Notes

Google Drive Permissions: How to Prove Who Can Open a Folder

A navy folder built from square blocks, with five small navy squares lined up beside it for the people who can open it, and one red square sitting off the line.

Somebody has asked you to prove who can open a folder in Google Drive. It could be a client, an insurer, a bank, or the member of staff who just handed in their notice. There is no one screen in Drive that answers the question, and that is why it is hard to answer.

For a single folder, the Google Drive permissions live in two places in the Share dialog, not one. Google’s own help puts it plainly: to find a complete picture of who can open a file, always check both the “People with access” list and the “General access” setting. The first names people. The second decides whether a link works for anybody holding it. Read one and miss the other and you have half an answer.

For the whole business at once, there is one report in the Admin console, filtered to files shared outside your own domain. It lists sharing that happened. It is not a live list of who can open what, and the difference matters.

Google’s Drive and admin help pages here are the ones on its site on 25 September 2026, and the two sharing changes below carry the dates Google put on its own announcements.

Before you check anything, the rule that catches people out: the folder decides. Google says files and folders inside a shared folder always inherit that folder’s permissions, and calls the parent folder “the primary source of truth for access”. You can no longer lock one file tighter than the folder it sits in by naming fewer people. One sentence on Google’s page cuts the other way for link sharing, and the section on the September 2025 change deals with it. If your last set of instructions told you to restrict a single file, they are out of date, and that section explains what replaced them.

How to see who can open one folder

Open the folder’s Share dialog and read two settings, not one. You do not need to open a single file inside it.

  1. On a computer, open Google Drive and find the folder.
  2. Right click the folder, click More, then File Information, then Details. A panel opens showing who owns the folder and who has access to it.
  3. Click Manage access to open the full sharing dialog. You will only see this if you have permission to make changes.
  4. Read the People with access list. These are the named people and groups. A group counts as everyone in it, so a group row can hide ten people behind one line.
  5. Read the General access setting. Restricted means only the people in that list can open the folder. Any other setting means a link does the deciding, and a link travels.
  6. If a section headed Access removed appears, read it, and then read the callout below before you believe it.

That sequence is the answer to the audit question for one folder. The trouble is that it only covers one folder. If the question you were asked is about a whole client archive or a whole finance folder, doing this by hand stops being a check and starts being a project.

How to check the whole business at once

One report, filtered one way. In the Admin console, the Drive log events report will list files your people shared outside your own domain, which is usually the half of the question somebody is actually worried about.

  1. Sign in to the Google Admin console with your administrator account.
  2. Go to Menu, then Reporting, then Audit and investigation, then Drive log events.
  3. Click Add a filter, choose Visibility, and select Shared externally.
  4. Click Search.
  5. Export the results to Sheets or a CSV file with Export all if the person who asked wants something they can keep.

Two things about that report, because they decide what you can honestly say about it.

It is a record of events, not a list of permissions. It tells you that a file was shared externally on a given day, by whom, and with what visibility. It does not answer “who can open this folder today”. Google is direct about the gaps: not all activities in Drive are logged, and most Drive audit events are logged only for files owned by users on supported editions. So treat a clean report as an absence of logged sharing, not as proof that nothing is open.

You need the right administrator privilege. Running a search on the Audit and investigation page needs the Audit and Investigation administrator privilege. If you are the only admin on the account, you already have it. If somebody granted you a narrow role, you may not, and the page will not be there.

Sharing is one line in a longer list of things worth switching on once and then leaving alone. The rest of that list is in our Google Workspace security checklist, which walks Google’s own fourteen items for a small business.

Google also sells a second, deeper tool, the security investigation tool, which can set up alerts and act on results. It is worth knowing it exists and worth not planning around it: Google lists it for Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus and Cloud Identity Premium. A business of five to fifty staff on a Business plan is not on that list. The same goes for the sharing boundaries Google added for Drive on 15 September 2026: the availability list names Enterprise, Education, Enterprise Essentials and Frontline editions, and no Business edition at all.

What each sharing role can actually do

There are two sets of roles, not one, and they are not the same size. A shared drive has five access levels. A file or folder in My Drive has an owner plus three roles. Mixing the two up is an easy mistake on this topic, so here they are separately.

