By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: StracPublished August 10, 2026

TL;DR: Google Workspace does not give administrators a single global view of files shared as “Anyone with the link,” leaving public Drive content easy to miss and hard to govern, according to Strac. The control gap is not discovery alone but continuous monitoring, classification, and rapid remediation before sensitive data becomes broadly exposed.


At a glance

What this is: This is an analysis of why publicly shared Google Drive files are difficult to govern at scale and how continuous discovery closes the visibility gap.

Why it matters: It matters because public-link exposure is both an access-control problem and a data-security problem, which means IAM, DLP, and GRC teams need shared visibility into who can access what and why.

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

👉 Read Strac's guide to finding publicly shared Google Drive files


Context

Public sharing in SaaS file systems is a governance problem because permissions can shift faster than manual review cycles can track. In Google Drive, a link that looks convenient to a user can become an uncontrolled access path for regulated data, confidential documents, or credentials, which makes data security inseparable from access control.

The identity angle is real here because public links are an authorization decision, even when no traditional account is involved. That puts this topic squarely in the overlap between IAM, DSPM, and compliance operations, where teams need to know not just that a file exists, but whether its sharing state has changed.

For most organisations, the gap is not that sharing controls do not exist. The issue is that native tools often lack continuous, centrally actionable visibility across the full file estate, which makes this an ordinary collaboration pattern with atypically high exposure potential.


Key questions

Q: What breaks when organisations rely on manual review for public Drive links?

A: Manual review fails because public-link exposure changes continuously while review cycles are periodic. By the time an admin searches, a file may already have been forwarded or indexed. The result is a large gap between exposure and remediation, which is why continuous discovery and automated revocation are necessary for effective governance.

Q: Why do public file links create an IAM issue as well as a data security issue?

A: A public link is still an access decision, even if it is not tied to a named user account. That means identity governance has to account for link-based authorisation, revocation, and evidence. When access is granted outside normal account controls, IAM, DSPM, and compliance teams need shared visibility.

Q: How do security teams know whether privacy controls are actually working?

A: Look for evidence that discovery, classification, DSR routing, and consent enforcement update when the environment changes. If privacy artifacts only refresh on calendar cadence or after manual chases, the programme is operating on stale assumptions. Working controls produce current inventory, traceable approvals, and audit-ready logs without depending on memory.

Q: Who should own the decision to remove public access from shared files?

A: Ownership should sit with the teams that can act on both access and data sensitivity, usually a joint workflow between IAM, data security, and compliance. Without that shared ownership, public links remain an orphaned risk because no single team can both classify the file and close the exposure path.


Technical breakdown

Why public-link sharing becomes an access control gap

Google Drive sharing states such as “Anyone with the link” and “Public on the web” are effectively unauthenticated access policies. Once a file leaves the boundary of tenant-enforced identity controls, the problem is no longer just storage governance but exposure management. Audit logs can show that a change happened, but they do not by themselves maintain a live inventory of every file currently public. That is why orgs often discover exposure after the file has already circulated.

Practical implication: treat public-link state as a continuously monitored access control condition, not a periodic review item.

How continuous discovery changes Drive security operations

Continuous discovery layers watch for new public links as soon as they are created and can classify file content to separate harmless collaboration from material risk. In practice, this means the control is not just visibility, but prioritisation: public files containing PII, credentials, or regulated data can be escalated first. This is a classic DSPM pattern applied to SaaS files, where the control objective is to reduce exposure time and focus human review on the files that matter most.

Practical implication: pair public-link detection with content classification so security teams triage by business risk, not by file count.

Why remediation needs to happen at the permission layer

The fastest way to reduce exposure is to change the sharing permission itself, not to rely on downstream alerts or manual cleanup. When remediation is tied directly to the file permission model, teams can remove public access, enforce policy, or notify owners without leaving the governance plane. This matters because the risk window is often measured in minutes or hours, not days. In identity terms, the control is revocation of access, even if the access path is a share link rather than a user account.

Practical implication: design workflows that can revoke public access immediately and consistently across the file estate.


Threat narrative

Attacker objective: The attacker objective is to obtain broad, low-friction access to sensitive file content through an exposed sharing link.

  1. Entry occurs when a user sets a Google Drive file to public or shareable via link, intentionally or by mistake. Credentialed access is not required because the link itself becomes the access mechanism.
  2. Escalation happens when the link is forwarded, indexed, or reused outside the original collaboration context, extending access beyond the intended audience.
  3. Impact follows when sensitive business information, regulated data, or embedded secrets is exposed without the organisation detecting the sharing-state change in time.

NHI Mgmt Group analysis

Public-link governance is an identity problem disguised as a file-sharing problem: when access is granted through a link, the control plane is still authorisation. That makes this issue relevant to IAM teams, even when it sits inside a data platform rather than a directory service. The practical lesson is that sharing state must be treated as part of the identity lifecycle for content access, not as a separate admin concern.

