"We moved all our critical files from individual drives to shared drives. Now they won't disappear even when employees leave, so we're safe"—at a company where this was said, an uproar occurred a few weeks later when an entire folder that was there the week before suddenly vanished. Upon investigation, there was no malicious intent; a team member intending to clean up their own workspace folder had accidentally moved an adjacent team's folder into the trash. Moving files to a shared drive was fundamentally the right move. The problem was that everyone had been granted permissions allowing them to do anything.
The decision to consolidate individually managed files into shared drives was addressed in our article on migrating from My Drive to shared drives. This article covers the next step: deciding who should be allowed to do what once files are moved. If you skip this, the consolidated repository you worked so hard to build turns into a place that anyone can inadvertently break.
Shared drives feature five permission tiers
Members of a shared drive are assigned one of the following five roles. Permissions become broader and more powerful toward the top.
| Role | Permissions | Recommended target |
|---|---|---|
| Manager | Everything, including adding/removing members, altering permissions, and deleting the shared drive itself | A very small number of people, such as IT team members or department heads |
| Content manager | Creating, editing, moving, deleting, and organizing files (cannot manage members) | Operational leads who regularly organize folders |
| Contributor | Creating and editing files (cannot move or delete) | The vast majority of regular members |
| Commenter | Viewing and commenting only | Collaborators who only perform reviews |
| Viewer | View only | Stakeholders who only need reference access |
Accidents occur in many companies because they ignore these distinctions and assign everyone as a Manager or Content manager. The well-intentioned desire not to hinder anyone with permission roadblocks results in an environment where anyone can delete or move folders. The missing folder incident mentioned earlier was a prime example of this pattern.
How strictly should you limit who can delete and move files?
When planning roles, the most effective starting point is determining who is allowed to delete and move files. Contributors can create and edit files, but they cannot move or delete them. In other words, if the majority of members are made Contributors, daily tasks proceed smoothly while preventing accidental deletions of other teams' folders.
On the other hand, employees who need to organize folders and clean up unneeded files require Content manager permissions. Setting up a structure where only one or two people per team hold this role clarifies accountability for folder maintenance while limiting the blast radius of any mistakes. Full Manager permissions should be reserved for the IT team handling onboarding, offboarding, and permission adjustments. This three-tiered structure—very few Managers, a limited number of people who can delete, and the vast majority as Contributors—is the foundational setup for preventing accidents.
Pay attention to external members and files outside shared drives
Along with assigning roles, you should verify whether external accounts are present in your shared drives. It is not uncommon for contractor or partner accounts to remain members of shared drives long after contracts have ended. Establishing an operational rule to review membership lists upon resignations or contract terminations, combined with a design that separates policies by organizational unit (OU), significantly reduces the burden of auditing access.
Another frequently overlooked scenario is when files assumed to be inside a shared drive still reside in personal My Drive folders, or are redundantly shared via "Anyone with the link." Carefully architected permissions are rendered useless if backdoors remain open. How to audit "who can see what in the first place" is covered in detail in our article on auditing sharing settings. Designing roles and auditing access must always proceed hand in hand.
Redesign permissions before files go missing or are leaked
Shared drives become a safer alternative to personal storage only when roles are assigned correctly. Leaving broad permissions granted to everyone amplifies risk rather than reducing it through centralization. Simply limiting deletion and moving rights to a few individuals while making the majority Contributors, and auditing external members alongside duplicate sharing, will prevent most incidents.
"We moved our files to shared drives, but we don't know who should have which permissions," "We noticed everyone has become a Manager, and we're terrified to touch anything," or "Former partner companies might still have access to our internal folders"—if you share these concerns, please feel free to consult GleamHub's Google Workspace implementation and operations support. We will work alongside you to audit and redesign roles tailored to your actual business operations.









