The email from the Year 11 teacher
First week of term. A teacher forwards you a message from a parent: a link to a class Doc, with every pupil's name and their marks in it, has been doing the rounds in a parents' group chat. Anyone with the link can open it. The student who set it that way did it in June, to hand it in from a phone, and nobody has thought about it since.
You are the IT lead. You are also, in most schools, the network, the printers, the MIS and the keeper of the projector remote. This is the Drive sharing audit for that job: what Google Workspace for Education gives you natively, where it stops on the Fundamentals edition, and the org-wide scan that fills the gap – which, for schools, is free.
What your edition actually includes
Google Workspace for Education Fundamentals is available at no cost to qualifying institutions, and the edition you are on decides what you can see.
On Education Standard and Education Plus you have the security investigation tool, the file exposure report and Drive inventory export.
On Fundamentals you have none of the three. You are in the same position as a company on a Business edition: the Drive log, the shared drive management screen, the sharing settings, and no domain-wide view of what is exposed.
Set the sharing rules by organisational unit first
Get the rules straight first, because in a school one rule cannot fit everyone.
Go to Menu → Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options. External sharing can be Off, limited to allowlisted domains, or On with optional warnings, and the setting can differ per organisational unit. With students in their own OU and staff in theirs, you can turn external sharing off for students while letting staff share with allowlisted partner domains, or with warnings.
Two honest caveats. The setting is a control, not a report – it does not tell you what is already shared. And it only works if your OU structure is real. A school where every account sits in the root OU has one rule for a Year 7 pupil and the head of finance.
Four things that go wrong in a school domain
Student accounts that graduate. Whatever you do with the accounts – suspend for a year, delete after results – the sharing those students set up does not change when their sign-in stops. Suspension blocks sign-in and is reversible; deletion offers to transfer ownership of their files, and anything not transferred is kept for 20 days and recoverable only by restoring the user. None of those steps looks at what the leaver shared, or with whom. We argue this in full in suspended is not the same as gone. The school version: a student shares their whole portfolio to a personal Gmail in June so they can keep it. The account goes; the share stays.
Class shared drives with a departed teacher as the only Manager. Only Managers add members, and the teacher who built a drive in 2022 and left in 2024 may have been the only one. Go to Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives and filter for drives with no managers. As an admin you can add a Manager from that screen. The longer treatment is in auditing shared drive permissions org-wide.
Public links on student work. Students set "anyone with the link" for the same reason adults do: it always works. A student can find their own by searching sharedwith:public owner:me in Drive. What you cannot do is run that search across other people's Drives from the admin side; there is no domain-wide search in the Drive UI.
Staff sharing with personal Gmail. Teachers mark at home, and the fastest route is a share to their own Gmail. It is an external share that outlives the staff member, and the staff OU's sharing setting is the only native control on it.
What the Drive log shows, and for how long
The Drive log is the native evidence for all four. Menu → Reporting → Audit and investigation → Drive log events. The default view is the last seven days, so widen it. Filter on the Visibility change attribute to see every change to who can see a file. External users appear as anonymous unless the file was shared with them individually or through a specific group – so a public-link viewer is "anonymous", while a teacher's personal Gmail, if shared to directly, shows as the address.
Drive log events are retained for six months. A public link set on a Year 10 project two years ago is not in the log. The log is activity history, not a current permissions map.
On Education Fundamentals, this is where Google stops.
The org-wide scan, and why it is free for schools
Behind all four problems is one question: across every student's Drive, every teacher's Drive and every class shared drive, what is public, what is external, and what is still shared with people we no longer work with?
Drive Guard for Admins is a Google Workspace Marketplace add-on that an admin installs once; it deploys to every user, so nobody in a classroom installs anything. It scans every user's My Drive and every Shared Drive in the domain and shows public links, external shares and legacy access on one dashboard, with exports. It reports; you fix in Drive. Revoking from inside the dashboard is on the roadmap, not live today.
Drive Guard for Admins is free for education institutes. Write to support@8apps.co from your school address and we will set it up. Scan at the end of each term and again after results day, when the leaving cohort's accounts are dealt with – the cadence is yours to set.
For the general procedure the scan sits inside, start with auditing Google Drive access across the whole organisation.
Sources
- Compare Google Workspace for Education editions – "Google Workspace for Education Fundamentals is available for no charge for all qualifying institutions."
- Drive log events – Admin console path; default 7-day view; Visibility change attribute; external users appear as anonymous unless shared with individually or via a specific group; security investigation tool edition list (Education Standard and Plus, not Fundamentals).
- Data retention and lag times – Drive log events retained 6 months.
- File exposure report – edition list (Education Standard and Plus; not Fundamentals).
- Export your organization's Drive inventory – edition list (Education Standard and Plus; not Fundamentals).
- Manage external sharing for your organization – Admin console path; Off / allowlisted domains / On with warnings; can differ per organisational unit; supported on all editions.
- Manage shared drives as an admin – Admin console path; filter for drives with no managers; admin can add members and change access levels; supported on Education.
- Shared drive access levels – only Managers add members.
- Delete or remove a user from your organization – read 2026-09-01 (for DGA-B4, re-cited): suspension blocks sign-in, reversible; deletion offers ownership transfer; untransferred files kept 20 days, recoverable only by restoring the user.
- Google Drive search operators –
sharedwith:public owner:meworks on the user's own Drive only. Re-read 2026-09-09.