1. Zen IT Technologies
  2. Technical notes
  3. The file server nobody provisioned

The file server nobody provisioned

Jonny Flaks, Founder & Principal Architect

Technical note in Identity & Access Management

Somebody needs to get a contract to a client this afternoon. The document is in their My Drive because that is where they wrote it. They click Share, enter the client's email address and send the link.

Nothing unusual happened. There was no Shared Drive configured for that client, nobody had said where external work should live, and Google Workspace allowed the file to be shared from My Drive, so the platform did not object.

Repeat that pattern for long enough and My Drive quietly becomes something nobody designed or approved: the company's external file server.

Nobody provisioned it. It is still where the work ended up.

How My Drive becomes the external file server

My Drive is where work naturally starts. Creating a document there is automatic and sharing it from there takes seconds, while moving it somewhere more appropriate first requires knowing where appropriate is.

If the organization has never defined that destination, My Drive inevitably becomes the default for client files, contracts, partner material, supplier information and everything else that eventually needs to leave the company.

Users did not choose the architecture. They followed the path the company gave them.

The Shared Drives were there the whole time

Having Shared Drives is not the same as having somewhere to put things.

On one engagement, a mid-sized Google Workspace tenant already had several dozen Shared Drives, only a couple of them clearly intended for external collaboration. Across the entire Shared Drive estate, the number of external members was zero.

The spaces existed. They just were not where the external work was happening. Nobody had created an obvious destination for the actual client, partner and supplier relationships the business had, so people kept doing what they had always done.

The company had provisioned dozens of Shared Drives. The file server its external relationships actually depended on was the one nobody had provisioned.

What the sharing data showed

Once we looked at the actual sharing state rather than the Shared Drive membership lists, the difference was hard to miss. Every file in that tenant that was publicly reachable by link sat in somebody's My Drive. The external grants surfaced in the review followed the same pattern: dozens of files reachable by anyone with the link, and several thousand shared directly with external recipients across hundreds of outside organizations.

Consumer email addresses were the largest external category by a wide margin. Some were employees sending work to themselves, some were legitimate counterparties who happened to use personal addresses, and others belonged to relationships nobody could still explain. Beyond that sat many thousands of files shared broadly across the company.

Almost none of this was visible from looking at Shared Drive membership, which is one reason a conventional access review can give a misleading picture of Google Drive. An entitlement review usually asks what this person can access. External sharing requires a different question: what has this company made accessible to somebody else? Those are not the same review.

Ownership follows a person

Files in My Drive are tied to the user who owns them, which becomes important when the user leaves.

During offboarding, an administrator can transfer a departing user's owned Drive content to another account. That solves the immediate retention problem without explaining any of the history. The new owner can inherit thousands of files created by somebody else, including documents they may never open and sharing relationships they did not create. Nothing in the transfer tells them whether an external grant from three years ago is still required, why a personal Gmail account can see a contract, or whether a supplier is still a supplier.

The content survived the employee leaving. The context did not.

Shared Drives change that ownership model. In a Shared Drive, the content belongs to the Shared Drive rather than to the individual user who created it, so someone leaving the company does not require the organization to find a new owner for every file they created there. That is one of the strongest governance arguments for Shared Drives, and it matters very little if the important content never gets into them.

The policy that was never narrowed

Underneath all of this was another problem: external sharing had never really been designed. Users could share Drive content externally because the organizational policy allowed them to, and there had been no decision that client work belongs in one location, supplier work in another, or that some parts of the organization should not share externally from My Drive at all.

Google Workspace has controls for this. External Drive sharing can be restricted, approved domains can be treated differently, policies can vary between parts of the organization, and Shared Drives can carry tighter restrictions around external and non-member access.

Finding the setting is not the difficult part. Turning it on safely is. Restrict external sharing tomorrow without knowing what currently depends on it and somebody's live business process breaks: a client loses a document, a supplier stops receiving files, a board member loses access to something nobody knew was being distributed from an employee's My Drive. That is why permissive sharing configurations can stay untouched for years.

The policy change is easy. Knowing what it will sever is the work.

The safe place to begin is read-only. Measure the current sharing state before changing it: what is externally shared, where it lives, who can reach it and which business relationships depend on it. Then change the policy without guessing.

Shared Drive membership is not the whole access model

Moving externally shared work into Shared Drives is the right direction, and it is not the whole solution.

