Learn
Guide


Giving an agency, accountant, or vendor access to your Google Workspace files does not require adding them as a user or handing over a shared drive. The three access methods, adding a Workspace user, sharing a shared drive, and sharing individual files or folders, carry very different cost and risk profiles, and most operators default to whichever one their agency asks for rather than the one that fits the actual job. The safest pattern for external collaborators is narrow, time-bound file or folder sharing, backed by Admin console settings that limit where external sharing can happen at all, plus an expiration date set on day one, not remembered on the way out.
TL;DR
Adding an external collaborator as a full Workspace user is the most expensive and highest-access option. Sharing individual files or folders is usually the right one for agencies and vendors.
Shared drive “Manager” and “Content manager” roles carry broader access than most operators expect, including the ability to change sharing settings and manage membership.
The Admin console controls that matter most for external access are the domain-wide sharing on/off toggle, trusted domain allowlists, target audiences, and the external sharing warning banner.
“Anyone with the link” sharing is the most common route to accidental exposure, because a link created for one recipient can be forwarded without the file owner ever knowing.
Every agency engagement should have an access expiration date set at onboarding, and offboarding should include a verification step, not just a checklist item marked done.
About the Author
ShiftControl builds access and provisioning tooling purpose-built for Google Workspace, used by growing companies that work with outside agencies and vendors but have no dedicated IT team to manage who can see what. This guidance draws on patterns the ShiftControl team has seen managing Workspace access across hundreds of external-collaborator relationships.
What Is the Difference Between a Workspace User, a Shared Drive, and a Shared File for External Access?
These are three distinct mechanisms with different scopes, and confusing them is the most common reason agencies end up with more access than intended.
Adding someone as a Workspace user means creating a license and an account inside your domain. That person now has a company identity, potentially email, calendar, and access to anything shared with “all employees” groups. This is appropriate for long-term embedded contractors who function like staff, but it is overkill and costly for an agency doing a single campaign or an accountant doing quarterly books.
Sharing a shared drive with an external account gives that external Google account access to everything inside the drive, subject to their assigned role. This is a reasonable middle ground when a vendor needs ongoing access to a defined project space, but “the drive” tends to accumulate unrelated files over time, and few teams audit what has quietly landed inside a shared drive months after a vendor was granted access.
Sharing individual files or folders with an external email address is the narrowest option. The vendor sees only what was explicitly shared, nothing more, and permissions can be set per document (view, comment, edit).
The trade-off is straightforward: broader access is easier to set up and forget about, narrower access takes a bit more discipline to maintain but limits what’s exposed if the vendor relationship ends badly or the vendor’s own account is compromised. For most agency and vendor relationships, file- or folder-level sharing should be the default, not the exception.
Access Method | Scope of Access | Setup Effort | Ongoing Risk |
|---|---|---|---|
Workspace user | Full domain account, group memberships, org-wide shared content | High (license, provisioning) | High if not offboarded promptly |
Shared drive membership | Everything in the drive, present and future | Medium | Medium, grows as drive content grows |
Individual file/folder share | Only the specific item shared | Low | Low, but easy to lose track of at scale |
Which Google Workspace Admin Console Settings Actually Control External Sharing?
Before any individual file gets shared, the Admin console sets the outer boundary for what’s even possible, and this is the layer most operators never touch after initial setup.
Under Apps > Google Workspace > Drive and Docs > Sharing settings, admins control whether external sharing is allowed at all, and if so, under what conditions. The controls that matter most for agency and vendor access:
External sharing on/off, by organizational unit. You can turn external sharing off entirely for finance or legal teams while leaving it on for marketing, which is useful if only certain departments regularly work with outside vendors.
Trusted or allowlisted domains. Rather than allowing sharing with any external address, you can restrict external sharing to a specific list of domains, such as your agency’s or accountant’s firm domain. This closes off the risk of a file being shared with a personal Gmail address by mistake.
Target audiences and sharing labels. These let you define named groups of external collaborators that internal users can pick from when sharing, rather than typing a raw email address every time.
