Managed Google Drive access audits

Know exactly who can reach your team's files.

Every share your team has ever made in Google Drive stays live until someone turns it off: ex-contractors, former clients, the public links you forgot. We audit your whole Drive with you, lock down what shouldn't be open, and then watch it so nothing quietly leaks again.

Guided setup, read-only by default. We're onboarding teams from the waitlist. Nothing in your Drive changes unless you choose to revoke access.

CLIENT DELIVERABLES / SCAN
๐Ÿ“ Client Deliverables you ยท owner
๐Ÿ“ Contracts mara@studioplo.com ยท editor
๐Ÿ“„ Q3 retainer.pdf inherited
๐Ÿ“ Brand assets 2 people
๐Ÿ“„ logo-final-v4.ai anyone with the linkRevoke
๐Ÿ“„ fonts-license.txt not shared
๐Ÿ“„ invoice-archive.xlsx jt@formerclient.io ยท viewer

What a scan reveals

Drive's own sharing screen shows one file at a time. A scan reads the whole folder tree at once and shows who has access, person by person, not file by file.

Public links

Files anyone can open

Every item set to "anyone with the link", including ones you shared years ago and forgot. A report flags these before anything else.

Outside collaborators

Every external address

One row per person: what they can reach across the whole tree and the highest role they hold. Former contractors show up here.

Inherited vs. direct

Where each grant lives

Whether access flows from a folder share or sits on the file itself. Grants made directly on a file survive un-sharing its folder.

How it works

STEP 1

Join the waitlist

We'll email you when it's your turn. Onboarding connects read-only access, so there's no IT project and nothing to install. Google only asks for change permission later, if and when you decide to revoke something.

STEP 2

We audit your whole Drive with you

One pass reads every file your team owns and reports it by person, not by file: public links, outside collaborators, and whether each grant is inherited from a folder or sits on the file itself.

STEP 3

Lock it down, then we watch it

Revoke stale access in bulk (reversible in one click), then monitoring keeps running. You get alerted when a new public link or outside share appears, instead of finding out a year later.

The audit that doesn't go stale

Access sprawl comes right back the moment someone shares a new file. Monitoring keeps your audit current, so you're not starting from scratch every quarter.

Continuous monitoring

We watch for new exposure

After the first audit we keep checking your Drive for newly public links and new outside collaborators, so the report reflects today, not the day you signed up.

Change alerts

Told when it matters

Get notified when a file is newly shared with the world or an outside domain, instead of discovering it in next year's review after the damage is done.

Records you can hand over

Export & compare over time

Every audit exports to CSV and prints cleanly, and you can compare any two points in time. That helps when it's for a client, an auditor, or a SOC 2 control.

Careful by design

Read-only default

The standard sign-in can only read sharing metadata. Write access is a separate consent, asked for only when you revoke.

Tokens encrypted

Your Google credentials are encrypted at rest and never leave the backend. Sessions live in an HttpOnly cookie.

Reversible actions

Every unshare keeps a record of the original role, so one click restores it. No one gets an email about it.

Yours to delete

Scan reports belong to your account. Delete any scan and its data is gone from our storage.

The full details are on the security page.

Common questions

Will this change anything in my Drive?

Not on its own. Scanning is read-only. Your Drive changes only when you press Revoke on a specific permission, and you can undo that from the same report.

What access does it ask for?

At sign-in: your basic profile and read-only Drive access (drive.readonly). If you later choose to revoke a permission, Google will ask you separately to grant full Drive access. That's the scope revocation requires, and the app asks for it only at that moment.

Does it work with shared drives?

Yes. Shared Drives combine drive-wide membership roles (Manager, Content Manager) with sharing on individual files and folders on top of that, the same inherited-vs-direct split Drive Auditor already reports on for My Drive. It covers both, alongside My Drive, where personal sharing sprawl usually piles up unnoticed.

How much of our Drive can you audit?

The whole thing. One pass inventories every file you own in My Drive, often thousands of files, and reports who can reach each one. Large Drives run in the background and fill in as they go.

What does it cost?

Pricing is per organization: a guided setup plus ongoing monitoring. We're finalizing numbers before launch. Join the waitlist and we'll follow up with a quote.

See who can reach your team's Drive.

Join the waitlist and we'll email you when it's your turn.

Join the waitlist