Document Creation and Sharing
Share cloud documents with the right people at the right permission level, and manage access over the life of a file.
By the end of this lesson you can
- Share files and folders with specific people or by link
- Choose the appropriate permission level for a situation
- Use comments and suggesting mode for collaborative review
- Audit and revoke access when it is no longer needed
Lesson Notes
Read through the key concepts before you try the challenge.
Sharing is an access control decision
You manage shared documents at Lakeside Medical Associates.
Eighteen months ago someone shared a folder as 'anyone with the link can edit' so a temporary contractor could deliver a file. The contractor left a year ago. The link still works, it has been forwarded twice, and the folder now contains staff records nobody thought about when the link was created.
Your task: Treat every share as an access decision with a lifespan, not a one-off convenience.
Cloud sharing is genuinely convenient, which is exactly why it is dangerous. A link created in five seconds keeps working indefinitely, travels wherever it is forwarded, and grants access to whatever the folder contains later — not only what it contained when the link was made.
| Level | Can | Use for |
|---|---|---|
| Viewer | Read and download only | Distributing finished documents |
| Commenter | Read and comment, but not change the text | Review rounds where you keep authorship |
| Editor | Change content, and often re-share | Genuine co-authors |
| Owner | Everything, including deletion and transfer | One person; ideally an organizational account |
Sharing a document safely
Share a draft policy with three reviewers and one external consultant, without creating a link that outlives the project.
- 1
Share with named people rather than creating a link.
Named sharing ties access to identities you can audit and revoke individually. A link is a bearer token — whoever holds it has access, and you cannot tell who that is or how it reached them.
- 2
Give reviewers Commenter, not Editor.
They need to raise points, not rewrite the policy. Commenter is the least privilege that accomplishes the task, and least privilege is the principle that keeps sharing manageable.
- 3
For the external consultant, set an expiry date on the access.
External access should never be open-ended. An expiry means it ends whether or not anyone remembers to remove it — which is the realistic assumption, since nobody remembers.
- 4
Check what else is in the folder before sharing the folder.
Folder sharing grants access to everything inside, now and in future. This is exactly how the staff records in the scenario became exposed — nobody re-examined the folder after the link was made. Share the file when the file is what they need.
- 5
Review and revoke access when the project ends.
Closing the loop is the step that never happens on its own. Putting an access review in the project's closing checklist is what turns it from good intentions into something that actually occurs.
Result: Access limited to named people at the minimum useful level, with external access that expires on its own.
Share with people rather than links, grant the least privilege that works, set expiry on external access, and revoke when the work is done.
Why is sharing a folder riskier than sharing an individual file?
Challenge
Apply what you've learned in this lesson.
Practice the full lifecycle, including the part everyone skips.
- Share a document with a classmate as Commenter. Have them add a comment and a suggested edit. Accept one and reject the other.
- Create a link share, then convert it to named sharing. Describe what changed about who can reach the file.
- Audit your own Drive: find every file currently shared by link. Note how many you had forgotten and revoke any that no longer need it.
- Write a four-rule sharing policy for a small medical office. Include a rule about reviewing access, and state who is responsible for it.
Finished this lesson?
Progress is saved in this browser only. It is not a grade — official progress lives in Brightspace.