Warning banners on external sharing. Google Workspace can display a warning when a user is about to share with someone outside the organization, forcing a small conscious pause before the share happens.
None of these settings are hard to find, but they are easy to leave on their default state indefinitely. An operator who set up Workspace two years ago and never revisited the sharing settings is very likely running with defaults that were never evaluated against how the company actually works with vendors today.
Why Is Shared Drive “Manager” Access Broader Than Most People Assume?
Building on the Admin console layer above, the next place people underestimate exposure is inside the shared drive itself, at the individual member role level. Shared drives have layered roles, and the top two, Manager and Content Manager, are considerably more powerful than “can see the files.”
A Manager on a shared drive can typically:
Add and remove other members, including other external collaborators
Change sharing permissions for the entire drive
Move or delete files at the drive level
In many configurations, alter the shared drive’s external sharing settings
If an agency contact is added as a Manager “just to make things easier,” they now have the ability to invite their own colleagues into your drive without your involvement, or to change access settings you never approved. Content Manager is a step down, allowing file management but not membership changes, and Contributor and Viewer roles are progressively narrower still.
The practical rule: external collaborators should almost never be Managers on a shared drive. Content Manager or Contributor is usually the ceiling, and for most agency and vendor scenarios, a shared drive is the wrong tool in the first place; individual folder sharing achieves the same collaboration outcome with a much smaller blast radius.
What Is Link Sharing, and Why Is It the Most Common Accidental-Exposure Route?
A related but distinct problem from role misconfiguration is link sharing, which introduces exposure that has nothing to do with who was deliberately granted access.
“Anyone with the link” sharing means the file’s access control is effectively the link itself, not a specific identity. Once that link exists, Google Workspace has no way of knowing who has it. If an agency contact forwards the link to a freelancer, or pastes it into a shared Slack channel with people outside the project, or the link ends up in a personal notes app that later syncs to another device, the file is now accessible to people who were never evaluated or approved.
This matters more for vendor and agency relationships than for internal sharing, because external parties are, by definition, operating outside your organization’s own controls. You cannot see their Slack channels or their file-forwarding habits. The only real defense is limiting how often “anyone with the link” is used at all, in favor of sharing with specific named email addresses, which Google Workspace logs and which respects domain restrictions set at the Admin console level.
A useful mental model: named-recipient sharing is like handing someone a key to a specific door. Link sharing is like leaving a key under the mat and telling one person where it is, except the mat is visible to anyone who happens to look.
Why Does Every Agency Engagement Need an Expiration Date on Access?
Stepping back from the mechanics of sharing itself, the harder problem is time. Access granted at the start of an engagement rarely gets revoked automatically when the engagement ends, and Google Workspace’s native tools make this worse rather than better.
Google’s own controls have real limitations here: there is no simple bulk view of every external party with access to a given user’s files, no automated expiration on shared drive membership, and limited visibility into nested folder permissions once access has propagated a few levels deep. This means the responsibility for setting and enforcing an end date sits entirely with the person granting access, not the platform.
Google Drive does support setting an expiration date on individual file or folder shares, and this should be treated as a default step, not an optional one, for any agency, vendor, or accountant engagement with a known end date. Set the expiration when access is granted, not when the project starts to wrap up. An expiration date set at kickoff needs no one to remember it later; one you plan to add “before the contract ends” depends on someone remembering, and that is exactly the kind of task that slips during a busy quarter.
What Does a Safe Pattern for Onboarding and Offboarding an Agency Look Like?
Pulling the previous sections together, a workable pattern for agency access looks less like a single decision and more like a short sequence of deliberate steps, repeated consistently.
At onboarding:
Confirm the agency needs file- or folder-level access, not a shared drive or a full Workspace account. Default to the narrowest option unless there’s a clear reason for more.
Share the specific folder, not the parent drive, with the agency’s named contacts using their work email addresses.
Set an expiration date on the share that matches the contract’s end date or review point, even if that date is months away.
If the agency will need repeat access over a long engagement, consider adding their domain to a trusted domain allowlist rather than sharing with individual personal accounts.
