domainwidedelegation.comStart free

Use cases → Documents and Drive

Audit cross-domain sharing of Drive documents

Identify which files in your domain are shared externally, and flag risky or unexpected exposure across tenant boundaries.

Who it is forIT admins or security teams responsible for data loss prevention and external sharing oversight.
APIsDrive API
Typical scopesdrive.readonly

The problem

Files intended for internal use are often shared externally, sometimes by accident, sometimes by design. Over time, the list of externally accessible files grows, and manual checks are patchy at best. Audit requirements or incident response often require a full, up-to-date inventory of these exposures.

How it works

  1. Use a delegated service account with domain-wide delegation to impersonate a super admin or auditor account.
  2. List all users in the domain, and iterate through each user's Drive files using the Drive API, filtering for files with external permissions.
  3. Extract and log sharing details, recipient domains, and permission types to a central report.
  4. Flag files shared with 'anyone with the link' or with specific external domains for review.
  5. Schedule regular runs to catch new shares and changes.

What changes

You gain a reliable, repeatable inventory of all externally shared files, making it possible to track exposure over time and respond to audit requests with evidence.

The trap in this one. Drive API's permissions list can lag behind actual sharing state by several minutes, especially for recently changed files. If you run an audit immediately after a bulk permission change, you may miss or misreport exposures. Always account for propagation delay by rerunning audits after a grace period, and never assume a single pass is complete for files edited in the last hour.

Questions people ask

Can I filter only for files shared outside the domain?

Yes, by inspecting each permission object for email addresses or domains not matching your own. Do not trust summary fields; always parse the full permissions list.

Does this catch files in Shared Drives?

Only if you explicitly list and audit Shared Drives and their contents. User Drives and Shared Drives require separate queries; missing one is a common oversight.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Create a client folder structure the moment a deal closes

Provision a consistent Drive folder tree, seeded with templates and shared with the right people, automatically.

Generate documents from a template and real data

Produce agreements, letters and reports from a Docs template with fields filled from your systems.

Sort incoming files into the right place automatically

Watch a drop folder, work out what each file is, and file it where it belongs with a consistent name.