The five access levels on a shared drive

Start with the line that surprises people: all members of a shared drive can view all files and folders in it. The access level does not decide whether somebody can see your work. It decides what they can do with it and whether they can hand it to anybody else.

What each shared drive access level allows, from Google’s own permission table (Google Workspace Learning Center, 25 September 2026)
Can they Manager Content manager Contributor Commenter Viewer
View files and folders Yes Yes Yes Yes Yes
Comment on files Yes Yes Yes Yes No
Edit files Yes Yes Yes No No
Add and remove people on a specific file Yes Yes Yes No No
Add and remove people on a specific folder Yes Yes, unless an admin or a Manager has switched it off No No No
Set limited access on a folder Yes No No No No
Add or remove members of the shared drive Yes No No No No

Content manager against Contributor is the pair people ask about. Both can edit files, create files and folders, and add or remove people on a single file. The difference is reach. A Content manager can share a whole folder, move files and folders to the trash, and move things around inside the shared drive. A Contributor cannot do any of those three. There is also a trap outside the browser: in Google Drive for desktop, and in the Chrome OS Files app, Contributor access gives read access only. If your bookkeeper works in the desktop app and cannot save a file, this is the first thing to check, and Content manager is the fix.

Only a Manager can set limited access on a folder, which is Google’s way of walling off one subfolder so that only the people it is shared with can open it, even though everybody can still find the folder above it. Only a Manager can add or remove members of the drive, too. If one person in your business is going to be responsible for answering the audit question, that person needs Manager on the drives that matter.

The roles on a file or folder in My Drive

Outside a shared drive, the set is smaller and the owner carries more weight.

Owner
One person, usually whoever created the file. The owner can take away an editor’s ability to change permissions or share the item. Ownership is also what makes a file leave the business when its owner’s account is deleted, which the last section deals with.
Editor
Can change the file. By default an editor can also change sharing permissions and share the file onward, so an editor is closer to a co-owner than the word suggests. You can switch that off in the Share dialog’s settings.
Commenter
Can read the file and comment on it. Cannot change the file itself.
Viewer
Can read the file. Nothing else. This is the answer to the other question people ask: a Commenter can comment, a Viewer cannot, and neither can edit.

My Drive or a shared drive: who owns the file

In My Drive, one person owns each file. In a shared drive, the team owns them. That single difference decides most of what happens next, including who can lock a folder down and what walks out of the door when somebody resigns.

My Drive belongs to a person. Every file in it has one owner. If that person shares a folder out of My Drive, the sharing hangs off their account. When you move a file out of somebody’s My Drive into a shared drive, Google is explicit about what changes: you are still the creator of the file, but no longer the owner.

A shared drive belongs to the business. Google’s admin help is unusually blunt about why that matters: keep the files teams collaborate on in shared drives and the files are owned by the entire team, so you do not need to worry about losing them when somebody leaves. It is the cleanest single answer to the ownership problem, and Google gave shared drives to Business Starter customers too, so the lowest Business plan already has them.

A shared drive is not a private space, though, and this is where owners get caught. All members of a shared drive can view all files and folders in it. If you put the payroll folder in the company shared drive, everybody in that drive can read it, whatever access level they hold, unless you set limited access on that one folder. Only a Manager can do that.

Two more facts worth holding on to before you move anything.

Moving a folder into a shared drive can change access quite widely, so Google restricts the move itself: only users with Manager access to both the old and the new location can move folders into or between shared drives. And when the move happens, all members of the shared drive can see the contents of that folder, including files that were previously hidden. Hidden files are the ones you had removed access to individually inside a shared My Drive folder. They stop being hidden.

If you are on Business Starter, read this bit twice. Google gave Business Starter customers shared drives from mid-September 2024, so you can create them and add members, files and folders. What it said at the same time is that certain admin and security controls are not included in the version of shared drives Business Starter gets, and it named one of them: the ability to control access to the items in a shared drive. Google’s Learning Center repeats the point from the other side, saying that access control on shared drives only works if your organisation supports it. If you need the drive-level restrictions in the next section, check your edition before you plan around them. Our comparison of Business Starter and Business Standard sets out what the upgrade costs in Singapore dollars and which apps get Gemini on each plan.