Avoid “anyone with the link” for anything involving vendor deliverables, financial data, or client information. Use named-recipient sharing so access is auditable.
At engagement end:
Do not assume expiration dates fired correctly. Check the sharing settings on the relevant folder directly.
Search Drive activity or the Admin console’s sharing reports for the agency’s domain or named contacts to confirm no other files were shared outside the original folder.
If the agency was ever added to a shared drive, verify their membership was actually removed, not just that their role was downgraded.
Document the offboarding date and confirmation step somewhere your team can reference later. A vendor offboarding checklist that includes an actual verification step, not just a box to tick, is the difference between assuming access ended and knowing it did.
This is where the gap between Google Workspace’s native controls and what growing companies actually need becomes clear. The platform gives you the levers, but connecting a vendor’s offboarding date to an actual access revocation, and confirming it happened, is a manual process unless something else is doing that tracking for you. This is also where shadow IT risk creeps in: an agency granted broad access early in a relationship, then left unchecked for a year, is functionally an unmanaged app or account nobody is actively watching, even though it was fully sanctioned at the start.
Third-party access is a documented factor in security incidents more broadly. Vendor access misconfiguration and oversight pose real security risks, and frameworks like NIST’s Cybersecurity Framework and the CIS Controls both point to the same underlying fix: least privilege access, continuous review, and MFA on any account that touches company data. Vendor access management works as the same discipline as general Workspace security, applied to people outside your payroll.
Frequently Asked Questions
Can I share a Google Drive folder with someone who doesn’t have a Google account?
Yes. Google Workspace supports visitor sharing, which lets you share files and folders with people who don’t have Google accounts. The recipient gets a secure PIN code sent to their email that they use to view, comment on, or edit the file, without being required to create a Google account or hold a Workspace license for your domain.
What’s the difference between “restricted” and “anyone with the link” in Google Drive sharing settings?
“Restricted” means only people explicitly added can open the file. “Anyone with the link” means anyone who obtains the URL can open it, regardless of whether they were the intended recipient.
Should I ever add an agency contact as a full Workspace user?
Generally no, unless they are functioning as a long-term embedded team member with a need for company-wide tools like email and calendar. For most agency, accountant, or vendor relationships, file-level sharing is sufficient and lower-risk.
How do I stop employees from sharing files with personal Gmail accounts?
Use trusted domain allowlisting in the Admin console to restrict external sharing to approved domains only, which blocks sharing to arbitrary personal addresses while still allowing collaboration with known vendor domains.
Does Google Workspace let me set an expiration date on shared drive membership, not just individual files?
Native expiration controls are more limited for shared drive membership than for individual file or folder shares, which is one reason folder-level sharing with an expiration date is generally the safer default for time-bound engagements.
What is a target audience in Google Workspace sharing settings, and is it relevant to external vendors?
Target audiences are named groups that make it easier for users to share with the right recipients internally. They are primarily an internal collaboration feature rather than an external access control, but they can reduce the risk of typos or incorrect recipients when combined with external sharing rules.
How can I tell if a vendor still has access to company files after their contract ends?
Check the sharing settings on the specific folders shared during onboarding, and review Admin console sharing reports for the vendor’s domain. Relying on memory or an informal checklist without a verification step is how stale access accumulates.
About ShiftControl
ShiftControl is an IT operations and SaaS management platform purpose-built for Google Workspace, giving small and growing companies the kind of access control, spend visibility, and incident response that larger enterprises have, without requiring a dedicated IT hire. Founded by operators who ran IT at ExpressVPN as it scaled from 100 to 700+ employees across 7 global offices, ShiftControl was designed around the real operational gaps that show up as companies grow, including vendor and agency access that gets granted correctly but never gets reviewed again. Setup takes about 10 minutes through a single Google Workspace login, and cyber incident response through Blackpanda’s IR-1 service is included in the subscription rather than sold as a separate upgrade. Pricing is public, with a standard per-user rate and a separate discounted tier for startups.
If your team works with agencies, accountants, or vendors on a recurring basis and you want a clearer picture of who has access to what, and for how long, ShiftControl is worth a look.
