domainwidedelegation.comStart free

Use cases → Documents and Drive

Control cross-domain Drive sharing with a delegated service account

Apply and audit sharing restrictions on Drive files to prevent data leaving your domain, using service account delegation for enforcement.

Who it is forAdministrators and security teams responsible for information barriers or regulatory compliance.
APIsDrive API, Admin SDK
Typical scopesdrive, admin.directory.user.readonly

The problem

Documents can be shared externally, intentionally or by accident, and manual reviews are sporadic and incomplete. Relying solely on organisation-wide Drive sharing settings misses user-level exceptions and file-specific overrides.

How it works

  1. List all users and relevant files using the Admin SDK and Drive API, filtering for items with sharing outside the domain.
  2. Iterate through files and update permissions to remove or restrict external access.
  3. Log actions and exceptions for audit and follow-up.
  4. Schedule regular sweeps to catch new violations or bypasses.

What changes

External sharing is systematically detected and removed, reducing data loss risk and making enforcement auditable.

The trap in this one. Drive API permission removals can silently fail on files in Shared Drives where the service account is not a member, or where the file owner’s sharing settings are more permissive than the domain policy. These failures do not throw errors but simply skip the change, so an audit pass may report success while files remain externally shared. You must explicitly verify the effective permissions after attempted changes.

Watch it explained

“Google Drive SDK: CORS support” — Google for Developers on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.

Questions people ask

Can I enforce this for Shared Drives as well as My Drive?

Yes, but the service account must be explicitly added as a manager to each Shared Drive. Without this, permission changes are ignored with no error.

How do I find which files are shared externally?

Query the Drive API for permissions where 'domain' does not match yours or where 'anyoneWithLink' is true. Always filter on the effective permission, not just the explicit ones.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Rotate Drive access for external collaborators via automation

Regularly expire and re-grant Drive file access for external users without manual intervention or missed revocations.

Enforce Drive storage quotas on a schedule

Identify and act on users who exceed Drive storage limits by scanning usage periodically and triggering clean-up or escalation.

Migrate Drive data between teams with delegated access

Move shared Drive content for a whole team between organisational units or domains, preserving permissions and structure with a delegated service account.