Google Workspace makes external sharing effortless and cleanup nearly impossible. Here’s why manual audits won’t fix it, and what will.
Right now, there are files in your company’s Google Drive that someone shared externally and forgot about. Maybe they shared something with a contractor whose project wrapped last year. Or maybe it’s a folder set publicly to “anyone with the link can view,” and that public link is sitting in an old email or Slack thread, or even buried in a Jira ticket somewhere. No one remembers or needs the file access anymore, but the sensitive data inside it is still accessible to people outside your organization.
This isn’t one person’s fault. It’s a design choice. Cloud drives are designed for collaboration, and sharing file access takes seconds at most. Google made it easy to share a file with anyone who needs it. Working with a consulting group? Here are our financial reports from the past two years. Four different teams need this document? Sure, I’ll just grant everyone view access. This project would be great for my portfolio, let me share it to my personal email. It’s a frictionless process on purpose, but that also creates the problem at hand: what takes an employee one second multiplies and turns into thousands, or even millions, of external shares that are rarely ever reviewed, never mind revoked.
At our own organization of around 50 employees, we have nearly 1,000 externally shared files. We’ve heard from organizations that are staring down millions of files left to clean up. Even after months of manual auditing, sensitive company data is still exposed outside the organization: orphaned drives, shares to personal emails, stale shares to that agency or contractor you worked with eight years ago.
Someone is responsible for cleaning that up and protecting sensitive data. Google, one of the cloud file sharing companies that made the mess this easy to create, doesn’t make it easy to clean up. So most organizations accept the unknown, unquantified risk of perpetual external file access.
If I'm being honest—not much.
You might assume that Google would have something to help manage their sharing model, but when I took to Reddit (as many others seem to have also done), what I found were threads upon threads like this one encouraging OPs to manually audit each file, providing homemade Google Slides with flow charts, sharing scripts they’d developed that they run on a regular basis, and occasionally offering words of consolation.
To find out who's sharing files externally, an admin has to open the audit logs, hand-build a query for visibility changes, and export the results into a spreadsheet they then have to maintain by hand. Even then, the log only tells you a file’s visibility changed to external, not who currently has access across your whole Drive, whether those shares are still active, or whether any of them expose sensitive data. It’s an administrative record, not a security view. The underlying permission data lives in Google’s APIs (which is exactly why admins resort to writing their own scripts to pull it), but Google gives you no native, risk-aware way to see it all in one place and act on it.
Auditing files by hand only gets harder as a company grows. It never gets easier. We’re talking about the same incalculable math for reviewing every single OAuth grant introduced to an org, or every new third-party browser extension that employees download. (That’s the whole reason we built AI agents directly into our platform).
To manage external file shares across Google and other file sharing platforms, organizations need visibility across every single file without going on a scavenger hunt, insight into what risks a file holds, and the ability to act on it fast: revoking access, changing ownership, and so on, all while operating within your org’s own data policies.
Nudge Security shows you every externally shared file, folder, and Shared Drive across your Google Workspace in one place. No queries to build, no spreadsheet to babysit, no manual chasing.
It works through your existing Google Workspace connection. Once connected, Nudge Security can view the sharing and permission data Google already holds and turns it into something you can use. For every shared item, you can see who has access, what they can do with it, whether the owner still works here, and how long it's been since anyone opened it.
We also surface what deserves your attention first. A file shared to a personal Gmail account. A Shared Drive with no active owner. A share left open by someone who left two years ago. A folder set to "anyone with the link" that no one has touched in a year. You can group shares by domain too, so instead of staring at a hundred thousand rows, you start with the domains and people holding the most access.
Then you can do something about it without leaving the platform. Tighten or revoke access on any file, folder, or Shared Drive, with a confirmation that spells out what will change before anything does.
Take a look:
Every time someone shares a file, that's a small decision made at what we call the Workforce Edge, the place where work happens and risk grows.
External file sharing discovery is now available in open beta. Start a 14-day free trial today.