Opens in a new tab

Controlling Google Drive and SharePoint sharing permissions: where should SMEs start?

Nhóm nhân sự cộng tác tài liệu và thư mục cloud

Quick answer: Google Drive and SharePoint help teams collaborate quickly, but sharing permissions can expand quietly. A folder that started as a sales workspace may later include accounting, partners, former employees or public links. SMEs should start with critical folders, data owners, permission groups, external sharing, edit rights and leaver access.

Why cloud sharing gets out of control

Traditional file servers are often permissioned by IT at the folder level. Drive and SharePoint let users share files, create links, invite outsiders and move data into personal spaces. That speed is useful, but without rules, quotations, contracts, HR files, finance data and project documents can become over-shared.

The risk rarely appears on day one. It accumulates after months of department changes, completed projects, copied folders and ownership changes. When an incident occurs, nobody can quickly answer who has access to what.

Permission types to check

Permission type Question to answer Better operating practice
Owner Who is accountable for this folder? Assign ownership by department or process
Editor Who can change or delete files? Use groups instead of adding individuals
Viewer Who only needs to read? Separate view-only and edit access
External sharing Are outsiders included? Limit by project and review date
Public links Are any anyone-with-link URLs active? Require approval and owner review
Former users Do leavers still own files? Transfer ownership and remove access

Monthly review checklist

The company does not need to inspect every file every day. Start with important data groups: finance, contracts, quotations, HR, customers, projects and technical documents. For each group, identify the owner, root folder, viewers, editors, external links and files owned by former employees.

  • List business-critical folders by department.
  • Check public or external sharing links.
  • Transfer ownership from departed employees.
  • Prefer groups over individual permissions.
  • Document exceptions and next review dates.
  • Add the result to the monthly IT or security report.

What should the report say?

A useful access report should not only list the number of files scanned. It should show folders with external users, links that allow anyone-with-link access, owners who no longer work at the company, sensitive folders without a named owner and exceptions that need management approval. This turns a technical permission review into a business decision list.

For SMEs, this report can be short. The important part is that each risky permission has an owner, a reason to keep it, or a planned removal date. Without that owner, the same risky shares will remain open after every review.

How this connects with DLP and backup

Permission control does not replace Data Loss Prevention, but it reduces exposure before DLP rules are needed. DLP detects or controls sensitive data movement; permission governance limits who can access the data in the first place. For cloud documents, the business should also consider backup if accidental deletion, ransomware sync or compromised accounts are real risks.

Frequently Asked Questions

Should external sharing be disabled completely?

Not always. Many businesses need to collaborate with customers or partners. The key is ownership, scope, reason and review date.

Are permission groups better than individual sharing?

Yes. Groups make onboarding and offboarding easier and reduce scattered access from former users.

Do Google Drive and SharePoint need separate backup?

Consider it for important data, especially if retention, accidental deletion or ransomware recovery requirements exceed the platform defaults.

Need to standardize cloud data access?

IT Systems can review users, groups, Drive, SharePoint, leaver access and data-sharing risks as part of recurring IT administration.

View IT system administration