- Zen IT Technologies
- Technical notes
- Link sharing is the permission nobody revokes
Link sharing is the permission nobody revokes
Jonny Flaks, Founder & Principal Architect
Technical note in Identity & Access Management
A spreadsheet is created in 2019. The person who made it leaves in 2021. Their files transfer to their manager, who has never opened this one. Last month it was read by somebody who has never worked for the company.
No account was compromised. No control failed. Every system behaved exactly as configured.
The permission outside the lifecycle
Almost every permission in a company is attached to a person. Someone joins a group, the group is entitled to an application, and months later you can look the person up and see what they can reach.
An unauthenticated "anyone with the link" share is not granted to a named recipient at all. Possession of the URL is the authorization. An organization-wide link is different: the reader still authenticates, but the grant is to a broad audience rather than to a specific person.
Both patterns sit awkwardly beside controls built around named identities. There may be no individual entitlement to remove, no group membership that explains the access, and no useful answer to a person-centric review asking what one user can open.
Unless the platform or policy applies an expiry, the grant can remain long after the reason for creating it has disappeared.
Three settings, three different problems
The sharing dialog presents these as points on a slider. They are not the same kind of risk.
Anyone with the link. No recipient identity is required. The link can be forwarded, pasted into a ticket or copied into another system, and it remains usable until the share is removed or an expiry policy takes effect.
Anyone in the organization with the link. Authentication is required, but authorization is deliberately broad. Any account inside the allowed organization or audience can open it once they have or discover the link. This is the one people are most surprised by, because "internal" sounds narrower than it often is.
Published and discoverable. On platforms that support public publishing or indexing, the content can move from merely reachable to discoverable. Some of what you find here will be intentional. Some of it will end a meeting early.
Why offboarding walks straight past it
Deprovisioning is built around an identity. Disable the account, kill the sessions, reclaim the seat, transfer the files. Every step assumes a person at the center.
The important point is that the sharing grant belongs to the content, not to the creator's current employment status. Disabling the creator does not normally revoke a file-level share. Account deletion, ownership transfer and moves between locations can behave differently by platform, but none should be assumed to clean up old sharing automatically.
Ownership transfer is where this gets concrete. A leaver's files can move to a manager together with permissions the manager never chose, made by someone no longer available to explain them, on content the new owner may never open.
An access review has the same blind spot for the same reason. A review answers what this person can reach. It cannot answer what this person made reachable.
The folder decision from 2021
Two mechanics keep the total invisible.
Inheritance means a share applied to a folder covers everything dropped into it afterwards, including files created years later by people who never saw the original decision. A deliberate choice made once for one client project is still governing content added last Tuesday.
Re-sharing means a recipient can pass the link on. With an unauthenticated link there is no reliable chain of custody showing where the URL travelled. Authenticated platforms may log who opened content, but that is not the same thing as knowing who now possesses the link.
The result can grow much larger than expected. Environments that have never inventoried these grants often discover a long tail of old shares, including content created by people who have left.
Moving the file changes nothing
The common assumption is that reorganizing content into properly governed locations solves this. On its own, it does not.
Moving content into a better-governed location does not automatically mean its old permissions have been remediated. Depending on the platform and the kind of move, permissions may persist, be replaced by destination inheritance, or need explicit reconciliation.
Treat restructuring and permission remediation as two separate pieces of work. A clean folder structure is not evidence that every object inside it now has the intended audience.
What the inventory comes back with
Finding these usually means enumerating the file estate through administrative reports or APIs rather than relying on an ordinary content search. The exact route varies by platform, but the principle is the same: inspect sharing state at scale, including personal and shared locations.
Sort the output before changing anything:
Published and discoverable. Treat as incident-shaped. Handle today.
Anyone with the link, external reach. The real body of risk. Sort by age. A link created for a deal that closed four years ago is still live.
Anyone in the organization. Volume, not urgency. Fix by policy, not file by file.
Named external individuals. Not a link share, but the same exercise surfaces it, and it always contains a long tail of former vendors, agencies and candidates.
Then sort by owner as well as exposure. Files owned by departed staff, shared accounts and identities that no longer authenticate have no remaining human context. Nobody can tell you why those grants exist, which is precisely why they go first.
There is a newer reason this has become urgent. Assistants and retrieval tooling reach content through an authenticated identity, and internal link shares are exactly the material that identity can technically open but nobody intended it to surface. Over-permissive sharing stayed quiet for years because it was undiscoverable. It does not stay quiet once something is searching on the user's behalf. The companion note, Where data actually leaves through an AI platform, covers that path.
Fixing the default, or doing this again next year
Remediation without a default change creates a recurring cleanup job.
The settings that decide the shape of the problem going forward: what newly created content defaults to and whether users can widen it, whether external sharing is blocked, allowlisted or confined to designated locations, whether external links expire by default, whether recipients can re-share, and whether externally shared content can be downloaded, copied or printed.
Then the part people skip. Where exceptions live, who approves them, and when they get reviewed.
The goal is not to stop people sharing. It is to make the deliberate path the convenient one and the accidental path narrow and short-lived.
The check worth running
Pick someone who left eighteen months ago. Look at what they still have shared by link, and at what transferred to their manager with its permissions intact.
Whatever that returns for one person is roughly your posture, multiplied by every departure since the platform went in.
Explore this expertise: Identity & Access Management