Skip to main content

How to Find and Remove Someone's Access to Your Google Drive Files

A contractor's project ends. An employee resigns. An agency engagement wraps up. Months later, that person can still open every file that was ever shared with them — because in Google Drive, sharing doesn't expire when the relationship does.

The uncomfortable part: Drive has no screen that answers "what can this person access?" Sharing is stored per file, so the answer is scattered across every file and folder in your Drive. This guide covers the built-in options, where they fall short, and how to get the complete answer.

First, understand what you're looking for​

"Their access" is usually four separate things, and each needs different handling:

  1. Direct shares — files and folders shared with their email address.
  2. Group-based access — access they get from being in a Google Group or a Shared Drive's member list, not from any individual file share.
  3. Link access — "anyone with the link" files whose URL they know. Their name appears on no permission list.
  4. Files they own — documents they created that your team depends on. Removing these is the opposite problem: you need to keep access.

Most offboarding misses at least two of these.

Option 1: Drive's built-in search (quick but incomplete)​

In the Drive search bar, type:

to:person@example.com

This lists files you own that are shared directly with that address. It takes ten seconds and is worth doing — but know what it misses:

  • Files owned by your teammates and shared with the person (each owner has to run the search themselves)
  • Access granted through a group rather than their individual email
  • Shared Drive content, where access comes from membership, not per-file shares
  • Link-shared files, which have no record of who holds the URL

For one person and a small personal Drive, this may be enough. For an offboarding you need to stand behind, it isn't.

Option 2: Workspace admin offboarding (for managed accounts only)​

If the person had an account in your Google Workspace domain, the Admin console handles the account side: suspend the account, transfer ownership of their files, remove them from groups and Shared Drives.

But this does nothing for the most common risky case: an external address — a contractor's personal Gmail, an agency's domain — that your team shared files with over the years. You can't suspend an account you don't own. You have to find every share and revoke it, which brings us to the complete method.

Option 3: Audit everything, then filter by person​

Export every permission in your Drive to a spreadsheet, then filter for the person. This catches direct shares across all owners you can see, group and domain entries, and Shared Drive files in one pass.

Step 1: Run the export​

Copy the DriveAuditr template and run Drive Audit → Run Audit Now. It lists every file with one row per permission — email, role, type, and a direct URL to the file. (Full walkthrough: exporting Google Drive permissions.)

Step 2: Filter for the person​

In the Drive Audit tab, filter the permission email column by the person's address. Check all of their addresses — work account, personal Gmail, and any aliases you've seen them use.

Then two more filters most people skip:

  • Their groups. Filter for Permission type = group and review whether the person is a member of any listed group. Removing them from the group revokes that access in one step.
  • Their role. Sort your matches by role. writer entries are your priority — those can edit, not just read.

Step 3: Revoke, row by row​

For each match, open the file via the URL column, click Share, and remove the person. Work from owner and writer roles down to reader. For files owned by teammates, send them their rows — only an owner or editor can change sharing.

Mark each row as you go; the filtered sheet becomes your offboarding record — useful if you need evidence for a compliance review.

Step 4: Handle what a name filter can't catch​

  • Link-shared files. Filter Permission type = anyone. If a sensitive file is link-shared and the person plausibly had the URL, switch it to restricted sharing. (Full guide to finding public files.)
  • Files they own. Filter the owner column by their address. For a managed account, transfer ownership before the account is deleted. For an external owner, you can't take ownership — make copies of anything your team depends on, because their account can revoke your access at any time.
  • Shared Drive membership. Remove them from each Shared Drive's member list — per-file revocation doesn't cover membership-based access.

The offboarding checklist​

#CheckWhere
1Direct shares to all their addressesAudit sheet, permission email filter
2Group memberships that grant accessGoogle Groups / Admin console
3Shared Drive membershipsEach Shared Drive's Manage members
4Files they own that your team needsAudit sheet, owner filter
5Sensitive link-shared files they knewAudit sheet, type = anyone filter
6Re-run the audit to confirm zero matchesDrive Audit → Run Audit Now

Step 6 matters: after revoking, re-run the audit and filter for the person again. Zero rows is your confirmation — and your evidence.

Frequently asked​

Can I remove all their access in one click? Not with Drive's UI, and DriveAuditr deliberately doesn't either — it runs read-only, so an audit can never break your sharing. Bulk revocation is possible through the Drive API, but a scripted mass-removal that goes wrong is much harder to undo than an hour of deliberate clicking guided by a filtered sheet.

They own files we still need. Can I take ownership? Within a Workspace domain, an admin can transfer ownership. From an external personal account, no — ownership can only be given by the owner. Ask them to transfer it; if that's not possible, copy the files while you still have access.

Does removing someone from a group revoke their file access? Yes — access granted via a group disappears when they leave the group. Their direct shares on the same files remain, which is why you check both.

How do I stop this from piling up again? Audit on a schedule (Drive Audit → Setup Weekly Schedule) and make the person-filter check part of every offboarding. The security audit checklist turns this into a repeatable routine.

Next steps​

Questions? Email driveauditr@terrydjony.com.