"Send me the external sharing report"
Sooner or later the request lands – from an auditor, a prospective client's security questionnaire, or your own leadership after a near-miss. They do not want a feeling. They want a file: every document shared outside the organisation, who owns it, and how it is exposed.
There are three ways to produce that file. Which ones are available to you depends on your Google Workspace edition.
Route 1 – Google's file exposure report (if your edition has it)
Google builds exactly this report, but only into the top plans: Frontline Plus, Enterprise Plus, Education Standard and Plus, and Enterprise Essentials Plus. On those editions, start there – it is Google's own view of exposure.
On Business Starter, Standard or Plus, this report is simply not part of your plan, and no setting turns it on – see the reports your Workspace edition doesn't include for the full edition table.
Route 2 – the Drive log, filtered to sharing events
Every admin can open Reporting → Audit and investigation → Drive log events and filter to sharing and permission changes. Google documents the exact recipe: Add a filter → Visibility → Shared externally → Search. Read the result with Google's own caveat in mind – a share to a group that permits external users is marked Shared externally "even if the group doesn't have any external users". This produces something report-shaped, and it is worth doing – but understand what it is: a history of sharing changes in the window you filtered, not a statement of what is shared now.
The gap matters in both directions. A file shared externally two years ago and never touched since will not appear in a recent window. And a file shared then unshared last week appears in the log twice while being exposed zero times today. Handing this to an auditor as "the external sharing report" over-promises what it is.
Route 3 – scan the state, org-wide
The state answer – what is shared right now, across every user – is what Drive Guard for Admins produces. One admin install covers every user in the organisation; the scan walks all users' My Drives and Shared Drives; and the dashboard splits the results into the categories the report needs: external access, public links, and legacy access that has outlived its reason. Then you export it.
Pricing is US$4.80 per user per year, launch pricing against a US$8.80 list price, with a 7-day trial – credit card required, and one honest limitation worth knowing: during the trial everything is unlocked except downloading the raw data, so you can see your full results on the dashboard and export once you subscribe. Education institutes: free. More than 100 users: write to support@8apps.co for a discount.
What a good external sharing report contains
Whichever route produces it, the report that satisfies the person asking has these columns – the full template is here: file name and owner; what makes it external (named outside collaborator, or a link); link scope if any (public vs anyone-with-link inside a domain); last modified; and a status column your team fills in – keep, restrict, investigate. The status column is what turns a scan into an audit.
Keep the report honest
Date it. State the scope ("all My Drives and Shared Drives, N users, scanned on this date"). And state the method. An external sharing report that does not say how it was produced invites exactly the follow-up question you were trying to close.
Sources
- File exposure report – edition list (Frontline Plus; Enterprise Plus; Education Standard and Plus; Enterprise Essentials Plus). Re-read 2026-09-09.
- Drive log events – menu path; the "View files shared outside of a domain" recipe (Add a filter → Visibility → Shared externally) and its group false-positive caveat. Re-read 2026-09-09.