domainwidedelegation.comStart free

Use cases → Documents and Drive

Automated monitoring for external sharing violations

Detect and report when Drive files or folders are shared outside the organisation using a delegated service account.

Who it is forIT security and compliance teams responsible for controlling data leakage.
APIsDrive API, Admin SDK
Typical scopesdrive.readonly, admin.reports.audit.readonly

The problem

Manual spot-checks miss most external shares, especially when users grant access to personal accounts or external contractors. Policy enforcement is inconsistent and after-the-fact, with little visibility into what is actively exposed.

How it works

  1. Run a scheduled process as a delegated admin service account.
  2. List all files and folders in shared drives and user Drives.
  3. Check permissions for any non-domain users or link-sharing set to 'Anyone with the link'.
  4. Log and alert on any matches, including details of who shared and when.
  5. Optionally trigger remediation workflows (e.g., remove share, notify owner).

What changes

External shares are detected within hours, not months, and compliance teams can act before leaks become incidents.

The trap in this one. Drive API 'permissions.list' can lag several minutes behind actual sharing actions, especially for large folders or shared drives. A file shared and then immediately unshared may never appear in your monitoring window, producing false negatives. Relying solely on point-in-time polling means you can miss rapid share/unshare cycles that leave no trace in the current permissions list — only the Admin Reports API audit log will show these events.

Questions people ask

Can I detect when a file was shared and then unshared quickly?

No, not with Drive API alone. You must cross-reference with the Admin Reports API's Drive audit log to catch transient sharing events.

Does this approach catch all shared content?

It covers files the service account can enumerate, but hidden items (like orphaned files or those in suspended accounts) require extra care to include.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Rotate Drive access for external collaborators via automation

Regularly expire and re-grant Drive file access for external users without manual intervention or missed revocations.

Enforce Drive storage quotas on a schedule

Identify and act on users who exceed Drive storage limits by scanning usage periodically and triggering clean-up or escalation.

Migrate Drive data between teams with delegated access

Move shared Drive content for a whole team between organisational units or domains, preserving permissions and structure with a delegated service account.