The report that isn't in your Admin console
The ticket says "can you send me a list of everything shared outside the company?" You open the Admin console, go to Reporting, and find Drive log events. What you do not find is a file exposure report or a Drive inventory. Those exist – on someone else's invoice.
Google spreads its Drive reporting across six tools, and only one of them ships on every edition. Here they are edition by edition, and for each one a Business-edition admin lacks, how to get the same answer with what you have.
The table
| Tool | Business Starter / Standard / Plus | Enterprise Standard | Enterprise Plus | Education Standard / Plus | Frontline Plus |
|---|---|---|---|---|---|
| Drive log events | Yes | Yes | Yes | Yes | Yes |
| Security investigation tool | No | Yes | Yes | Yes | Yes |
| File exposure report | No | No | Yes | Yes | Yes |
| Drive inventory export (to BigQuery) | No | Yes | Yes | Yes | Yes |
| Trust rules for Drive sharing | No | Yes | Yes | Yes | Yes |
| Manage shared drives (admin view) | Yes (Starter with limits noted on Google's page) | Yes | Yes | Yes | Yes |
| DLP data protection insights (Drive) | Yes (Standard and Plus) | Yes | Yes | Yes | Yes |
Edition lists as on Google's Help pages, re-read 9 September 2026. Off the table: Frontline Standard gets the investigation tool only; Enterprise Essentials Plus gets all four gated tools; Cloud Identity Premium gets the investigation tool and inventory export; Education Fundamentals gets nothing beyond Drive log events.
Drive log events – what everyone gets
Menu → Reporting → Audit and investigation → Drive log events. By default it shows the last seven days; widen the range and you can go back six months, which is how long Google retains it. Its event names are View, Rename, Create, Edit, Print, Delete, Upload and Download, with Source Copy and the item-content events alongside. Sharing is not one of them: Google exposes it as searchable attributes instead – Visibility change ("visibility of the Drive item before the activity"), Prior visibility and Target. Add a condition on Visibility change and you have every moment a file's audience changed.
Two caveats. External users show as anonymous unless the file was explicitly shared with them, individually or via a specific group, so a public-link viewer is a row with no name. And a log is activity history, not a current permissions map – more in our piece on Drive audit log retention.
Security investigation tool – what it answers and the manual route
Google's page describes it as where super admins "identify, triage, and take action on security and privacy issues". On a Business edition you have the query half already: Drive log events filters on event, actor, document, visibility and date, and exports results to Sheets or CSV. What you lose is the action. Export the filtered Visibility change rows, sort by document, and open each file's sharing dialog by hand. Slow, but the same rows.
File exposure report – what it answers and the manual route
The one most Business admins are actually asking for. It shows sharing trends over time, including internal sharing, the most-viewed shared files, and the outside domains your users share to most. Enterprise Plus, Education Standard and Plus, Frontline Plus, Enterprise Essentials Plus.
By hand it has two parts. The trend comes from Drive log events: filter Visibility change by month and count. The "who are we sharing with" list comes from the users. Each can search their own Drive with sharedwith:external owner:me and sharedwith:public owner:me, or use the People filter chip and pick "Anyone with the link". No domain-wide version exists in the Drive UI, so the manual route is a request to each user with a deadline. Our external sharing report guide has a template for the ask.
Drive inventory export – what it answers and the manual route
The inventory export sends metadata for every file – size, labels, who it is shared with, not content – plus shared drive metadata to a BigQuery project with billing enabled (roughly 1.5 GB per million files, per Google). Weekly by default, daily as an option, each export overwriting the last, and it may miss some files. Enterprise Standard and Plus, Education Standard and Plus, Frontline Plus, Enterprise Essentials Plus, Cloud Identity Premium.
It answers the flagship question: what is the current sharing state of every file in the organisation? There is no manual equivalent at that scope. Per-user searches cover My Drive one person at a time. Shared Drives you inspect from Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives: every drive listed, filters for no members or no managers, membership and per-drive sharing settings editable – but no view of which files inside carry external or public permissions.
Trust rules – what they answer and the manual route
Trust rules are preventative: who may share with whom, before the share happens. Business editions have the coarser lever at Menu → Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options: off, allowlisted domains only, or on with warnings, settable per organisational unit.
The one exposure report Business editions do get
Before the workarounds, the report most Business-edition admins do not know they have. Under Menu → Security → Access and data control → Data protection, Google publishes a data protection insights report for Drive, updated quarterly. It is generated proactively – DLP "regularly and proactively scans all Drive files based on a set of default detectors for sensitive data" – so no DLP rules are needed and nothing has to be switched on. It is supported on Business Standard and Business Plus (and Frontline, Enterprise, Enterprise Essentials and every Education tier including Fundamentals).
For external sharing it gives the number of Drive files with sensitive content shared externally, the percentage of sensitive files shared externally overall and per data type, and a breakdown of how – external invites, public links, individual accounts, groups – across My Drive and shared drives.
Read the limits with it. It covers only files matching Google's default sensitive-data detectors, not everything you share; Google says "reports don't include details about every file or message in the reports"; and it is quarterly, so it is a trend, not a working list. It is a genuinely useful signal that your exposure is getting worse or better. It is not the file-by-file inventory this article's other four tools produce.
Where the native tools stop on a Business edition
A Business-edition admin can see six months of sharing history, inspect shared drive membership, set sharing policy per OU, read a quarterly sensitive-content exposure trend, and ask each user to search their own Drive. What they cannot do is answer "what is shared outside the organisation right now, across every My Drive and every Shared Drive" from one screen. That sits behind the inventory export and a BigQuery bill.
Where an org-wide scan starts
That gap – current state, whole organisation, no BigQuery – is what Drive Guard for Admins is for. One admin install from the Marketplace deploys it to every user; nobody installs anything themselves. It scans every user's My Drive and every Shared Drive and puts public links, external shares and legacy access on one dashboard, with exports. It reports; you fix, in the sharing dialog or Manage shared drives – revoking from inside the tool is on the roadmap. For the full manual method, start with how to audit Google Drive access across the organisation.
Sources
- Drive log events – event list, 7-day default view, anonymous external users, export to Sheets/CSV, investigation tool quote and edition list; Visibility change is an attribute, not an event name
- Data retention and lag times – 6-month retention for Drive log events
- File exposure report – edition list, what the report shows
- Export your organization's Drive inventory – edition list, BigQuery requirement, weekly/daily cadence, ~1.5 GB per 1M files, may miss files
- Create and manage trust rules for Drive sharing – edition list
- Manage external sharing for your organization – sharing options path, per-OU setting, all editions
- Manage shared drives as an admin – path, no-members/no-managers filters, edition support
- Find files shared with "anyone with a link" (Stanford UIT) – People filter chip method
- DLP data protection insights reports – Menu → Security → Access and data control → Data protection; edition list including Business Standard and Plus; Drive reports updated quarterly; "DLP regularly and proactively scans all Drive files based on a set of default detectors for sensitive data"; externally shared counts and percentages by data type and sharing method; "Reports don't include details about every file or message in the reports". Read 2026-09-09.
- Google Drive search operators –
sharedwith:public owner:me,sharedwith:external owner:me. Re-read 2026-09-09.