Use cases → Documents and Drive
Remove all external Drive shares in bulk across a domain
Systematically find and revoke external sharing links and permissions from Drive files using domain-wide delegation.
| Who it is for | IT and security teams responsible for data exposure in Google Drive. |
|---|---|
| APIs | Drive API, Admin SDK |
| Typical scopes | drive, admin.directory.user.readonly |
The problem
External sharing often persists long after the original need, exposing sensitive documents outside the organisation. Manual cleanup is slow and error-prone, especially at scale, and compliance reviews require repeatable, auditable processes.
How it works
- Enumerate all users in the domain via the Admin SDK.
- For each user, impersonate them and list their Drive files.
- Identify files and folders with permissions granted to external users or with shared links.
- Remove external permissions and disable link sharing using the Drive API.
- Log each change for review and audit.
What changes
External access is removed systematically, reducing exposure with a clear audit trail for compliance.
Questions people ask
Can I remove all external shares in one API call?
No. Permissions must be listed and revoked per file or folder, and inherited shares require checking the full folder hierarchy.
How do I ensure nothing is missed?
Repeat the process after a delay to catch propagation lag, and always handle both files and parent folders.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Rotate Drive access for external collaborators via automation
Regularly expire and re-grant Drive file access for external users without manual intervention or missed revocations.
Enforce Drive storage quotas on a schedule
Identify and act on users who exceed Drive storage limits by scanning usage periodically and triggering clean-up or escalation.
Migrate Drive data between teams with delegated access
Move shared Drive content for a whole team between organisational units or domains, preserving permissions and structure with a delegated service account.