Every collaboration platform in use today was designed to make sharing frictionless, and every one of them succeeded. Three years of distributed work turned that design goal into an access estate that nobody has ever reviewed: documents shared with anyone holding a link, guest accounts from projects that finished in 2020, and folder inheritance quietly granting a contractor visibility of a directory they were never meant to see. This is not a failure of the tools. It is the predictable result of asking millions of individual users to make permission decisions one file at a time, with no expiry, no review and no visibility into what the decision actually exposed.
Access certification asks who has a role. The exposure is in objects nobody has a role for
Identity governance programmes are built around applications, roles and entitlements. A manager certifies quarterly that their team should still have access to the finance system, and the audit evidence looks tidy. None of that touches collaboration permissions, because those are not roles. They are per-object grants created by ordinary users, held inside the platform, invisible to the identity system, and attached to content rather than to a job function. An organisation can pass every access certification it runs and still have a pricing model shared publicly, a board pack in a folder inherited by a former agency, and eleven hundred active guests from firms it no longer works with.
Four structural failure modes
The anonymous link. Created for speed — usually to get around a sharing prompt that was confusing at the time — then forwarded, pasted into a ticket, embedded in a supplier's document, and never expired. The guest who never left. External accounts survive the project that created them. The other organisation's leaver process does not touch your tenant, so their departed employee remains your active guest. Inheritance drift. Someone moves a file into a different folder, or a folder into a different site, and effective permissions change silently. Nobody is notified, because from the platform's perspective nothing went wrong. The orphaned owner. The person who created the workspace has left. There is no second administrator, so permissions cannot be changed, content cannot be reclaimed, and the usual response is to leave it exactly as it is.
Cross-organisation channels changed the shape of the problem this year
Shared channels between companies are now mainstream, and they are a genuinely different model from inviting an external person to a document. The relationship is continuous rather than transactional, membership is managed partly by the other organisation, and their staff changes propagate into your workspace without any action on your side. That needs its own rules: an external-collaboration policy per partner rather than per person, an end date on every cross-organisation space tied to the engagement rather than to memory, a named internal owner who attests quarterly that the partner still needs access, and clarity in the contract about whose obligation it is to notify leavers. Most organisations have adopted the feature enthusiastically and written none of this down.
An audit that actually finishes
The reason most permission reviews stall is that they begin with an inventory of millions of objects. Invert the order. Segment by exposure class, not object count. Anonymous links first, then externally shared, then organisation-wide, then team-level. The first two categories are usually a few thousand items in an estate of millions. Rank by sensitivity using signals you already have — classification labels, storage location, the presence of recognisable data patterns — rather than by reading content. Fix the defaults before the backlog, because otherwise you are draining a bath with the tap running. New links default to internal recipients, anonymous links expire automatically, sensitive labels block external sharing outright. Run one bulk remediation with a communicated grace period. Announce it, publish a self-service path to re-share properly, then revoke on the stated date. Then keep one recurring control, not five. Quarterly owner attestation for the highest exposure tier only. Anything broader will be abandoned by the third cycle.
Five numbers worth putting in front of an executive
Anonymous links pointing at sensitive content. Guests who have authenticated in the last ninety days as a proportion of total guests. Objects with no valid owner. External domains ranked by how many of your objects they can reach. And the median age of an anonymous link, which is the number that usually ends the argument.
Practical Guidance for Permissions Audit
- Set expiry on anonymous links and make internal-only the default scope for new shares.
- Give every guest account an end date tied to a contract, engagement or purchase order.
- Require two owners on any workspace above scratch level, so departures do not freeze content.
- Report external access by domain, not by individual, because that is how the relationship is actually managed.
- Block external sharing for labelled sensitive content rather than relying on user judgment.
- Alert on inheritance changes for a defined set of high-sensitivity locations.
- Run remediation in one announced wave with a grace period and a self-service re-share path.
- Attest quarterly on the top exposure tier only, and accept that the long tail is managed by defaults.
