Access and permissions: who should see what
Most access problems come from the same root cause: sharing that was generous when it was set up and never reviewed. An ex-contractor still in the shared folder, a "anyone with the link" document floating around, a whole team with edit access to a folder where they only ever read. None of this needs security software to fix — it needs simple rules and a regular look.
Start default-private
The simplest policy that works: new folders and documents start private, and access is granted deliberately. It's much easier to open things up as needed than to discover later that something sensitive was visible to everyone. When someone asks "why can't I see this folder?", the answer should be "let me add you" — not "I didn't know you could."
Share by role, not by person
Give access based on what someone needs to do, not who they are:
- Viewers can read and download. This is the right level for most people, most of the time — reports, reference documents, policies.
- Editors can change things. Reserve this for the people who actually produce the content in that folder.
- Owners or admins can change permissions and the structure. Keep this group tiny — one or two people per area.
If your tool supports sharing with groups (a mailing list, a team group), use groups instead of naming individuals. When someone joins or leaves, you update the group once instead of hunting through dozens of shared folders.
Sharing links need hygiene
Links are convenient and also the most common way access leaks. A few habits:
- Prefer links that require sign-in over "anyone with the link" links, especially for anything internal or sensitive.
- Set expiration dates on links shared with outsiders when your tool supports it. A link that dies in 30 days can't be forwarded around forever.
- Before forwarding an "anyone with the link" document further, stop and ask whether it should be one — switch to a named share first if it matters.
Audit access twice a year
Access decays: people change roles, contractors finish, projects end. Twice a year, go through your main shared areas and ask three questions:
- Who has access? Look at the actual sharing list, not who you think has access.
- Do they still need it? Former employees, finished contractors, and people who moved teams come off the list.
- Is the level right? Anyone with edit access who only ever reads goes down to viewer.
This takes less time than it sounds, and it catches the slow accumulation that turns "the finance folder" into "the folder half the company can edit."
Offboarding is part of access control
When someone leaves — employee, contractor, volunteer — removing their access should be a checklist item on their last day, not a "we'll get to it." The list:
- Remove them from shared drives and folders.
- Remove them from groups that grant access automatically.
- Transfer ownership of anything they owned (documents, forms, automations) to someone staying.
- Check for personal accounts used for work sharing and move the data first.
Keep the model simple enough to explain
The final test of any permissions setup: can you explain it to a new person in two minutes? "Everyone sees their team's folder, editors are the content owners, the admin group is just the two of us, and we review access every six months" is a complete access policy for most small teams. If your setup needs a diagram, it's too complicated — and complicated permissions are the ones nobody maintains.