The folder decides, and has done since September 2025

You cannot pick one file inside a shared folder and give it a shorter list of named people than the folder has. Google removed that option on 22 September 2025. The link side of the settings is the exception, and a later paragraph in this section deals with it. If a guide, a colleague or an old internal note tells you to open the file, click Share, and choose “update item only”, the option is not there any more, and it has not been for a year.

Here is what happened, in order, from Google’s own announcements.

  1. Google stopped allowing restricted access on specific files and folders inside a shared folder. The “update item only” option disappeared for people who could set restrictions on the parent folder, and the equivalent options were greyed out for everybody else. Google said restricted access should be managed through the limited access folder setting instead.
  2. The “Editors can change permissions and share” setting changed at the same time. Switching it off still stops editors sharing the item directly. It no longer stops changes made to the containing folder’s access from being applied to the item.
  3. Google applied limited access to items that already had that setting switched off, so on those items the owner stays the only person who can share them. Items where the setting is switched off after that date do not get limited access.
  4. Google announced that every item still carrying the old restricted access would be migrated to limited access automatically, with no change to who can see or open the files. The rollout started on 9 April 2026 for accounts set to see new features first, and 16 April 2026 for accounts set to get them at least a week later. Google calls those two settings Rapid Release and Scheduled Release, and an administrator chooses which track the account is on.

Take the worry out of the last one first, because it sounds alarming and is not. Google’s wording on the migration is that there is no change to who can see or access the files. A folder you locked down in 2024 was not opened up in 2026. What changed is the name of the mechanism and where you manage it.

The behaviour the change leaves behind is worth a scene, and Google supplies one. Say you have a file set to prevent editors from sharing, sitting inside a folder. You then make somebody an Editor of the whole folder. That editor shares the folder with a new person. The new person gets your file. Google’s explanation is that the file’s own setting only stops somebody sharing the file directly; it does nothing about them sharing the folder it sits in.

There is one sentence on Google’s help page that cuts the other way, and you should know about it because you will find it yourself. Under the heading for restricting general access, Google says that when you change an item’s general access to Restricted, only people with access can open the file, and that this overrides inherited parent folder permissions. So the link side of the settings does behave differently from the named-people side. Further down the same page, Google says files and folders inside a shared folder always inherit that folder’s permissions and that the parent folder is the primary source of truth. Both sentences are Google’s. Before you rely on either one for something sensitive, set it on a test file in your own account and try to open it from a second account.

Limited access is the tool that replaced the old per-file restriction, and it works on folders only. Google is explicit that you can only switch limited access on for a folder, not for a single file. Drive does sometimes apply it to an individual file by itself during a migration, and if you switch that off you cannot put it back. So the supported way to lock one document down is the one Google spells out: make a new subfolder, move the file into it, apply limited access to the subfolder, and share it with the people who need it.

Who can do that depends on where the folder lives. In My Drive, the folder’s owner can switch limited access on and off, and editors can too if “Editors can change permissions” is on. In a shared drive, only Managers can. Managers can also always change the list of people on a limited access folder, and Content managers can as well if the drive’s Manager has allowed content managers to share folders.

One more thing about a limited access folder, because it is not invisible in the way people assume. Everybody with access to the parent folder can find it, including shared drive Content managers, Contributors, Commenters and Viewers. Anybody who has not been given access to it sees it greyed out and cannot open it. The exception is a folder Drive limited automatically during a migration: those are hidden from people with access to the parent folder rather than greyed out.

Three settings worth checking on any folder that matters

Three, in this order. We are not going to tell you which one causes the most leaks. We could not find a published figure for it, and we are not inventing one. These are the three that answer the audit question between them.

1. General access

The setting above the names, in the same dialog. Restricted means only the people in the list can open the item. Anything else means a link decides, and a link can be forwarded, pasted into a chat, or left in an old email thread indefinitely. This is the setting to read first on any folder holding client files, staff records or accounts.

Link sharing inside a shared drive has a rule of its own that is easy to trip over. Link sharing cannot be less restrictive on something inside a folder that is already shared by link. If you have shared a folder with “Anyone in this group with this link can view”, you cannot then share a file inside it with “Anyone with the link”. Google names two ways round it, and one of them is simply doing it in the other order: share the item by link first, then share the parent folder.

