Security · Tech Notes

Google Drive security best practices

How Macktez structures Google Drive shared drives into internal, allowlist, and external tiers, and audits permissions annually to limit access.

April 9, 2025

Cloud file sharing services like Google Drive make it easy to work with collaborators outside your organization, sharing files far more broadly than you could with an on-premises file server. But that same openness, used without care, can hand access to the wrong people. And because permissions can be added at any time with no expiration, access that was appropriate for a moment can become a permanent, unmonitored way in.

Best practices

The principle of least privilege means each file and resource should be accessible to the fewest people necessary, and only for a legitimate operational purpose.

Elevated permissions — folders and files that external users can potentially reach — should be clear and explicit to everyone who uses the storage system regularly.

We recommend at least annual audits and policy reviews to purge permissions exceptions that get introduced into storage systems but have outlived their purpose.

Real-world implementation

We spent the first quarter of 2025 reviewing our own Google Drive policies, structure, and permissions exceptions. We made a few key updates to highlight permissions exceptions (when they are still needed), with a clearer divide between shared drives that allow external sharing and those that do not.

We use three tiers of permissions allowance:

  • Internal (no external sharing permitted)
  • Allowlist sharing (external sharing on individual files permitted only to specific domains)
  • External sharing (external sharing on individual files permitted)

In Google, each tier is set up as an Organizational Unit (OU) with its own security policies. Each top-level Shared Drive in Google Drive is then assigned to one of the three OUs.

  • The Internal OU holds Shared Drives such as "HR" and "Finance" — folders with documents that should never be shared with anyone who does not have a macktez.com address. By default, any new shared drive starts in this OU, so that any permissions added are added intentionally.
  • The Allowlist OU holds project folders that are primarily for internal use but may have more collaborative components with specific partners. In those cases we can add an external domain for ongoing sharing. We keep the number of domains in the allowlist very low, and share only specific collaboration subfolders — named to identify them as collaboration folders — with those external domains.
  • The External OU holds files that are exceptions to our default sharing guidelines, allowing more flexibility for external sharing. We have one-off collaborative documents with clients (ongoing meeting notes, asset lists, case studies, SOPs), vendors, and other partners that do not rise to the level of allowlisting an entire domain but still require collaboration. Storing them in this External OU keeps us intentional about the permissions a file is allowed to have.

Assigning a resource to one of these three OUs does not fully define its accessibility. Every file and folder still needs individual permissions. But the OU puts a ceiling on permissions options that is vital for organizational security.

Audit process

We review our permissions policies annually. This year we are paying particular attention to one-off collaborations that are no longer current. Since it is not practical to audit every single file and decide access individually, we are comfortable making broad determinations that reduce access. Adding access back when requested is always possible, and it keeps the rationale for exceptions up to date.

For example, a file from 2022 that was shared with two people outside Macktez but not accessed in the past 12 months is reverting to default permissions, accessible only by Macktez Team Members. One of those external collaborators may have a reason to try to open the file again; if they do, see that they no longer have access, and still need it, they can reach out and we can re-add them if that is still appropriate.

Key takeaways

  • Security is not a set-it-and-forget-it proposition. Review security policies at least annually.
  • Regular audits keep security rationales relevant. Even when you properly follow the principle of least privilege, exceptions inevitably creep into any storage solution. Plan for periodic purges of permissions exceptions.
  • Err on the side of limiting access. Setting stricter defaults means file sharing mistakes are more likely to be the kind where someone lacks access they should have, rather than the kind where too many people have access they should not.
  • Use naming conventions to identify areas of broader access. Name files and folders that are accessible outside your organization to clearly identify their intended audience.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.