ISSUE 26 · 6 MIN READ ·

The Drive files still shared with clients who left years ago

Tightening your sharing policy only governs new shares. Folders you opened to a former client or a personal Gmail years ago stay open. How to find them in ten minutes.

A few years ago you were mid-project with a client, and it was easier to just share the folder. You put their address into the sharing box on a Google Drive folder — often a personal Gmail, because that’s what they used — set it to “can edit”, and got on with the work. The project ended. The contract wrapped up. Maybe the client moved on, or the contact left their firm. Everyone shook hands and moved to the next thing.

The folder is still shared with them.

Nobody decided that. When a relationship ends, the emails stop and the invoices stop, but the sharing doesn’t — a Drive share has no notion of “this engagement is over”. It sits exactly as you left it, quietly granting a stranger’s inbox continued access to whatever is in that folder, plus anything you’ve added to it since. And because the change happened years ago, it has long since scrolled out of anyone’s memory and off the end of the audit logs.

That’s the quiet failure: not a breach, not a broken setting, but a slow accumulation of doors you opened for good reasons and never closed.

Why it stays invisible

Sharing is designed to be effortless and permanent, and that’s exactly the problem. Granting access takes two seconds and produces a small notification; removing access takes a deliberate act that nobody is ever prompted to perform. There’s no expiry by default, no “this share is a year old — still needed?” nudge. Left alone, a share simply persists.

Two things then hide it from you. First, tightening your organisation’s sharing policy — turning off external sharing, or restricting it to named domains — governs new shares going forward; it generally doesn’t reach back and revoke the ones already granted. You can lock the front door and still have handed out keys years ago.

Second, the audit trail fades. Admin logs and Drive’s activity records only go back so far — often six months, sometimes less on standard plans — so a share created three years ago simply isn’t in the log you’d think to search. The event that matters happened before your visible history begins. From where you sit today, everything looks tidy: your current policy is strict, recent activity looks normal, and an old folder quietly open to a departed client’s personal Gmail raises no alarm at all.

Find it yourself

You can get a real picture of who has access from outside your organisation in about ten minutes. You’ll want administrator access for the thorough version; there’s a no-admin fallback below.

  1. As an administrator, open the sharing report. In the Google Workspace Admin console, go to Reporting → Reports → Apps reports → Drive — every edition, including Business Starter, gets this summary of how much is shared outside the organisation. On Enterprise Plus, Education Standard and Plus, Frontline Plus and Enterprise Essentials Plus, there’s also the fuller file exposure report: go to Security → Security center → Dashboard and open the external file sharing panel. Google does reshuffle these menus from time to time, so if a label has drifted, head for Reporting or the security dashboard and look for Drive sharing.

  2. Filter to external and to “anyone with the link”. Narrow the view to files shared outside your domain, and separately to files set to “Anyone with the link”. These two buckets are where the old, forgotten grants live. Sort by owner or by date if you can, so the oldest shares surface.

  3. Scan the external addresses for people who’ve gone. Look down the list of external collaborators for former clients, contractors, agencies and — especially — personal Gmail addresses, which are almost always individuals rather than a company you still deal with. Anything tied to a finished project or a contact who has moved on is a candidate to revoke.

  4. Use the investigation tool if you have it. On the Enterprise, Education and Frontline editions — no Business edition includes it — the investigation tool at Security → Security center → Investigation tool lets you query Drive by visibility and by external collaborator directly, which is faster than eyeballing a report. If you don’t have it, the report in step 1 is enough.

No admin access? You can still check the folders you personally own. In Drive, open Shared with me and your own key project folders, right-click each and choose Share to see exactly who’s on it. Work through the folders from past clients and projects — you’ll likely find at least one external address that should have come off long ago.

The fix

The aim isn’t a one-off purge that quietly rebuilds itself; it’s to close what’s open and change the habit that opened it.

Revoke the stale external shares you found. For each old grant tied to a finished relationship, remove the external collaborator, or switch a folder off “Anyone with the link”. Start with the personal Gmail addresses and former clients — the ones most clearly outside anyone you still work with.

Share with expiry from now on. When you next share something externally, set an access expiry date (Workspace supports this for non-Google-account and external collaborators), so the share closes itself when the project should. A door that locks on its own is one you never have to remember to lock.

Tie offboarding to sharing, not just logins. When a client engagement or a contractor ends, add “remove their access to shared folders” to the wrap-up checklist, in the same breath as the final invoice. The reason these pile up is that ending a relationship has an email step and a billing step but no sharing step — give it one.

Prefer shared drives with managed membership. For ongoing external collaboration, a shared drive whose membership you manage centrally beats a sprawl of individually shared folders, because you can see and change who’s in it from one place instead of hunting folder by folder.

None of this is urgent in the way a live incident is, which is precisely why it’s worth a calm hour now rather than an anxious one later. Close the old doors, switch on expiry, and the quiet accumulation stops accumulating — the next departed client takes their access with them instead of leaving it behind.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.