Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Control who can view, change and reshare a document

One wrong recipient or public link can disclose data. Match access to the task and review it after sending.

Employees, external partners and cloud-service usersAbout 6 minutes of reading + 3 questions
Start with the example Shared a document with the wrong person?

What you will learn

  • Choose named access instead of a public link when the content is not public.
  • Grant only the permission the recipient needs.
  • Revoke mistaken or outdated sharing.

Practice example

A customer list is shared with an external partner

Cloud serviceA customer list is shared with an external partner

Anyone with the link can view and download the document. The link has no expiry date.

Access is not tied to a personMore is allowed than necessaryAccess has no end point
Fictional example for practice.
Show the example explanation
Access is not tied to a person
The link can be forwarded without a clear record of the actual recipient.
More is allowed than necessary
Viewing does not require editing, downloading or further sharing rights.
Access has no end point
The collaboration may finish while the document remains available.

Before sharing: check content and recipient

First establish whether the document may leave the organisation and whether it contains more information than the recipient needs. Check the full address or account; autocomplete can select a person with a similar name.

For confidential content, avoid “anyone with the link”. Tie access to a named account and, where supported, require sign-in and an additional authentication factor.

Grant the minimum permission

Separate three decisions:

  1. Who gets access? One person, a defined group or the whole organisation.
  2. What can they do? View, comment, edit, download or share further.
  3. For how long? Until a date, the end of the task or manual revocation by the owner.

If reading is enough, do not grant editing. If the work has an end date, set an expiry or record the need to remove access.

A public link is convenient but makes it harder to know who used it. It can remain in a forwarded message, chat history or old project document. Named access gives better records and a practical way to revoke access to sensitive information.

Do not enter a cloud-service password on a page opened from an unexpected message. Open the known service independently and check the shared item there.

Review access over time

  • Remove people who no longer work on the task.
  • Review group membership, not only the document’s visible recipient list.
  • Remove links with no owner or business purpose.
  • Check whether recipients can download or share further.
  • Follow the organisation’s process when an employee or supplier leaves.

If information was shared incorrectly

  1. Revoke the link or remove the incorrect recipient immediately.
  2. Preserve the audit record and note what was shared, with whom and for how long.
  3. Notify the data owner and relevant security, privacy or legal team under your organisation’s procedure.
  4. Do not assume revocation erased copies that were already downloaded.
  5. If the account itself may be compromised, secure it and review other files and links it shared.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A business document should be seen by one external partner. How do you share it?

Why does this matter? Named access supports identity checks and later revocation without sending another copy.

  1. Use a public link with no expiry so sign-in cannot become a problem.

    A public link can be forwarded and remain active after the work ends.

  2. Share to a named account, view-only, for the duration of the task.Correct answer

    Recipient, permission and duration match the actual need.

  3. Attach it to a personal address supplied in a message.

    A personal address and new copy may bypass policy and make revocation impossible.

The recipient only needs to read a document. Which permission fits?

Why does this matter? The minimum required permission reduces the impact of a mistake or compromised account.

  1. Owner.

    Ownership grants far more control than the task requires.

  2. Can edit and reshare.

    Editing and resharing are not necessary for reading.

  3. Can view.Correct answer

    View access supports the task without unnecessary capabilities.

A document went to the wrong recipient. What do you do first?

Why does this matter? Prompt revocation can prevent later access, but cannot prove that the content was not already viewed or downloaded.

  1. Revoke access immediately and notify the data owner or relevant response team.Correct answer

    Revocation limits further exposure, while reporting enables assessment and documentation.

  2. Rename the document.

    Renaming does not change the permissions on an existing link.

  3. Wait for the recipient to say they did not open it.

    Waiting leaves access active and delays response.

No registration. Your answers are not sent; the result is just for you.

Share controlled access, not an uncontrolled copy

Check the recipient, minimum permission and the moment access should end.

Respond if information has already been exposed

References

Sources and further reading

The access-control principles are based on the UK National Cyber Security Centre guidance for secure SaaS use (United Kingdom), including named recipients, minimum permissions and revocable access.

Content last reviewed