The audit that only happens after something goes wrong
Most Google Drive access reviews are triggered, not scheduled. Someone leaves, a client's questionnaire asks "how often do you review external sharing?", or a document turns up where it should not be – and then you look.
This checklist makes it a calendar item. Thirty minutes is the budget for the review on a Business edition, using the Admin console alone. Fixing what you find is on top.
It pairs with two working files you build once and reuse: an external-sharing report, one row per exposed file, and an evidence log, one row per audit. The report template post sets out the report's columns; the access review post sets out what the evidence log has to carry.
0. Before you start – 3 minutes
- Confirm your edition: Menu → Billing → Subscriptions. Business Starter, Standard and Plus do not have the file exposure report or the security investigation tool, so parts 1 and 2 use the Drive log and manual search. If you have the file exposure report (Frontline Plus, Enterprise Plus, Education Standard and Plus, Enterprise Essentials Plus), start there and use this checklist for the gaps.
- Open the report template and the evidence log; put today's date and your name in the header.
- Decide the window: since the last audit, or 90 days if this is the first. Drive log events are kept for 6 months, so a first audit cannot look back further – see the retention post.
1. What changed – the Drive log – 10 minutes
- Go to Menu → Reporting → Audit and investigation → Drive log events – you need the Audit & Investigation administrator privilege. The default view is the last 7 days; change the date range to your window.
- For the external half, use Google's documented recipe: Add a filter → Visibility → Shared externally → Search. (Google's caveat: a share to a group that allows external users is marked Shared externally "even if the group doesn't have any external users", so expect false positives.) For visibility changes generally, filter on the Visibility change attribute – it is one of Google's search attributes, not an event name. Any change to "Public on the web" or "Anyone with the link" goes into the report as
public; any change that shares an item outside the domain goes in asexternal. - Check Download and Source Copy events by external or anonymous users – external users appear as anonymous unless the item was shared with them individually or via a specific group. Note anything sensitive in the evidence log as an incident, not an exposure.
- Write down what the log cannot tell you: a file already public or external before the window generates no events. The log is activity history, not a current permissions map. Part 2 exists for that gap.
2. What is exposed now – 8 minutes, and the honest caveat
- Shared drives: Menu → Apps → Google Workspace → Drive and Docs → Manage shared drives. Filter for drives with no members and no managers, then open the member lists of the drives that matter and flag external members. Only Managers can add members, so a drive with no manager is one nobody can tidy. The shared-drive permissions post goes deeper.
- My Drives: there is no domain-wide search an admin can run from the Drive UI. A user can search their own Drive with
sharedwith:public owner:meandsharedwith:external owner:me, or use the People filter chip → "Anyone with the link". In 8 minutes, ask the users who appeared most in part 1 to run those searches and send you the results; log each hit with Found by =search. - A full per-user pass is where 30 minutes becomes a day, and where the Admin console stops on Business editions. An org-wide scan does this step for every user's My Drive and every Shared Drive in one pass, with the same columns as the report template. The manual route is in finding every "anyone with the link" file across the domain.
3. Leavers and legacy access – 4 minutes
- Menu → Directory → Users. List everyone suspended or deleted in the window. Suspension blocks sign-in, but collaborators who were granted access to shared documents keep it – the leaver's shares still work.
- For each deleted user: were their files transferred at deletion? Untransferred files owned by a deleted user are kept for 20 days and are only recoverable by restoring the user. The offboarding checklist has the full sequence; suspended is not gone explains why.
- Search the report for domains you no longer work with – former agencies, clients, vendors – and mark those rows
legacy.
4. Decide – 3 minutes to decide, fixing on top
- For every
publicrow: does it need to be public? If not, restrict it and record who decided. - For every
externalrow shared with a personal address (gmail.com, outlook.com and the like): restrict or write a justification. - Sharing settings: Menu → Apps → Google Workspace → Drive and Docs → Sharing settings → Sharing options. Confirm the setting (Off, Allowlisted domains only, or On), the external-sharing warning, and whether it differs by organisational unit.
- Third-party apps, every other quarter: Menu → Security → Access and data control → API controls. Block any app with Drive access that nobody uses.
5. Record and schedule – 2 minutes
- Fill one row in the evidence log: date, window, owner, edition, files reviewed, public, external and legacy found, restricted, justified, incidents.
- Name the owner of the next audit and put the date in the calendar. Quarterly by default; monthly if you are regulated; always after a leaver.
- Export the report as the "external sharing report" whoever asked for it wanted. The access review post explains why log row plus export is what an auditor accepts.
Where the 30 minutes goes, and where it does not
Steps 4–7 and 11–19 fit the budget on any Business edition. Step 9 does not, once you have more than a handful of users: one search per person, per quarter, and the admin cannot run it for them. That is why the report template has a Found by column – so you can see, a year later, how much of the population you covered.
The flagship guide to auditing Drive access across the organisation is the long-form version of this page.
Sources
- Drive log events – Admin console path, 7-day default view, Visibility change attribute; the "View files shared outside of a domain" recipe (Add a filter → Visibility → Shared externally) and its group false-positive caveat; Audit & Investigation administrator privilege required; Download and Source Copy event names, external users appearing as anonymous, security investigation tool edition list.
- Data retention and lag times – Drive log events retained 6 months.
- File exposure report – edition list (Frontline Plus; Enterprise Plus; Education Standard and Plus; Enterprise Essentials Plus).
- Manage shared drives as an admin – path, filters for no members / no managers, member management.
- Shared drive access levels – only Managers add members.
- Manage external sharing for your organization – Sharing options path, Off / Allowlisted domains only / On, per-OU differences.
- Suspend a user temporarily – Menu → Directory → Users; "Collaborators who have been granted access to shared documents will retain their ability to view, edit, and collaborate on those documents."
- Delete or remove a user from your organization – transfer offered at deletion; untransferred files kept 20 days, recoverable only by restoring the user. Re-read 2026-09-09.
- Which edition and payment plan do I have? – Menu → Billing → Subscriptions.
- Control which third-party & internal apps access Google Workspace data – Menu → Security → Access and data control → API controls; apps listed with requested services incl. Drive; Trusted / Limited / Blocked.
- Find files shared with "Anyone with the link" (Stanford University IT) – People filter chip → Anyone with the link method.
- Google Drive search operators –
sharedwith:public owner:me,sharedwith:external owner:me, own Drive only. Re-read 2026-09-09.