The Challenge
As teams grew at an Enterprise organisation, Google Drive shares multiplied faster than anyone could track. A project folder would go out as "anyone with the link." A contractor would keep access after their last day because nobody remembered which files they touched. Calendar invites went to individual emails instead of department groups, so when someone left, meetings broke and shared drives became orphan folders with no owner.
Collaboration worked — until it did not. HR would ask IT to revoke access for a departing employee and discover they had editor rights on finance folders, marketing assets, and a personal shared drive nobody on the current team recognised. Sensitive documents travelled through inboxes because it was faster than checking permissions. New joiners waited days for the right folder access because onboarding was a manual list in someone's notebook.
The organisation did not need to slow down collaboration. It needed structure underneath it — the same way ERP access is role-based and reviewed, not handed out one file at a time.
The Approach
We treated Workspace like infrastructure, not a free-for-all file dump. The first step was inventory: dormant accounts, external shares, admin roles, and drives without named owners. Then we rebuilt the access model around groups and lifecycle, not individual convenience.
- Org model — Department groups became the default for Drive and Calendar permissions. Share to the group, not to six individual emails that go stale.
- Sharing defaults — Tightened external sharing policies and required explicit review before broad "anyone with link" access was enabled.
- Lifecycle — Joiners received role-based group membership on day one via a checklist. Leavers lost access the same day through a mirrored offboarding checklist — drives, calendars, groups, and admin roles.
- Admin hygiene — Scheduled audits of dormant users, stale external shares, and elevated admin roles. Each finding had a named owner and resolution path.
- Documentation — Wrote short SOPs for managers: how to request a new group, how to share externally, who approves sensitive folder access.
How It Worked
Instead of granting file-by-file access, managers requested group membership. Finance, operations, HR, and project teams each had owned groups with a named group manager responsible for quarterly review. New shared drives required an owner and a retention label before creation — no more untitled drives with 200 random files.
External sharing went through a simple rule: internal-first, external-by-exception with a documented reason. When someone left, the offboarding checklist ran the same day — account suspended, group memberships removed, shared drive ownership transferred. IT stopped discovering ghost access weeks later during an unrelated audit.
Results
Onboarding and offboarding became predictable. New hires had working folder access on day one. Departing employees did not retain silent editor rights on sensitive folders. Open link shares dropped because teams defaulted to group-based internal sharing. Sensitive documents stopped travelling through random inboxes — they lived in owned drives with visible permissions.
Teams still collaborated quickly. The difference was that collaboration ran through owned groups instead of personal sprawl. IT spent less time on ad-hoc permission fixes and more on planned improvements. Managers understood the model because it mirrored how they already thought about team structure.
Security reviews became easier too: instead of hunting for rogue shares, auditors could review group membership, external exceptions, and admin roles from a single governance log. The organisation gained control without adding friction to day-to-day work. New managers onboarded faster because folder access followed their team group — not a ticket queue.
Takeaway
Workspace is infrastructure. Treat permissions like ERP access: least privilege, named owners, and a review cadence. Speed and control are not opposites — they improve together when groups and lifecycle are designed upfront.