sits among the search attributes, not under Event name. Each row carries a Shared drive ID when the file lives in a shared drive, so you can narrow to one drive. But the log holds events, not current state, defaults to seven days and is retained for six months. A file shared out of a drive last year is not in it. The file exposure report and Drive inventory export do give a current picture – on Frontline Plus, Enterprise Plus (Enterprise Standard for the inventory export), Education Standard and Plus and Enterprise Essentials Plus, not Business. That gap is covered in the reports your Workspace edition doesn't include.

The org-wide scan, including every Shared Drive

Drive Guard for Admins is installed once by a Workspace admin from the Google Workspace Marketplace and deploys to every user. It scans every user's My Drive and every Shared Drive in the organisation, and shows public links, external shares and legacy access on one dashboard with exports. For shared drives, that is the file-level layer the member list cannot show – every file inside every drive shared with an outsider or a link – alongside the same view for My Drive, so one export covers the whole estate.

It reports; it does not yet change anything. Revoking a share from inside the tool is on the roadmap, not live. The fix is still yours, in the drive's settings or on the file, and the export tells you where to go.

A routine that holds

Quarterly, and after any leaver who was a Manager anywhere: run No managers and No members, review external members drive by drive, spot-check the per-drive restrictions on anything holding finance, HR or client data, then take the file-level pass from the log or the scan. Write down the counts and the date. The wider method, covering My Drive and offboarding, is in how to audit Google Drive access across the organisation.

Sources

  • Manage shared drives as an admin – Admin console path; admin sees all drives; "No members" and "No managers" filters; add/remove members, change access, per-drive sharing settings, defaults by OU, delete/restore; the four per-drive restriction labels; "When unchecked, external users can't have access, even if you allow users to share files outside of your organization"; edition list.
  • Shared drive access levels – Manager, Content manager, Contributor, Commenter, Viewer; only Managers add members.
  • Manage external sharing for your organization – Sharing options path; Off / Allowlisted domains / On; external users with Google Accounts can be shared-drive members; visitor sharing for those without.
  • Drive log events – path; Visibility change and Shared drive ID attributes ("If the file isn't in a shared drive, this field isn't populated"); default 7 days.
  • Data retention and lag times – Drive log events retained 6 months.
  • File exposure report – edition list.
  • Export your organization's Drive inventory – edition list; exports shared drive metadata.