domainwidedelegation.comStart free

Use cases → Documents and Drive

Track cross-domain document sharing in Google Drive

Map every document shared outside your domain, recording who shared it, with whom, and when, using a delegated service account for Drive.

Who it is forIT administrators and compliance teams responsible for data leakage prevention across multiple Workspace tenants.
APIsDrive API, Admin SDK
Typical scopesdrive.readonly, admin.reports.audit.readonly

The problem

Users frequently share files with external parties, but the built-in Drive sharing reports lag behind and often miss changes made by scripts or third-party tools. Manual audits are slow, incomplete, and don't scale across large domains or multiple tenants.

How it works

  1. Iterate all users with the Admin SDK to obtain their primary email addresses.
  2. Impersonate each user with a delegated service account and list files they own via the Drive API.
  3. For each file, enumerate permissions and flag any that grant access to accounts or groups outside the domain.
  4. Record the file, owner, external sharee, permission type, and timestamp for reporting or remediation.

What changes

You get a near real-time, domain-wide index of externally shared documents, including who shared each one and when. This enables proactive review and targeted clean-up.

The trap in this one. Drive API's permissions.list endpoint can omit inherited permissions from parent folders, especially if the file itself has no direct external shares. This leads to false negatives—documents appear private when they're actually visible outside the domain. Always check both the file and its parent folders for permissions, and expect propagation delays of up to several minutes after a share change.

Questions people ask

Can I get notified instantly when a new external share happens?

No. The Drive API does not push real-time sharing events. The closest you get is polling with some delay, or consuming Admin audit logs, which can also lag.

Does this capture links shared via 'Anyone with the link'?

Yes, but only if you explicitly check for permissions with type 'anyone' or 'domain'. These are easy to miss if your script only looks for named external users.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Rotate Drive access for external collaborators via automation

Regularly expire and re-grant Drive file access for external users without manual intervention or missed revocations.

Enforce Drive storage quotas on a schedule

Identify and act on users who exceed Drive storage limits by scanning usage periodically and triggering clean-up or escalation.

Migrate Drive data between teams with delegated access

Move shared Drive content for a whole team between organisational units or domains, preserving permissions and structure with a delegated service account.