Nirmion
HelpLog in Find a tool

Security & Privacy · THE NO-PANIC PLAN

Review Google Drive access for a sensitive shared document

A document can be exposed through a direct invitation, a broad link setting, a Google Group or permissions inherited from a parent folder. Reviewing one sensitive item means checking those paths and their owners before changing anything. This workflow is for Google Drive; Workspace administrators may have additional audit-log controls that ordinary users cannot see. Follow your organization?s access policy and preserve required business access. Nirmion?s Access Review Checklist helps record reviewers and actions, but changes must be made and verified in the Google account that owns or administers the file.

MISSION Find and reduce unnecessary direct, inherited and link-based access to a sensitive Google Drive file or folder while preserving access that authorized collaborators still need.

Review shared-file access

THE REAL-WORLD BIT

What happens outside this browser tab?

Identify the exact file and owner; inspect direct, group, link and inherited permissions; confirm each recipient and role with the data owner; make least-privilege changes at the correct parent or file level; and verify the final access state and document evidence.

YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES

One step at a time.

Follow the order below. If a step names a Nirmion tool, its link is right there with it.

  1. 01

    Identify the exact item, owner and sensitivity

    Record the document or folder name, canonical Drive location, owner, business purpose, sensitivity category and review date. Confirm that you are reviewing the authoritative item rather than a copy, shortcut or exported duplicate. Ask the owner or data steward which teams, external partners or service accounts still need access, and what action each collaborator must perform. Do not attach the document or paste its contents into the review record. If it contains regulated or highly sensitive data, follow the organization?s restricted-access and incident procedures before changing permissions. Google Drive permissions can apply to folders and affect files within them, so identify the parent path before treating a file?s visible collaborator list as the complete access picture. (Sources 1, 2)

  2. 02

    Inspect direct, inherited, group and general-link access

    Open Manage access for the item and record each direct person, group, role and any expiry date. Check General access for restricted, organization-wide or anyone-with-the-link settings, and determine whether collaborators receive access through a Google Group or parent folder. For folders, inspect the owner and inherited permissions; members may gain access when groups change, and a child item may inherit broader access than its direct list suggests. In a Workspace environment, ask an administrator to review relevant Drive audit events if you need a history of sharing or external access and have authorization. Treat missing log entries as unavailable evidence, not proof that access never occurred. Never forward a link to test it with an unauthorized account. (Sources 1, 2, 3)

  3. 03

    Confirm each person?s need and the minimum role

    Ask the accountable owner to confirm each named person, group or external collaborator still has a current work need. Distinguish viewing, commenting and editing; remove or reduce permissions only after confirming the task and any retention or collaboration requirement. Check whether a group?s membership is broader than the document?s intended audience and whether an external user is still under contract. Review link access separately: if broad access is unnecessary, change the general setting to Restricted and notify approved collaborators through a secure channel. Apply least privilege and preserve an approval record. Google notes that folder permissions can propagate to child items, so an item-level change may require adjusting the parent or moving the file to a correctly restricted location. (Sources 1, 2, 4)

  4. 04

    Apply approved changes and record them in the review checklist

    Use Nirmion Access Review Checklist (tool 853) to assign a reviewer and record the approved action, owner, due date and verification evidence; do not enter the document?s confidential contents. In Drive, change only the permissions authorized by the owner: remove former collaborators, reduce Editor to a role that fits, expire eligible access where available, restrict a link, or adjust a parent-folder/group permission when inheritance is the cause. If you are not the owner or lack permission to change the setting, request the owner or Workspace administrator to do it. Before changing a shared folder or group, identify all affected items and members so a narrow file review does not unintentionally remove access from an entire team. (Sources 1, 2, 4)

  5. 05

    Verify the final state and schedule the next review

    Reopen Manage access and confirm the intended people and groups retain the right role, undesired direct and link access is gone, and inherited settings now match the documented decision. Ask the owner or an authorized administrator to verify from the correct account; do not test by impersonating someone or sharing the file with an unapproved account. For managed Workspace accounts, retain permitted audit-log evidence and the change timestamp in the organization?s approved record system. Record unresolved owner/group changes, the approver, reviewer and next review trigger, such as a project end, contract end, role change or sensitivity change. If you discover an unauthorized public link or suspected data exposure, use the organization?s incident-response route promptly rather than treating routine cleanup as a complete response. (Sources 2, 3, 4)

THE HELPER CREW

Tools for the fiddly bits.

These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.

RECEIPTS, PLEASE

Sources & review notes

Each source is linked to the steps it supports. Open it to check its scope and current guidance.

Source checked 2026-10-08