"I just shared the link for now"—a phrase frequently heard in organizations using Google Drive. While effortless sharing is a major benefit, incorrect settings can inadvertently expose confidential company information to the public internet.
Targeting small and medium-sized businesses and teams using Google Workspace, this article systematically explains Drive sharing settings from the ground up: organizational settings in the Admin console, proper permission assignment, and secure external sharing practices. Master the key principles of configuration to bolster security without sacrificing internal and external collaboration efficiency.
Google Drive sharing settings: Understanding the three layers
Google Drive sharing settings are controlled across three layers: "Organization (Admin)," "Shared drives," and "Individual files/folders." Restricting access at a higher layer prevents permissions from being loosened at lower layers. Understanding this hierarchical architecture is the starting point for secure operations.
1. Organization level (Admin console)
This is the top-level policy configured by administrators under "Admin console → Apps → Google Workspace → Drive and Docs → Sharing settings." It centrally controls domain-wide rules including whether external sharing is permitted, link-sharing scopes, and permissions for downloading, printing, and copying.
2. Shared drive level
For each shared drive, you can configure settings individually, such as whether to permit sharing with external users or allow access to anyone with the link. This is effective for segmenting access scopes by project or department.
3. Individual file and folder level
These are the most familiar sharing settings, configured by users via the "Share" button. However, if restrictions are imposed at the organization or shared drive level, users can only configure permissions within those boundaries. Following a specification change in September 2025, child files can no longer have different access settings from their folders, inheriting settings from the parent folder instead.
Choosing permissions: Selecting properly between Viewer, Commenter, and Editor
There are three types of permissions you can set when sharing individual files. Adhering to the principle of least privilege by granting only the minimum level necessary is fundamental to mitigating data breach risks.
| Permission | Permissions | Recommended use cases |
|---|---|---|
| Viewer | View only | Distributing materials, reference-only documents |
| Commenter (Viewer + Comments) | View and add comments | Collecting feedback, requesting reviews |
| Editor | View, comment, edit, and change sharing settings | Collaborative drafting, team members responsible for data entry |
Particular caution is warranted with Editor permissions. By default, editors can also add other users and modify sharing settings. Administrators can disable this ability for editors to change sharing settings in the Admin Console. Organizations handling highly confidential documents should make sure to review this setting.
External sharing settings: recommended configuration in the Admin Console
Situations where you need to share files with users outside your organization will inevitably arise. Completely banning external sharing reduces business agility, making an approach that appropriately restricts permitted scopes more realistic.
Admin Console sharing setting options (key choices)
- Off — Completely prohibits external sharing. Suited for organizations requiring high confidentiality
- Share only with allowlisted domains — Restricts sharing exclusively to specified domains, such as business partners
- Allow sharing with external users who have a Google Account — Permits sharing only when the recipient is signed in with a Google Account
- Anyone (including people with the link) — The most open setting. Not recommended for anything other than public information
In practice, what works well for small and medium-sized businesses is combining options 2 or 3. It is also effective to segment organizational units (OUs), setting the company-wide default to 3 (requiring a Google Account) while configuring particularly sensitive departments to 1 (prohibited).
Prohibiting the "Anyone with the link" setting in principle
The setting requiring the most caution is the option allowing anyone with the link to access the file. If such a link is forwarded via email or shared on social media even once, there is a risk of confidential information falling into the hands of unintended third parties. Establish a clear organizational rule that this setting must not be used for anything other than content meant to be published publicly, such as recruitment information or press releases.
Shared drive settings: key points for distinguishing use with external members
When using shared drives with external members, there are several configuration precautions that differ from My Drive.
- External sharing can be controlled per shared drive: By separating dedicated shared drives for projects involving external members from internal-only shared drives, you create a structure that prevents external parties from accessing internal-only content
- Start external member permissions as Viewer or Commenter: Restricting permissions later tends to create friction, so starting with the minimum necessary permissions from day one is best practice
- Regularly review shared drive membership management: External members frequently remain in shared drives even after projects conclude, making it essential to establish a habit of conducting quarterly audits
Three additional settings to enhance security
In parallel with optimizing sharing settings, verifying the following configurations can further mitigate risk.
1. Restricting downloading, printing, and copying
You can prohibit viewers and commenters from downloading, printing, or copying files. This is effective when sharing view-only access to highly confidential contracts or financial documents. You can configure this by going to the file's Sharing settings and clicking the settings gear icon.
2. Setting expiration dates on sharing links
On Google Workspace Business Standard and higher editions, you can set expiration dates on sharing links. When temporary external sharing is necessary, establishing an expiration aligned with the project timeline prevents unnecessary access after the project concludes.
3. Utilizing alerts and audit logs
In the Admin Console under Reports > Audit > Drive, you can review logs detailing who shared which file with whom. You can also configure alerts to notify administrators when external sharing occurs. This is effective both for early incident detection and as a deterrent.
Regarding Google Drive security features, the recently officially released ransomware detection and file recovery capabilities are also vital topics. Implementation details are explained in the following article.
Practical operational workflow: creating a pre-sharing checklist
Even with proper settings in place, unintended configuration mistakes can occur during daily operations. Establishing a pre-sharing checklist at the individual and team levels significantly reduces human error.
- Who is the recipient? — Internal / External / Unspecified general public
- What level of permission is required? — View only / Comment / Edit
- What is the duration? — Set an expiration date if the timeframe is fixed
- Can downloading and copying be permitted? — Apply restrictions if the document is confidential
- Should notifications be sent upon setting changes after sharing? — Confirm whether to notify collaborators when changes occur
We recommend compiling this checklist into a team document or spreadsheet and utilizing it as training material for onboarding new team members.
For an overview of initial Google Workspace setup and the Admin Console, please also refer to this article.
Summary: reviewing configurations establishes continuous security
Configuring Google Drive sharing settings is not a one-and-done task. It is vital to review them regularly as your organization expands and relationships with external partners evolve.
- Clearly define organizational sharing policies in the Admin Console
- Establish requiring a Google Account and restricting sharing to specific domains as the foundation for external sharing
- Never use the "Anyone with the link" setting for anything other than public content
- Separate shared drives by project and department, and audit members on a regular basis
- Leverage audit logs and alerts to detect suspicious sharing early
When configured properly, Google Workspace sharing settings achieve both robust security and a seamless collaboration environment. If you have concerns about your current settings or wish to establish organizational security policies, consider consulting with specialists.
At GleamHub, we provide tailored support for small and medium-sized businesses, ranging from Google Workspace onboarding and configuration optimization to security policy development. Please feel free to reach out if you would like to verify whether your current settings are appropriate or need assistance establishing internal guidelines.









