Card on proving file access, external link exposure, and sync client risk. Can your file sharing setup prove who had access, and since when?
Image: Productivity Software Reviews

Maintenance

Part of A file sharing service is really selling you its permission model

Can your file sharing setup prove who had access, and since when?

File sharing security starts with what you can prove: who had access, since when, and who opened it. Plus external links, sync, and restore times.

What to take away

  • Four questions decide this purchase. Most entry tiers answer two of them well.
  • Historical access is the hard onewho could reach a file on a past date, and since when they could.
  • Audit logs expire. Entry tiers commonly keep 30 days; compliance add-ons sell longer retention with export.
  • External links accumulate because no step closes them. Expiry by default is the fix.
  • A restore you have not timed is a plan, not a control.

The four questions to test in a trial account

Run all four against one folder, with two members and one external guest, before you sign.

QuestionWhat a good answer looks like
Who can reach this file today?Membership now, including groups and guests
Who opened, downloaded or deleted it?Per-user activity with exportable timestamps
Which link carried that access?Link creator, creation date, expiry date
Who had access last March, and since when?Point-in-time membership history

Questions one to three are standard in business tiers. Question four is where products separate, and it decides disputes.

If a product shows only today's state, your evidence about last year is whatever your team wrote down at the time.

Permission models differ between products, which is why the file sharing review belongs beside this page when you compare tiers.

Four questions to test

  • Who has access, including groups and links?
  • When was each grant made, and by whom?
  • Who opened this file, and how far back?
  • What did access look like six months ago?

External links outlive the reason they were made

Nobody plans four hundred active external shares. They arrive over three years, one reasonable decision at a time.

  • A link outlives its reason, because no step in the workflow closes it.
  • A link is transferable, so the holder may not be the person it was made for.
  • A folder-level link covers everything added later, including files that did not exist when it was created.

The countermeasures are dull and they work. Outside shares expire by default. The owning group reviews a listing of active links each quarter. Outside access is granted at file level unless somebody explains why a folder is needed.

Retention windows, defaults and export

Audit records expire, and the default is shorter than most teams assume. Entry business tiers commonly keep activity logs for 30 days. Mid tiers often publish a year.

Google Vault and Microsoft Purview eDiscovery are the best known add-on tiers built for retention, hold and export. Base business tiers of the same products, and the consumer sync tools many teams start with, generally show current membership and a short activity feed.

Check two things in a trial: the default window, and whether you can export the log on demand. Retention also drives price, because seat counts and retention windows shape most file sharing pricing.

An audit trail earns its keep only if it names the user, the action, the timestamp and the address the action came from.

Decide the lookback you would need after a client complaint, then buy retention that covers it.

Sync clients put copies on laptops

Sync makes these products pleasant. It also puts a full copy of a shared folder on a device you may not control. Three decisions follow.

  • Which devices may sync, and whether policy enforces that or only states it.
  • Whether selective sync is on by default, so a new member does not pull a large space by opening one file.
  • What remote removal does to a lost device, and how quickly it takes effect.

NIST SP 800-171 is written for a narrower context than most readers occupy, but its requirement holds: limit access to authorized users and to the actions they may take.

Example: a restore test on a hundred files

Encrypted files sync. A client replicates the damage to the shared copy and to every other copy, at speed. Test the path before you need it.

  1. Add 100 files to a trial folder and give two members access.
  2. Encrypt or corrupt all 100.
  3. Restore from the vendor's rewind or version history, and start a timer.
  4. Record whether sharing settings returned, or whether the restored files arrived owned by whoever ran the restore.

Typical timing for a few hundred files from version history runs from minutes to a couple of hours. A bulk rollback of a large shared space is often measured in days.

The CISA ransomware guidance covers the wider problem. The number you need is your own restore time on your own estate.

Restoring is a permissions problem as much as a copying one, which is the argument in migration is a permissions problem.

Four things to test in restore

  • Windowhow far back, admin vs user?
  • Granularitywhole folder or file by file?
  • Speedfour days or two hours?
  • Statesharing settings kept or lost?

Two classification tiers you will maintain

Elaborate schemes fail the way elaborate naming schemes fail. People stop applying them, and a half-applied scheme produces false confidence.

Two tiers survive: ordinary and restricted. Restricted means a short written list, such as material holding personal data or material under a confidentiality obligation.

Apply exactly one rule to restricted that applies nowhere else. Banning external links is the usual choice.

Most enforcement stories involve ordinary lapses rather than sophisticated attacks, which is the point of the FTC data security guidance.

Who owns the twice-yearly access review

Twice a year, the owning group of each top level space receives a list of who has access and every active external share. They confirm or remove each entry. No forms.

The value is not the removals. It is that somebody looks.

Departures need their own check, because content owned by a leaver is the commonest way material becomes unreachable. That check belongs with the joiner and leaver process, and it works only if spaces were assigned to groups in the first place.

Common questions

Is encryption at rest enough?
It handles one threat, somebody obtaining the physical storage. It does nothing about a link that should have expired or an account that kept access after a role change.
Should we turn off external sharing?
Rarely. People route around it with personal accounts and attachments, and then you have exposure with no record at all. Set expiry by default, require sign-in, and keep sensitive material at file level.
How long should access records be kept?
Long enough to cover the period in which you would realistically learn about a problem, which is usually longer than the vendor default. If the default is short, export to storage you control.

More in Maintenance

Latest from Reporting Desk