After this module you can: share a file to named people with least access (and an expiry where your plan offers one) โ and explain in one sentence why a public link is publication, not sharing.
โ Fact-checked 2026-09-03 against current Google Drive / Workspace behaviour. Where something depends on your plan or on how a link travels, we say so โ we'd rather you trust this than over-scare you.
1 ยท The Friday report
It's Friday, 17:40. An account manager finishes the monthly partner performance report โ operator names, revenue figures, game results. A colleague on holiday needs it tonight, from a personal laptop, without wrestling with logins.
One click: "Anyone with the link โ Viewer." Link pasted into chat. Done. Weekend saved. Nobody did anything malicious โ the unsafe button was simply one click easier than the safe one.
Here's what that click actually did: it removed the login wall from that file. From that moment, anyone who obtains that string of characters can open it โ no account, no login, no record of who they are โ and it stays that way until a human changes the setting. Not "for my colleague." And links travel.
"Anyone with the link" doesn't share a file with a person โ it publishes the file to the world and hopes the world doesn't notice.
2 ยท How a "private" link escapes โ no hacking required
A link is just text. Text gets copied. Each hop below is boringly ordinary:
1
Forwarding โ by far the most common route. Your colleague pastes it to someone "who also needs it," who pastes it onward. You no longer know who holds it โ and every holder can open it, because nothing checks who they are.
2
Chat & tool previews. Paste a link into many chat apps or ticket tools and their servers may fetch the URL to build a preview card. What they retrieve depends on the service and file, but metadata such as a sensitive title โ and sometimes preview content โ can leave Drive and appear in that channel. Don't assume it is the whole document; don't assume it is nothing.
3
Search discovery โ possible, but conditional. Google does not automatically list a file in search just because it's set to "anyone with the link." If the URL is later posted on a public, crawlable page, search engines and other crawlers can discover and fetch it; whether a given engine indexes the Drive page or its contents varies. (Docs also has a separate File โ Share โ Publish to the web option designed for public web distribution โ never use it for sensitive work content.)
4
Scrapers & leak collectors. Automated tools do harvest exposed cloud links โ where links get published or pasted, not by guessing (Drive IDs are long random strings; brute-forcing them isn't practical). Once a link is out of your hands, collection is automated and cheap.
5
Old links never die. Three weeks โ or three years โ later, the link still works, long after everyone forgot the file exists.
6
No audit trail โ the one that hurts most in our industry. A public link doesn't know who opened it. When a partner or regulator asks "who had access to this player data?", the honest answer is "we cannot say." That applies even if nothing was ever forwarded or indexed.
Why we're not exaggerating: most public links are never indexed and never scraped โ that's exactly the trap, because it feels fine and the habit survives. The reason we don't do it isn't that discovery is certain; it's that exposure becomes unbounded and unprovable, and you only learn which links mattered afterwards.
The contrast: with named-recipient sharing, every one of those hops slams into a login wall โ a forwarded link just shows a "request access" screen. The file checks who you are, not what string you have. Link access checks possession; named access checks identity โ and identity means you can answer "who had access?"
Honest limit: named sharing controls access, not copying. Anyone who can open a file can screenshot it, and in Drive a Viewer can download by default (the owner can turn that off). Least access shrinks the circle and preserves the audit trail โ it doesn't make a file un-copyable. Share with people you'd trust with a printout.
Open the ๐ Link-Sharing Risk Simulator. Set: Customer data + game results โ Anyone with the link โ Never expires, then toggle "someone forwards it" and "3 weeks pass." Watch the audience. Then fix it: Named ร2, Viewer, 7-day expiry โ and watch every leak path die.
3 ยท What was at stake, in Tom Horn terms
That report sat on our Restricted / Confidential shelf:
Customer & operator data โ commercial relationships, contract-sensitive numbers.
Player game results โ regulated data. Regulators can ask us to prove exactly who could access it; "the internet, possibly" is an answer that damages licenses.
Company financials โ competitor gold; negotiation leverage lost.
For a regulated iGaming supplier, a public link to this isn't just an "oops" โ treat it as a potential data incident: email infosec@tomhorngaming.com immediately (and tell your line manager). The response team assesses exposure and decides whether any partner, regulator or authority notification is required. The person who reports fast is doing exactly the right thing โ every time, no blame.
4 ยท The safe-sharing ladder โ your new default
๐ฅ Named people, Viewer. The default. Covers almost everything.
๐ฅ Named people, Commenter / Editor. Only those who must annotate or edit. In most tools, Editor can also re-share โ grant it consciously.
๐ฅ Everyone at Tom Horn (signed-in link). Genuinely company-wide material only. Outsiders still hit a login wall โ but any colleague can open it, and can pass the link to any other colleague. Fine for a handbook; not for a Restricted file with a small need-to-know circle.
๐ซ Anyone with the link. Practically never for work files. Truly public material (a press kit) is a deliberate publishing decision, made with the owner's OK.
Least access in one line: the fewest people, the lowest permission, for the shortest time that still gets the job done. Plus two habits: add an expiry where your tools offer it, and prune stale shares once a quarter.
๐ How expiry really works in Google Drive. Expiration dates apply to named-people shares only โ not "anyone with the link" or organisation-wide General access. A public link stays open until a human changes it. Expiry also needs an eligible Workspace plan (not personal Google accounts), and on folders Google currently offers it only for the Viewer role. So expiry is a useful safety net on named shares โ never a reason to feel OK about a public one. No "Add expiration" option? Ask IT rather than falling back to a link.
The 10-second ritual before every share
Who exactly needs this? โ type their names.
What's the least they need? โ usually Viewer.
How long? โ add an expiration if it's offered (named shares, eligible plans).
Can they re-share? โ Editor can; Viewer/Commenter can't.
Is the file sensitive? (customer data, player results, financials, contracts, credentials, unreleased games) โ if yes: named recipients only, and pause before adding anyone external.
And the holiday-colleague fix? Share to their named account, Viewer, 7-day expiry if available. One extra click. No public-link exposure โ and a record of who was granted access. Actual view history depends on Workspace settings and can be hidden, so don't promise a perfect list of who opened it.
5 ยท Hands-on
Hunt one of your own open links. Heads-up: Google Drive has no "Shared by me" list (that's Dropbox, not Drive), so use one of these:
In My Drive, spot the small shared (people) icon next to a file โ open Share โ check "General access."
Or select a batch of files โ Share โ review their access together.
Or ask IT / the Workspace admin for a sharing report โ admins can list files shared externally or by link across the domain. That's the reliable way to find old ones at scale.
Restrict what you find, or consciously confirm it's meant to be public. If you find something sensitive already public, that's a win, not a fail: fix the setting and give security a heads-up (Module 8 shows how).
6 ยท Quiz โ 10 questions, pass at 8
Scenario-based, unlimited retries, every answer explained. No record of failed attempts is kept.