Sharing a file is granting access — we just forget it counts
A lean team shares files constantly and thinks about it almost never. Someone drops a link in a client email, flips a folder to "anyone with the link," attaches a contract to a chat thread, and moves on. Each of those is a real access-control decision — you have just granted someone the ability to read, and often to edit, company data — but it does not feel like one, because there is no request, no approval, and no record. It feels like sending a message. The result is that the most common way data leaves a small company is not a breach at all. It is a share link that outlived its reason, pointed at a file that was never as harmless as everyone assumed.
The problem is not that people share. Sharing is the work. The problem is that shares are created casually, scoped generously, and then never revisited — so a link created for a two-week deal is still live two years later, still resolving, still reachable by whoever forwarded it, whoever left the client, and whoever guesses the URL. This article is general guidance on sharing data with people outside your team without leaving that trail. The actual controls live inside your file platform — Google Workspace, Microsoft 365, Dropbox, whatever you use — and our platform's role is to help you organize, watch, and prove that sharing stays sane, not to configure your Drive or make anyone secure on its own.
The three ways external sharing goes wrong
Before fixing it, it helps to name the failure modes, because they are distinct and each has a different answer.
- The link that never expires. "Anyone with the link can view" is convenient precisely because it asks nothing of the recipient — and grants access to anyone the link ever reaches, forever, with no login and no trail. It is the single most over-used setting in collaborative file tools, and the one most worth reining in.
- The over-broad grant. Sharing the whole folder when the recipient needed one file, or granting edit when they needed view. It is the least-privilege problem in miniature, made worse by the fact that folder shares silently extend to everything added later.
- The external guest who quietly became a permanent fixture. A contractor added to a shared drive for a project, still a member long after the project ended — the file-sharing cousin of skipping an offboarding step, except the person was never an employee, so no offboarding process ever covered them.
Every one of these is invisible in the moment. None of them announces itself. That is exactly why sharing needs a discipline rather than good intentions.
Set defaults that fail safe
The highest-leverage move is to change what happens when someone shares without thinking, because that is the common case. If the easy path is also the safe one, you have solved most of the problem before anyone has to make a decision.
- Default new shares to named people, not open links. Requiring the recipient to sign in turns an anonymous, forwardable URL into an auditable grant tied to an identity — the same reason you route internal access through single sign-on rather than scattered standalone logins.
- Prefer view over edit, and files over folders. Grant the narrowest thing that does the job. A folder share is a standing promise about every file you will ever put in it, which is rarely what anyone actually means.
- Put expiry on external access by default. A link or guest grant that dies on its own after 30 or 90 days converts a permanent liability into a temporary one, and turns "we forgot to revoke it" from a silent risk into a non-event. Renewing a still-needed share is cheap; discovering a two-year-old live link is not.
- Restrict who can share the most sensitive material at all. Your data classification should decide this: the folder holding customer records or signed contracts is not the folder anyone should be able to flip to "anyone with the link" on a Tuesday afternoon.
Defaults do the quiet work of protecting you from the shares nobody deliberated over — which is nearly all of them.
Know what "shared externally" actually looks like right now
You cannot manage sharing you cannot see, and the honest starting position for most lean teams is that no one knows the full picture. The files that worry you are not the ones you remember sharing; they are the ones you forgot. So the foundational step is visibility: a way to answer, at any moment, what is currently shared outside the company, with whom, and how broadly.
Both major workspace platforms expose this — reports of externally shared files, links set to "anyone," and guest members of shared drives. Treat that inventory the way you treat any other asset inventory: something you can enumerate on demand rather than reconstruct in a panic. The specific things worth surfacing:
- Every file or folder shared with "anyone who has the link," especially anything holding classified data.
- External domains with standing access to shared drives — which contractors, partners, and former collaborators are still members somewhere.
- Edit access held by people outside the company, which is a higher-risk grant than view and deserves a shorter leash.
The point of the list is not to eliminate external sharing — that would break the business. It is to make external sharing a known quantity instead of an accumulating blind spot, so the risky outliers stand out from the ordinary, necessary shares.
Sharing is data leaving — treat it like egress, not filing
It is tempting to think of file sharing as a filing-and-permissions chore, but strategically it belongs next to your data loss prevention thinking, because an over-broad share is one of the most common paths for data to leave without anyone deciding it should. The mindset shift is to stop asking "who did I mean to give this to" and start asking "who can actually reach this, and is that still true on purpose."
That reframing connects sharing to controls you already run. A file shared externally should still be protected by encryption in transit on the wire, and the recipient's access — like all access — is only as trustworthy as the identity behind it, which is why open links that require no authentication are the weakest form of sharing you can choose. Sharing is not a break from your security model; it is a place your security model either holds or leaks.
Review external access on a cadence, and prove it
Even with safe defaults, access accretes. New shares get made, projects end, people leave, and the population of "who can reach our files from outside" drifts upward unless something pulls it back down. The fix is the same lightweight rhythm you apply to internal permissions: a periodic review, treated as real work, that closes what is no longer needed.
- Run a recurring external-sharing review, the external-facing sibling of your access reviews: walk the list of externally shared items and standing guests, and revoke everything that no longer has a live reason.
- Turn a stale or over-broad share into a tracked finding with an owner and a due date, ranked with the same exposure-first triage as everything else — a "public link" on a folder of customer data outranks a view-only share of a marketing one-pager.
- Watch for drift, not just the starting state, because the risk is created continuously; a share count that only ever goes up is a continuously monitored signal, not a one-time cleanup.
- Keep the review as evidence. A dated record that you check external access and remediate the outliers is exactly the kind of artifact that lands in audit evidence when an assessor asks how you control access to company data.
One honest caveat: a platform can help you keep the inventory of what is shared externally current, turn the risky outliers into tracked findings, and prove that you review and prune external access on a schedule — it organizes, watches, and proves the work. It does not reach into your Drive or SharePoint and revoke a link for you, decide which shares are legitimate, or make you compliant, and no tool by itself grants any certification; the sharing settings, the revocations, and the judgment about what a client actually needs are steps your team owns, and which data-handling obligations apply to you is a question for counsel.
A share link is an access grant that never felt like one, which is why lean teams accumulate them until "who can reach our files" is a question nobody can answer. Fix it at the source: default shares to named people with expiry, prefer view over edit and files over folders, and treat "anyone with the link" as the exception it should be. Then see what is actually shared right now, review it on a cadence, and prune the links that outlived their reason — before one of them outlives the company that trusted you with the data.