Automation
Google Drive Permissions Audit Automation · Complete Business Guide
9 min readAmichai Shekel
How to automatically clean open permissions in Google Drive? A practical guide for business owners to prevent data leaks and spot accidental shares.
You send a price quote link to a client, forgetting that anyone in your organization, or anyone with the link, can view, copy, or edit the file. After a year and a half of operations, your business drive is cluttered with 4,200 shared files tied to former vendors, departed employees, and casual clients without any oversight. The business risk grows every single day you have no idea who holds the keys to your sensitive documents.
This guide is built for managers and business owners who want to solve this issue without hiring an external cybersecurity expert or manually reviewing files for hours. We will show how to build an automated workflow that scans your business folders, flags anomalies, sends organized alerts, and resets unnecessary open permissions before they turn into legal or commercial liabilities.
By the end of this read, you will know exactly how to set up basic automation managing your information access, what the real project costs are, where common risks lie, and one small action you can take tomorrow morning to close the most glaring gaps in your business drive.
The Core Problem · Why Drive Permissions Spin Out of Control
Small organizations start out working conveniently. Edit access is granted to anyone requesting a link, project folders are opened to everyone because there is no time for granular permissions, and the status quo is forgotten. After 12 months, over 60% of organizational files are open to anyone on the internet with the URL. This feels convenient daily, but the moment a key employee departs or an old vendor keeps a stored link, your business data is entirely exposed. Good automation does not block daily work, it creates transparency preventing leaks without hurting team velocity.
How Permission Audit Automation Works
The technological foundation is very simple. Instead of reviewing every file manually, we connect a script or an automation tool like Make that runs weekly, enters the corporate Google Drive, reviews all documents and folders, and checks for specific conditions: Is access set to Anyone with the link? Are there external users with personal Gmail suffixes holding editor permissions? The system aggregates all these findings into a central control sheet or form, sending a targeted summary to the operations manager. This lets you handle only standout anomalies instead of wasting time on compliant folders.
What the Automation Does in Practice · 4 Control Steps
- Weekly or daily scan of all files and folders in the organizational drive based on defined filters.
- Automatic identification of files shared with the public domain or unauthorized external domains.
- Creation of an updated control report in Google Sheets detailing file name, owner, and share link.
- Direct alert dispatch to a Slack channel or security officer's email within the business.
Step by Step · Building Your First Workflow
To build automation correctly so it lasts over time, you must follow a fixed operational sequence. You cannot jump straight to automated deletion before ensuring the script correctly identifies data.
Setting Up Targets and API Access Permissions
Establish a secure connection against your primary Google Workspace account. It is crucial to use a primary admin account or Service Account with appropriate permissions, while ensuring you do not grant full wipe access to the entire drive without manual confirmation.
Enjoyed the guide?
Want to build things like this yourself?
AI Master Club includes a live weekly session, recordings, ready-to-use tools, and a community that helps you apply them.
Defining Search Filter Criteria
Set the conditions where the system halts and flags a file as problematic. For example: sharingSetting equals anyoneWithLink or presence of external users outside the official company domain (company.co.il).
Generating Control Reports and Alerts
Every file found violating rules logs a new row in an internal control sheet. The system sends a weekly summary message containing the top 5 sensitive files requiring immediate action.
Copyable Prompt or Script Setup Template
Here is an exact instruction template you can feed into a development tool or automation wizard to produce the basic drive scanning script. No need to change anything except your own domain setting.
- Objective: Scan all Google Drive files in the organizational account.
- Detection criteria: Flag any file or folder where sharing is set to 'Anyone with the link' or an external user does not end with '@mycompany.co.il'.
- Output addition: Generate a documentation row in Google Sheets aggregating file name, owner ID, share type, and last scan date.
- Constraint: Do not delete or change permissions automatically. Only collect data and alert via Slack if over 10 anomalies are found in a day.
Risks, Costs, and Automation Limitations
Automation handling access permissions carries one central risk: misconfiguration could block access to critical business documents during routine work. Therefore, the golden rule is to scan and alert only during the first stage, and only after a month of stability allow staged automated remediation.
The cost of such a solution is significantly lower than hiring an external security expert. Most tools operate within standard automation packages costing between 29 to 99 dollars a month, or completely free using built-in Google Apps Script inside your account.
Practical Tips for Saving Time and Preventing Errors
Enjoyed the guide?
Now move from reading to doing
- 01A live AI session with Amichai every week
- 02Immediate access to the recording library
- 03Ready-to-use prompts, agents, and tools
- 04An active community for questions and implementation
Club membership
₪47 per month
No commitment. Cancel in one click at any time.
Always start with one closed folder as a proof of concept, such as accounting or human resources, and only after verifying the report displays accurate results should you expand the scan to the entire organization. It is recommended to schedule run times during late night hours (like 02:00 AM) to prevent straining private servers and avoid slowing down team work during the day.
Frequently Asked Questions on Drive Permission Automation
Do I need coding knowledge to set up this automation?
Not at all. You can use visual no-code tools like Make or use ChatGPT to generate ready-to-paste Google Apps Script code for you without writing a single line of code alone.
How long does it take to set up such a permission control system?
Initial setup and testing on a sample folder typically takes between one to two hours. Full deployment across the entire corporate drive requires about another hour of alert tuning.
Can the automation accidentally delete important files?
No, if you follow the guidelines in this guide. The proposed script performs reading and filtering only and does not touch files themselves, unless you consciously choose to add a permission modification action.
What is the monthly cost of such automation tools?
Using Google Apps Script is completely free within your Google Workspace account. If you choose to use the Make platform, the cost will run around 9 dollars a month for standard small business volume.
Enjoyed the guide?
Want to build things like this yourself?
AI Master Club includes a live weekly session, recordings, ready-to-use tools, and a community that helps you apply them.
Does this work for personal Google accounts as well?
Yes, but the most powerful tools for checking external shares work best in business Google Workspace accounts where broad permissions must be managed.
How do you handle shared files that must remain public?
You can pre-define a Whitelist in the script or control sheet so the system ignores marketing or public files that do not require stringent security.
What do you do if too many alerts are received per day?
This indicates the threshold is too sensitive. You should adjust the threshold so the system alerts only on files containing sensitive keywords like salaries, contracts, or passwords.
Your Next Action for Tomorrow Morning
Tomorrow morning, open Google Drive, navigate to the Shared files tab, and run a quick sort by date or share level to identify at least three critical files accidentally open to everyone. From there, proceed to build the basic script or join us at the AI Master Club to see exactly how to implement advanced automation workflows without losing business control.


