Quarterly Google Drive Access Audit Checklist

8apps Team·

A 30-minute quarterly Google Drive access audit checklist for Workspace admins: Drive log, current exposure, leavers, decisions, evidence log, console paths.

The audit that only happens after something goes wrong

Most Google Drive access reviews are triggered, not scheduled. Someone leaves, a client's questionnaire asks "how often do you review external sharing?", or a document turns up where it should not be – and then you look.

This checklist makes it a calendar item. Thirty minutes is the budget for the review on a Business edition, using the Admin console alone. Fixing what you find is on top.

It pairs with two working files you build once and reuse: an external-sharing report, one row per exposed file, and an evidence log, one row per audit. The report template post sets out the report's columns; the access review post sets out what the evidence log has to carry.

0. Before you start – 3 minutes

  1. Confirm your edition: Menu → Billing → Subscriptions. Business Starter, Standard and Plus do not have the file exposure report or the security investigation tool, so parts 1 and 2 use the Drive log and manual search. If you have the file exposure report (Frontline Plus, Enterprise Plus, Education Standard and Plus, Enterprise Essentials Plus), start there and use this checklist for the gaps.
  2. Open the report template and the evidence log; put today's date and your name in the header.
  3. Decide the window: since the last audit, or 90 days if this is the first. Drive log events are kept for 6 months, so a first audit cannot look back further – see the retention post.

1. What changed – the Drive log – 10 minutes

  1. Go to Menu → Reporting → Audit and investigation → Drive log events – you need the Audit & Investigation administrator privilege. The default view is the last 7 days; change the date range to your window.
  2. For the external half, use Google's documented recipe: Add a filter → VisibilityShared externally → Search. (Google's caveat: a share to a group that allows external users is marked Shared externally "even if the group doesn't have any external users", so expect false positives.) For visibility changes generally, filter on the Visibility change attribute – it is one of Google's search attributes, not an event name. Any change to "Public on the web" or "Anyone with the link" goes into the report as public; any change that shares an item outside the domain goes in as external.
  3. Check Download and Source Copy events by external or anonymous users – external users appear as anonymous unless the item was shared with them individually or via a specific group. Note anything sensitive in the evidence log as an incident, not an exposure.
  4. Write down what the log cannot tell you: a file already public or external before the window generates no events. The log is activity history, not a current permissions map. Part 2 exists for that gap.

2. What is exposed now – 8 minutes, and the honest caveat

  1. Shared drives: Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives. Filter for drives with no members and no managers, then open the member lists of the drives that matter and flag external members. Only Managers can add members, so a drive with no manager is one nobody can tidy. The shared-drive permissions post goes deeper.
  2. My Drives: there is no domain-wide search an admin can run from the Drive UI. A user can search their own Drive with sharedwith:public owner:me and sharedwith:external owner:me, or use the People filter chip → "Anyone with the link". In 8 minutes, ask the users who appeared most in part 1 to run those searches and send you the results; log each hit with Found by = search.
  3. A full per-user pass is where 30 minutes becomes a day, and where the Admin console stops on Business editions. An org-wide scan does this step for every user's My Drive and every Shared Drive in one pass, with the same columns as the report template. The manual route is in finding every "anyone with the link" file across the domain.

3. Leavers and legacy access – 4 minutes

  1. Menu → Directory → Users. List everyone suspended or deleted in the window. Suspension blocks sign-in, but collaborators who were granted access to shared documents keep it – the leaver's shares still work.
  2. For each deleted user: were their files transferred at deletion? Untransferred files owned by a deleted user are kept for 20 days and are only recoverable by restoring the user. The offboarding checklist has the full sequence; suspended is not gone explains why.
  3. Search the report for domains you no longer work with – former agencies, clients, vendors – and mark those rows legacy.

4. Decide – 3 minutes to decide, fixing on top

  1. For every public row: does it need to be public? If not, restrict it and record who decided.
  2. For every external row shared with a personal address (gmail.com, outlook.com and the like): restrict or write a justification.
  3. Sharing settings: Menu → Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options. Confirm the setting (Off, Allowlisted domains only, or On), the external-sharing warning, and whether it differs by organisational unit.
  4. Third-party apps, every other quarter: Menu → Security → Access and data control → API controls. Block any app with Drive access that nobody uses.

5. Record and schedule – 2 minutes

  1. Fill one row in the evidence log: date, window, owner, edition, files reviewed, public, external and legacy found, restricted, justified, incidents.
  2. Name the owner of the next audit and put the date in the calendar. Quarterly by default; monthly if you are regulated; always after a leaver.
  3. Export the report as the "external sharing report" whoever asked for it wanted. The access review post explains why log row plus export is what an auditor accepts.

Where the 30 minutes goes, and where it does not

Steps 4–7 and 11–19 fit the budget on any Business edition. Step 9 does not, once you have more than a handful of users: one search per person, per quarter, and the admin cannot run it for them. That is why the report template has a Found by column – so you can see, a year later, how much of the population you covered.

The flagship guide to auditing Drive access across the organisation is the long-form version of this page.

Sources