by Drive Explorer
Find out who has access to your Google Drive files. Scan personal and Shared Drives to detect external links, view permissions, and bulk manage access in Google Sheets™.
💡 Tip: Scan any folder or Shared Drive to inspect Owners, Editors, Viewers, and Public link states across all nested subfolders.
Google Drive file permissions govern who can view, comment, edit, or delete sensitive content. Understanding each permission level is essential for auditing and maintaining least-privilege security.
Owner
Owns the file and consumes personal Drive storage quota. Only the owner can permanently delete files or transfer file ownership to another user in the domain.
Editor / Content Manager
Can edit file content, create new files, share with additional collaborators (unless restricted by the owner), and move or trash files within folders.
Commenter
Can view contents and submit suggested edits or comments. Commenters cannot alter document content directly or re-share files.
Viewer
Strict read-only access. Viewers can open, inspect, and read files. Copying, printing, or downloading can be restricted by the owner.
General Access: Restricted vs Link
Determines whether people need explicit email invitations ("Restricted") or if anyone with the link (or anyone in your Workspace domain) can gain access.
Limited Access (Inheritance Broken)
In Google Drive, subfolders normally inherit parent permissions. "Limited Access" disables inheritance so only specified members can access the nested folder.
While My Drive files are owned by individual accounts (and count toward personal storage), files in Google Workspace Shared Drives belong to the entire organization. Shared Drives introduce specialized roles like Manager (full access including member management), Content Manager (default editor role), and Contributor (can edit and add files, but cannot delete or move folders). Auditing Google Shared Drive permissions ensures that contractors or former teammates do not retain persistent access to company assets.
Giving someone access, choosing their permission, and creating a link all happen in the same sharing dialog. Here is what each choice actually does.
Open the Share dialog
Right-click the file or folder in Google Drive (you can select several files first) and click Share.
Add the person
Type a name or email address. People without a Google account can still join: Workspace orgs with visitor sharing send a PIN-verified guest invite (7-day sessions), and everyone else gets an email invitation to create a free Google account.
Pick the permission
Choose Viewer, Commenter, or Editor — that choice is the permission they receive. The access roles above show the differences.
Click Send
They get an email with a link to the item, and it shows up under "Shared with me" in their Drive.
Everyone you add gets the same access to every file in the folder — including files you add later.
You cannot give someone less access to a single file than they have on its parent folder. Drive will point you to the folder’s permissions instead.
A file you move out of the folder loses folder-based access, but anyone you shared that file with directly keeps theirs.
Under General access in the same dialog, you choose who can open the item with nothing but its URL:
Restricted — only the people and groups you have added can open it.
Anyone with the link— this is the “shareable link”: anyone who has the URL can open it, usually without signing in, and it will not show up in Google Search.
Your domain— anyone signed in to your organization’s account (Workspace accounts only).
Use Copy link to grab the URL, and set General access back to Restricted to switch a shareable link off again.
A shareable link keeps working for anyone the URL reaches — forwarded, pasted, or scraped. The Share Status column in the tool above flags files where link sharing is still on.
Sources: Google Drive Help — Share files from Google Drive · Stop, limit, or change sharing.
Short answer: yes, by default. Viewers, commenters, and editors can all download, print, and copy until the owner turns that off — the sharing settings have a checkbox for each role group.
Always can download
You own the file and its storage quota.
Can download by default
Edit access includes downloading — but the owner can turn download, print, and copy off for editors too, with a separate “Editors” checkbox.
Can download by default
The owner turns download, print, and copy off by unchecking “Commenters and viewers.”
Can download by default
Same control as commenters — the owner switches both off with one checkbox.
Google’s own permissions table lists downloads for viewers and commenters as “Yes, by default. The owner can control it.”
Select the file or folder
Right-click it in Google Drive (selecting several files works too) and open Share. Set the option from a folder’s dialog to cover everything inside it.
Open the sharing settings
Click the gear icon at the top of the sharing window.
Uncheck the role groups to restrict
Under “People who can download, copy, and print,” uncheck “Editors” or “Commenters and viewers.”
Click Done
The download, print, and copy options disappear for those roles on that item.
Workspace admins can enforce this at the drive level instead of per file:
In the Google Admin console, open Drive and Docs → Manage Shared Drives.
Select the Shared Drive, open Settings, and uncheck “Allow viewers and commenters to download, print, and copy files.”
Save. The setting applies to every file in the drive, and members cannot switch it back on.
The default for newly created Shared Drives lives under Drive and Docs → Sharing settings → Shared drive creation.
It does not spare editors: “Editors” has its own checkbox, so their download, print, and copy can be switched off too.
It cannot recall a copy someone already downloaded, and it cannot stop screenshots.
There is no Drive-wide switch for My Drive files: the control lives on each file (or per Shared Drive in the Admin console).
It does not reach owners: restricting an owner takes a Workspace admin Drive DLP rule.
Google Drive does not show you who has access across a whole folder tree — external addresses, “anyone with the link” files, limited-access subfolders. Scanning the folder with the tool above is how you find those.
