Review what each folder is shared with, remove people who no longer need it, replace open links with named access, and check what has been shared outside the business entirely.

Permissions only accumulate

Access gets granted because somebody needed a file, and it never gets removed because nothing prompts anybody to remove it.

Over a few years that produces a drive where everybody can reach everything: payroll, contracts, customer records, and the folder somebody made for a project that ended in 2019.

Nobody decided that. It is the sum of forty small reasonable decisions, none of which was ever reversed.

The same is true of links: a share created to send one document to one person remains live indefinitely, and frequently grants access to the folder rather than the file.

What the review looks for

The third is the one that produces genuine surprise, because an open link is not visible from inside the folder unless somebody looks at the sharing settings deliberately.

The link is the sharp edge

Worth separating because it behaves differently from named access.

A link set to anybody with the link can be forwarded, pasted into an email chain, included in a document, or indexed if it appears somewhere public.

It does not expire, it is not attached to a person, and revoking it requires somebody to remember the file exists.

Named access is different: it is attached to an account, it appears in a list you can review, and it is removed when somebody leaves.

The rule worth adopting is that links are for things you would not mind being public, and everything else is shared with named people.

Where a link is genuinely convenient, set an expiry if the platform supports it, which most now do.

Start with the sensitive folders

A full review of every folder is a project nobody finishes.

Instead, list the folders that would matter: payroll and employment records, financial records, contracts, customer data, anything with passwords or keys, and anything commercially sensitive.

That is usually five or six folders in a small business.

Review those properly, fix what you find, and treat the rest as a lower priority to be worked through when there is time.

Doing five folders thoroughly is worth more than starting a complete audit and abandoning it in week two.

A worked example

A firm reviewed sharing on their main drive expecting a few stale permissions.

Two people who had left, one of them three years earlier, still had access to everything.

An accountant they no longer used had access to a folder containing four years of financial records.

Eleven open links existed, of which one led to a folder containing employment records and had been created to send a single template to a new starter.

And the payroll folder was shared with everybody because it lived inside a parent folder that was.

Fixing it took about two hours: removing four accounts, revoking nine links, and moving payroll out of the inherited structure.

Nothing had gone wrong, and the employment records link had been live and forwardable for two years.

Inheritance is what catches people

The mechanic behind most surprising findings.

Sharing a parent folder generally shares everything inside it, including subfolders created later by somebody who had no idea the parent was shared.

So a folder created last month for sensitive material inherits permissions granted three years ago to a shared project folder.

The practical response is structural: keep sensitive folders outside any broadly shared parent, at the top level, shared explicitly with the people who need them.

Check inheritance specifically when reviewing, since a folder can appear correctly restricted while inheriting access from above.

Make it part of leaving

The single change that stops this rebuilding.

Whatever you do when somebody leaves should include removing their access to the drive, transferring ownership of anything they created, and checking for links they made.

Ownership is the one that gets missed: files created by somebody are often owned by their account, and deleting that account later can remove or orphan the files.

Transfer ownership before the account is disabled rather than afterwards, which is considerably easier.

Add it to whatever list already covers keys, uniforms, and the final invoice, since that list gets followed and a separate one will not.

Set a review date

Because this is a recurring problem rather than a one-off fix.

Once a year, look at the sensitive folders again: who has access, which links are live, and whether the structure still matches how the business works.

Put it in the same month as another annual task so it happens, and give it a named owner.

It takes under an hour once the first review has been done, because you are checking a known list rather than discovering one.

Most platforms can also report on external sharing, which makes the annual check faster and is worth finding once.

The counter-case

Restricting access has real costs and can be overdone.

A small business runs on people being able to find things, and a drive locked down folder by folder produces a daily tax of requests, delays, and files being emailed around instead, which is worse for security than the sharing you removed.

Most material genuinely does not need restricting: job photographs, templates, marketing files, and general documents are fine shared widely.

The distinction is between broad access to ordinary material, which is efficient, and broad access to payroll and contracts, which is not.

Restrict the five folders that matter and leave the rest open, which is both more secure and less irritating than a general lockdown.

The review

  1. List the five or six folders that would matter.
  2. Check who has access to each, including inherited.
  3. Remove anybody who has left or no longer needs it.
  4. Find and revoke open links.
  5. Move sensitive folders out of shared parents.
  6. Add access removal to your leaving process.
  7. Diarise an annual review.

Step four produces the finding people remember, and open links are invisible unless somebody looks for them deliberately.

Departures are covered in who still has access after they left.


Frequently asked questions

Why do shared drives end up open to everyone?

Because access is granted when somebody needs a file and never removed afterwards. Nothing prompts a reversal, so permissions only accumulate.

What is the problem with share links?

A link set to anybody with the link can be forwarded, pasted into an email chain, or indexed. It does not expire and is not attached to a person, so revoking it requires remembering the file exists.

Should I review every folder?

No. List the five or six that would matter, such as payroll, financial records, contracts, and customer data. Doing those thoroughly beats abandoning a complete audit in week two.

What is inheritance?

Sharing a parent folder generally shares everything inside it, including subfolders created later by somebody unaware of it. Keep sensitive folders outside broadly shared parents.

What should happen when somebody leaves?

Remove drive access, transfer ownership of files they created before the account is disabled, and check for links they made. Add it to the list that already covers keys and the final invoice.

Can restricting access go too far?

Yes. A locked-down drive produces requests, delays, and files emailed around instead, which is worse. Restrict the five folders that matter and leave ordinary material shared.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Never looked at your open links?

Check the sensitive folders for anybody-with-the-link sharing. That is the finding people are not expecting.

Start a Conversation