A Shared Drive membership list does not necessarily describe everybody who can reach the content inside it. Unless the appropriate restrictions are configured, individual files and folders can still be shared with people who are not members, and if the wider organizational policy permits external sharing, some of those people can be outside the company.

On the same engagement, roughly two hundred Shared Drive membership entries sat above more than ten thousand direct file-level grants. Reviewing membership alone would have described only a small fraction of the access model.

The Shared Drive had a membership model. The individual content inside it did not always follow the same boundary.

Someone still has to own the space

Shared Drive content is not owned by an individual user, but the Shared Drive still needs somebody responsible for it, and over time that responsibility can disappear. People leave, accounts are removed, teams reorganize and projects finish, and nobody remembers that one of the participants was also the only person managing the drive.

In the environment we reviewed, twelve Shared Drives no longer had a Manager. Five had no members at all. The content still existed; the organizational responsibility for it did not.

This is an offboarding problem as much as a Drive problem. Removing an account is not enough. You also need to know what that account was responsible for.

Moving content is not permission cleanup

There is another trap during remediation. A file has been identified in My Drive, so somebody moves it into the correct Shared Drive, and the natural assumption is that it is now governed by the new location.

That assumption needs to be verified. Moving content changes where it lives. It does not necessarily remove permissions that were granted directly on that content, and those grants need to be reviewed separately. A file arriving in the correct Shared Drive does not by itself prove that every old external grant has disappeared.

Restructuring and permission cleanup are two different jobs. Move the content, then check who can still reach it. Do not assume the first action completed the second.

What the design has to decide

Almost none of this starts as technical work. It starts with decisions nobody has been assigned to make.

Where does external collaboration happen? Create named spaces for the relationships that need them. A client, partner, regulatory process or category of external work should have an obvious destination.

What is My Drive for? Working material and personal drafts are reasonable. Long-lived company information with an external audience or retention requirement should not depend on one person's account.

Who is responsible for each Shared Drive? Every important space needs someone accountable for membership and restrictions, and that responsibility should be checked during offboarding rather than discovered missing years later.

Does membership come from groups? Where practical, access should follow the identity structure. Add somebody to the right group and they receive what they need; remove them and the access follows.

What is the sharing baseline? Decide which locations allow external sharing, whether non-members can receive individual content, where exceptions live, who approves them and when they are reviewed.

What does the organization allow from My Drive? This is the decision that determines whether the designed structure is real or merely recommended. The safe path and the convenient path need to become the same path.

Only then does the cleanup make sense. Revoking several thousand old grants without changing the structure that created them only resets the clock.

A control nobody explained is a control people route around

Restrict external sharing without telling people what to do instead and the sharing does not stop. It moves.

The contract still has to reach the client this afternoon. If Google Drive now refuses to share it, somebody attaches it to an email, uploads it to a file transfer service, or sends it from a personal account. The exposure has not necessarily been reduced; it has been relocated somewhere with less visibility, less control and often no practical way to revoke it later. That can leave the organization in a worse position than where it started.

Annual security awareness training does not solve this. The answer has to be much closer to the moment the work happens.

Put it in onboarding, not as a policy somebody clicks through but as the answer to a practical question. This is where client work goes. This is where internal drafts go. This is how you request a new space for an external relationship, and this is who to ask when you are not sure.

Give managers the same answer, because they are usually present when the question comes up. A team lead saying "put that in the client Shared Drive, not your My Drive" is worth considerably more than a policy document nobody remembers reading.

Explain the reason too. "External sharing from My Drive is restricted" sounds like an obstacle. "Client material lives in the client's Shared Drive so it survives people leaving and we can see who has access to it" is something people can understand. Most people will work with a control when they understand what it protects and have a practical way to do the job.

Announce restrictions before they take effect, with the exception path working on day one. Then watch what happens. If requests for new external collaboration spaces increase after the change, people are using the structure. If external sharing drops to zero and nobody asks for anything, the business probably did not stop sharing files, and it is worth finding out where they went.

The check worth running

Pick the three most sensitive external relationships in the company: a major client, a strategic partner, and your lawyers, accountants, auditors or another party that regularly receives sensitive material.

Ask one question. Where do those documents live?

If the answer is somebody's My Drive rather than a Shared Drive deliberately configured for that relationship, that is the posture. It tells you considerably more than counting how many Shared Drives the company has.

Explore this expertise: Identity & Access Management

All technical notes