Use cases → Documents and Drive
Control cross-domain Drive sharing with a delegated service account
Apply and audit sharing restrictions on Drive files to prevent data leaving your domain, using service account delegation for enforcement.
| Who it is for | Administrators and security teams responsible for information barriers or regulatory compliance. |
|---|---|
| APIs | Drive API, Admin SDK |
| Typical scopes | drive, admin.directory.user.readonly |
The problem
Documents can be shared externally, intentionally or by accident, and manual reviews are sporadic and incomplete. Relying solely on organisation-wide Drive sharing settings misses user-level exceptions and file-specific overrides.
How it works
- List all users and relevant files using the Admin SDK and Drive API, filtering for items with sharing outside the domain.
- Iterate through files and update permissions to remove or restrict external access.
- Log actions and exceptions for audit and follow-up.
- Schedule regular sweeps to catch new violations or bypasses.
What changes
External sharing is systematically detected and removed, reducing data loss risk and making enforcement auditable.
Watch it explained
“Google Drive SDK: CORS support” — Google for Developers on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.
Questions people ask
Can I enforce this for Shared Drives as well as My Drive?
Yes, but the service account must be explicitly added as a manager to each Shared Drive. Without this, permission changes are ignored with no error.
How do I find which files are shared externally?
Query the Drive API for permissions where 'domain' does not match yours or where 'anyoneWithLink' is true. Always filter on the effective permission, not just the explicit ones.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Rotate Drive access for external collaborators via automation
Regularly expire and re-grant Drive file access for external users without manual intervention or missed revocations.
Enforce Drive storage quotas on a schedule
Identify and act on users who exceed Drive storage limits by scanning usage periodically and triggering clean-up or escalation.
Migrate Drive data between teams with delegated access
Move shared Drive content for a whole team between organisational units or domains, preserving permissions and structure with a delegated service account.