Sources: Google Drive Help — Share files from Google Drive · Google Workspace Admin Help — Manage shared drives as an admin.
Google Drive makes sharing effortless — which also makes unauthorized access accumulation inevitable over months and years of collaborative work.
Dormant Ex-Employee & Contractor Shares
When contractors, interns, or employees depart, individual file shares created outside Shared Drives often remain live, leaving proprietary documents accessible to personal Gmail accounts.
Accidental "Anyone With the Link" Exposure
Colleagues frequently switch permissions to "Anyone with the link can view/edit" to bypass login barriers. These links can be forwarded, scraped, or leaked indefinitely.
Compliance Audits (SOC 2, ISO 27001, HIPAA)
Auditors require regular quarterly access reviews demonstrating that sensitive customer data, employee records, and financials are restricted strictly to authorized stakeholders.
Nested Permission Drift & Orphaned Folders
Files moved into shared folders often retain previous direct shares or augmented permissions that aren’t visible from parent directory inspection.
Why manual file inspection fails for growing workspaces and enterprises.
Native Google Drive UI
Drive Explorer Permissions Auditor
Follow these three simple steps to extract a complete access report and verify exactly who has view, edit, or public access to your files.
Click the "Select Google Drive Folders" button above. Choose any personal folder, Shared Drive, or client directory. Drive Explorer securely connects through Google official OAuth dialog in your browser.
Tip: Selecting a root folder will recursively scan all nested subfolders and files.
Check "Export file details to a Google Sheet™" and provide a sheet URL (or view results in-browser). Drive Explorer iterates through files and populates columns for Owner, Viewers, Commenters, Editors, and Share Status.
All processing occurs locally in your browser — zero files or metadata are uploaded to external servers.
In your Google Sheet, use Data → Create a filter. Search for external domains (e.g. personal @gmail.com accounts or former contractors), identify files marked "Anyone with the link", and update permissions.
Use the Drive Explorer Add-on (Extensions → Drive Explorer → Share) to share or update access directly from Sheets.
Prefer to write your own custom script? Use this Google Apps Script template to iterate through a folder and print sharing permissions directly into Google Sheets.
auditFolderPermissions.gs
/**
* Google Apps Script: Audit Google Drive File Permissions
* Logs file owners, viewers, editors, and public sharing status to the active sheet.
*/
function auditFolderPermissions() {
const folderId = "YOUR_FOLDER_ID_HERE"; // Replace with your target folder ID
const folder = DriveApp.getFolderById(folderId);
const sheet = SpreadsheetApp.getActiveSpreadsheet().getActiveSheet();
// Append audit header row
sheet.appendRow([
"File Name",
"File ID",
"Owner",
"Sharing Access",
"Sharing Permission",
"Editors",
"Viewers",
"File URL"
]);
auditFolderRecursive(folder, sheet);
}
function auditFolderRecursive(folder, sheet) {
const files = folder.getFiles();
while (files.hasNext()) {
const file = files.next();
try {
const owner = file.getOwner() ? file.getOwner().getEmail() : "Shared Drive Item";
const access = file.getSharingAccess();
const permission = file.getSharingPermission();
const editors = file.getEditors().map(u => u.getEmail()).join(", ");
const viewers = file.getViewers().map(u => u.getEmail()).join(", ");
sheet.appendRow([
file.getName(),
file.getId(),
owner,
access.toString(),
permission.toString(),
editors || "None",
viewers || "None",
file.getUrl()
]);
} catch (err) {
Logger.log("Error reading file: " + file.getName() + " - " + err.message);
}
}
// Recursively audit subfolders
const subfolders = folder.getFolders();
while (subfolders.hasNext()) {
auditFolderRecursive(subfolders.next(), sheet);
}
}Important Technical Limitations of Google Apps Script:
• 6-Minute Execution Limit: Google Apps Script enforces a hard 6-minute maximum runtime per execution. If your folder contains more than ~300 files, the script will time out before completing.
• DriveApp Rate Limits: Calling file.getViewers() and file.getEditors() makes multiple synchronous API requests per file, easily triggering Exceeded maximum execution time or Drive quota errors on mid-sized drives.
• Drive Explorer Alternative: Drive Explorer bypasses Apps Script execution limits by processing batches directly through official Google Drive REST APIs in your browser with automated pagination.
Drive Explorer is fully compatible with Google Workspace Shared Drives. All file metadata processing happens strictly in your browser and never touches third-party servers.
Google Verified
Drive Explorer undergoes recurring security audits by Google to maintain access to Drive APIs. We meet Google's strict security and privacy standards.
No Server Storage
Your file data never touches our servers. We don't collect, store, or transmit any of your Google Drive files or folder information.
Frontend Processing
All operations happen entirely in your browser. Your data stays on your device and is never sent to any external server.
Need scheduled access audits, continuous compliance monitoring, or bulk sharing management? Drive Explorer runs directly inside Google Sheets™ and connects to Google Workspace for instant permissions visibility and reporting.
Answers to common questions about Google Drive share permissions, access audits, and security.
Everything you need to audit, organize, migrate, and optimize your Google Workspace storage.