Continuous visibility is the named concept that matters here: organisations do not fail because they lack one more audit report, they fail because the exposure state changes faster than review cycles. Native audit logs show events, but they do not by themselves provide a living control surface over public links. Practitioners should therefore think in terms of continuous visibility, not point-in-time inspection.

DSPM and IAM have to converge on collaboration platforms: public files are where content sensitivity and access governance intersect, so the file estate cannot be split between security ownership and productivity ownership. When a Drive link can expose regulated material, the right question is who can revoke, classify, and evidence that decision across the full environment. Teams should align ownership before exposure becomes a compliance issue.

Manual review is a weak control for dynamic sharing states: the governance assumption that periodic searches are enough breaks as soon as users create and redistribute links at normal collaboration speed. That assumption gap is familiar across cloud and SaaS security, but it is especially visible in file-sharing workloads because the exposure path is simple and silent. Practitioners need automated detection plus policy enforcement, not seasonal clean-up.

Public access windows should be measured as risk duration, not just risk occurrence: a file that is public for ten minutes and one that is public for ten days are different governance failures. The useful metric is how long sensitive content remains exposed before remediation closes the link. That shifts programmes from chasing a count of risky files to reducing the time those files stay risky.

What this signals

Public sharing in collaboration platforms is now best treated as a control-state problem, not a document-management problem. That means security teams need telemetry that tells them when exposure begins, how long it lasts, and whether the file contains regulated data before the window closes.

Exposure duration becomes the metric that matters: a public file is not just a yes-or-no finding, it is a timer. The programme question is whether your current controls can detect, classify, and revoke exposure quickly enough to reduce the time sensitive content stays reachable.

For identity and data teams, the practical shift is toward shared governance of access paths that do not look like identities at first glance. Public links, delegated sharing, and SaaS permissions all behave like authorisation events, which is why file-sharing controls increasingly belong in the same operational conversation as IAM and DSPM.


For practitioners

  • Implement continuous public-link discovery Monitor Google Drive sharing states in real time so every new “Anyone with the link” or “Public on the web” event is detected immediately.
  • Classify file content before triage Combine sharing-state alerts with content-aware detection for PII, credentials, and regulated documents so analysts can prioritise the highest-risk files first.
  • Automate permission revocation workflows Use policy-driven remediation to remove public access or downgrade sharing permissions without waiting for manual cleanup or owner action.
  • Align IAM and data-security ownership Define who owns the decision to revoke, approve, and evidence public-file exposure across collaboration platforms, especially where Drive is used for regulated content.

Key takeaways

  • Public Google Drive links create an access-control gap that native tooling often cannot govern continuously.
  • The main operational risk is not discovery alone, but how long sensitive files remain public before remediation closes the exposure window.
  • IAM, DSPM, and compliance teams need shared ownership for link-based access revocation and evidence collection.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Public-link governance depends on managing access permissions across collaboration tools.
NIST SP 800-53 Rev 5AC-6Least privilege is directly challenged when files are shared publicly by link.
CIS Controls v8CIS-5 , Account ManagementAccount and access governance underpin the review of externally shared file access.
ISO/IEC 27001:2022A.5.15Access control policy is central to governing public file sharing in SaaS environments.
GDPRArt.32Public exposure of personal data in Drive can trigger security-of-processing obligations.

Use CIS-5 to keep ownership and access review processes aligned with collaboration-platform sharing states.


Key terms

  • Public Link Exposure: Public link exposure occurs when a file is made accessible beyond the intended user base through shareable or open link settings. In practice, it creates an unauthenticated access path that bypasses normal identity controls and can remain active until someone notices and revokes it.
  • Continuous discovery: Continuous discovery is the ongoing process of detecting identities as they appear, change, or disappear across environments. For AI agents and other NHIs, it prevents inventory drift and keeps ownership, privilege, and lifecycle controls aligned with the live environment.
  • Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
  • Link-Based Authorisation: Link-based authorisation is access granted through possession of a URL rather than through a named account or session. It is convenient for collaboration, but it weakens identity assurance because access can spread outside normal governance channels once the link is forwarded.

What's in the full article

Strac's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step manual workflow using Google Workspace Reports API and Drive Audit Log for locating public links.
  • Dashboard and remediation sequence for changing sharing permissions on risky files in one action.
  • Configuration details for alerts when files switch to “Anyone with the link” or “Public on the web.”
  • Content-aware scanning details for identifying PII, PCI, PHI, secrets, and other regulated data.

👉 The full Strac article covers manual discovery steps, monitoring workflow, and one-click remediation details.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management in the context of modern access control. It helps identity and security practitioners build the lifecycle discipline needed to manage exposed credentials, tokens, and access paths.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org