Google Drive External Sharing Report Template

8apps Team·

The external-sharing report template for Google Workspace admins: twelve columns, four exposure types, three ways to fill it, top-ten triage, sign-off.

Three people, one file

An auditor asks for "a list of Drive files shared externally, with owners". A prospective client's security questionnaire asks the same with a tick box. Your managing director, after a document went astray, asks "how many of these are there?" All three want the same file, and on Business Starter, Standard and Plus Google does not build it – the file exposure report is on Frontline Plus, Enterprise Plus, Education Standard and Plus and Enterprise Essentials Plus.

So you build it. This post is the template: the columns, why each exists, what to do once it is full. The external sharing report post covers the three routes to producing the rows; this one is the file itself. It sits alongside the quarterly checklist and the evidence log described in the access review post.

The twelve columns and why each exists

File name. For the humans reading it; never the key, because names duplicate.

File ID / link. The key. Two rows with the same ID are one file with two exposures, which you want side by side.

Owner. The person who can change the sharing, and the first thing to check against the leavers list. A suspended owner means nobody will fix the row unless the admin does.

Location – My Drive or the Shared Drive name. Responsibility and the fix path differ. A My Drive file is its owner's to restrict; a shared-drive file is governed by the drive's members and settings, under Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives.

Exposure type. Four values; the whole report sorts on this column:

  • public – anyone with the link, or published on the web. No sign-in needed.
  • external – shared with a specific address or group outside your domain.
  • legacy – external, to a domain or person you no longer work with: a former agency, a finished client, last year's contractor.
  • internal-wide – shared with everyone in the organisation. Not external, but a row an HR or finance file should never have.

Shared with. The domain or address. Sorting this column surfaces personal addresses (gmail.com, outlook.com and the like); those need a justification or a restriction every time.

Role. Viewer, commenter or editor. An external editor on a contract is a different conversation from a viewer on a brochure.

Last modified. A public file untouched for eighteen months is an easy restrict. A file edited yesterday and shared externally is live work; restricting it without asking breaks something.

Found by – log, search or scan. Which source produced the row. It tells you, and later an auditor, how complete the population is: if every row says log, the report only covers changes inside the window, because the log records events, not current state.

Decision – keep, restrict or transfer. The column that turns a list into a review; empty means undecided.

Decided by. A name, often not the admin's – see below.

Done on. When the change was made. A decision with no Done on date is an open finding, and next quarter's first stop.

Filling it from three sources

Each source has a Found by value; the three routes post has the detail, so briefly:

The Drive log – Menu → Reporting → Audit and investigation → Drive log events, date range widened from the 7-day default, filtered on the Visibility change attribute. Every change to public or external in the window becomes a row marked log. Complete for the window, silent about everything exposed before it; Drive log events are retained for 6 months.

Per-user search. A user can search their own Drive with sharedwith:external owner:me and sharedwith:public owner:me, or use the People filter chip → "Anyone with the link". Their results become rows marked search. There is no domain-wide version an admin can run from the Drive UI, so it scales badly. Shared drives are the exception: Manage shared drives shows the admin every drive and its members.

An org-wide scan export. Every user's My Drive and every Shared Drive in one pass, with the same columns as the template; rows marked scan. This is where the Admin console stops on Business editions and a tool starts – the flagship guide sets out the boundary.

What to do with the top ten owners

Once the sheet has rows, sort by Owner and count. In most domains a few people account for most external sharing: the sales lead who shares proposals, whoever runs the agency relationship, the founder, and someone who left in February. That concentration is useful: ten ten-minute conversations usually clear most rows, most ending with "restrict everything older than six months".

Take the owners in order of row count. For each, filter to their rows, public first, then oldest Last modified first. Agree the decisions in one sitting, put the owner's name in Decided by, move on. Rows owned by suspended or deleted users go to whoever inherited their work – or to the admin, if nobody did.

The decision column and who signs it

The admin usually should not be deciding whether a client still needs a proposal. The person who owns the relationship decides; the admin records and, where needed, executes. So Decided by is often a line manager or the file's owner, and the admin goes in Done on.

Two rules keep the column honest. A keep needs a reason in the row, even one line – "client project, ends December". And an external row to a personal address never gets keep without a reason that survives being read aloud to the auditor.

The file they asked for

The same sheet answers all three requests. For the auditor: export it, dated, and copy the totals per exposure type into the evidence log – the access review post explains why the pair gets accepted. For the client questionnaire: totals and cadence, not the file. For the managing director: the top ten owners and the public count, one screen.

Sources