The Regional Angle
Three regional patterns make this worse here than the global guidance assumes. The first is the sheer weight of external advisers. Regional groups run on them — audit firms, legal counsel, government relations agents, family office advisers, banking relationship teams, systems integrators supplying staff who sit in your offices. Each engagement produces guest accounts, and each adviser firm rotates its own people constantly, with junior staff moving between clients every few months. The engagement letter has an end date; the guest account does not. The fix is administrative rather than technical: tie guest expiry to the engagement record or purchase order that authorised the work, and make the adviser firm, not the individual, contractually responsible for notifying you when someone leaves the account. A single afternoon reconciling active guests against currently open engagements typically removes more exposure than a year of user training. The second is that many regional groups run several legal entities inside a single collaboration tenant, and some of those entities have minority shareholders or joint-venture partners. In that architecture the permission boundary is the only thing separating co-owned businesses from each other, and an inherited folder right is not merely a policy breach — it is a partner seeing another partner's margins, or a joint-venture co-owner reading the group's negotiating position. The consequence lands in a shareholder meeting rather than in a security report. Keep jointly owned ventures in dedicated spaces with inheritance broken at the root, and audit those boundaries specifically rather than relying on the general estate review. The third is how people leave. Departures in this market are abrupt and physical: visa cancellation, final settlement, flights, sometimes within a week, and frequently at the employee's initiative. The offboarding checklist here was built around tangible things — the laptop, the access card, the company phone, the clearance signatures — and it is very good at those. What survives the departure is everything the person created in the cloud: links they shared, workspaces they own, guests they invited, folders whose only administrator has now left the country. The practical answer is to attach ownership transfer and share revocation to the final settlement process rather than to an information technology checklist, because final settlement is the one process in this region that always completes, on time, with signatures, before anyone gets on a plane.
The objection worth taking seriously
The strongest objection is that this is make-work. Nothing bad has happened. An unguessable link is not meaningfully exposed. Old guests are overwhelmingly benign. And a bulk revocation will break dozens of working arrangements, generate a week of help-desk tickets and produce at least three angry executives whose shared folders stopped working during a deal. Meanwhile actual breaches arrive through stolen credentials, session tokens and unpatched infrastructure, not through a forgotten share link — so a permissions programme spends scarce security attention on the least likely vector. The breach-causation point is correct, and any security team choosing between this and multi-factor enforcement should choose multi-factor enforcement. But the realistic threat model was never that an attacker guesses a link. It is that the link is forwarded outside its intended audience, that it walks out with a departing employee who remains able to read it, or that it is indexed because someone pasted it somewhere public. And the consequences that actually bite are not always breaches: they are the discovery request that reveals who could see what, the regulatory inspection that asks how regulated records are shared externally, and the due diligence exercise where an acquirer's counsel asks why a competitor's adviser has standing access to your pricing. All of that is avoidable at the defaults layer, which breaks nothing, plus one scoped remediation covering a few hundred objects rather than the whole estate.
Common Questions
Where should we start if we only have a week?
Expire anonymous links older than a defined age, list guests who have not authenticated in ninety days, and switch the default share scope to internal. Those three changes take days and remove most of the exposure.
Do we need a dedicated tool?
Usually not at first. Native administrative reporting in the major platforms is adequate for the exposure classes that matter; buy tooling once you know what your recurring control needs to be.
How do we avoid breaking legitimate external work?
Announce the change, provide a fast re-share path that produces a properly governed link, and give a grace period. Almost all resistance comes from surprise rather than from the policy.
What should we expect over the next twelve months?
Expect cross-organisation channels to keep spreading and to produce the first serious disputes about whose leaver process governs a shared space. Expect the platform vendors to ship stronger permission reporting, because enterprise buyers have started making it a selection criterion. Expect auditors and regulators to ask specifically how externally shared regulated content is controlled, which is a question most organisations currently cannot answer with evidence. Expect the problem to grow faster as flexible workspace tools spread and every team builds its own sharing conventions. And expect access review capability to be sold as a separate paid tier rather than included, which is worth negotiating for at renewal rather than after.
Permissions Audit — we rank your estate by exposure rather than object count, fix the defaults so the backlog stops growing, and tie guest expiry to the engagements and final settlements that actually complete.