2. The shared drive’s own restrictions, if the folder sits in one

This is a setting many owners have never opened, and it sits above everything else. A shared drive Manager, or a Workspace admin, can set restrictions on the whole drive. Google’s list of them is short and each one is worth a minute of your time:

  • Prevent sharing files with people outside your organisation.
  • Prevent sharing files with people who are not members of the drive.
  • Prevent specific members from accessing folders.
  • Prevent members with Content manager access from sharing folders.
  • Prevent Content managers, Contributors, Commenters and Viewers from downloading, copying or printing files.

Google says these restrictions override file and folder sharing. So if the answer you are looking for is “can anybody outside this company open this”, the drive’s restriction settings are where you find it fastest, and a file-by-file check can be flatly wrong.

3. Whether the folder should have limited access

Once you know who can reach the folder, the remaining question is whether the sensitive part of it should be walled off from the rest of the team. That is what limited access is for, and Google recommends the same shape we do: put the sensitive files in a subfolder, limit access on the subfolder, and leave the main folder shared with the wider group.

Check who holds the power to set it, too. In a shared drive it is Managers only. If the only Manager on your client drive left the company in March, that is a finding in itself.

What happens after the person who shared it leaves

Files in their My Drive go with them. Files in a shared drive stay. That is the whole answer, and it is why the last section spent so long on ownership.

The deadline is the part to write down. When you delete a user without transferring their files first, Google deletes those files 20 days later. Inside that window you can restore the deleted user, transfer ownership of their files to somebody still working there, and then delete the original account again. After it, the files are gone.

Access is the other half, and it is quieter. The sharing a person set up does not switch itself off because their account did. Two facts from Google sit behind that.

The first is about the leaver’s own access. When you remove somebody from a shared drive, they also lose access to anything in that drive that had been shared with them directly. That is clean, and it is the behaviour you want.

The second is the one that survives, and it is not about the leaver at all. It is about whoever they shared with. This is the drive restriction from check 2, and it is the reason a departure does not close the door by itself: the external person’s permission on the file never went away.

So the practical order for a departure is: transfer or move what the business needs before the account goes, then go back and read the General access setting and the People with access list on the folders that person owned or shared. Moving those files into a shared drive as part of the process is what stops the same job coming round again next year.

The account side of a departure, which is the suspend, the archive, the delete, and the 20 day restore window in detail, is a separate job with its own order of operations. We wrote that one up in full: the Google Workspace employee offboarding guide.

Questions we get asked

Can I give somebody access for a set period and have it end by itself?

Yes, on a file, if your Google account is a work or school one. Open the file, click Share, find the person, click the down arrow beside their name and choose Add expiration, then pick a date. Google limits the date to within one year of the day you set it. If the person is not on the file yet, add their email and share it first, then reopen Share to set the expiry.

Can I stop people downloading, printing or copying a file?

If you own it, yes. Open Share, click the settings icon at the top right, and under “People who can download, copy, and print” tick the roles you want to allow. Google is honest about the limit of it: you can control downloading, printing and copying inside Drive, Docs, Sheets and Slides, but you cannot stop somebody passing the content on in other ways. A screenshot is still a screenshot.

If I delete a file I shared, does everybody lose it?

Not straight away. If you own the file, anybody who could view, comment or edit it can still make a copy until you delete it permanently from your trash. If you do not own it, deleting it removes the file from your Drive only, and the other people on it keep their access.

Does the Admin console report tell me who can open a folder right now?

No, and this is an easy misreading of it. Drive log events is a record of things that happened, such as a file being shared externally on a particular day. Google says not all activities in Drive are logged, and that most Drive audit events are logged only for files owned by users on supported editions. For “who can open this folder today”, the Share dialog on that folder is still the answer.

We are on Business Starter. Do we get shared drives?

Yes. Google gave Business Starter customers shared drives from mid-September 2024, and Business Starter users can create them and add members, files and folders. Some admin and security controls are missing from that version, and Google specifically named the ability to control access to the items in a shared drive. So you get the team ownership, and you may not get the drive-level restrictions in check 2 above.

What to read next

If you landed here because somebody is leaving, this page has answered half of the problem. You can now read who can open a folder, and you can tell whether the folder belongs to a person or to the business. The other half is the account itself: what to suspend, what to archive, what to transfer, and in what order, inside the 20 days Google gives you before the files go.

We wrote that one up step by step in our Google Workspace employee offboarding guide, which starts where this page stops.