Patronum Logo
00%
Patronum Logo
menu-icon

How to Audit Google Drive Access, Sharing and Logs

By Patronum

July 13, 2026

Read Time: 6 mins

To audit Google Drive access, open the Google Admin console, go to Reporting, then Audit and investigation, then Drive log events. From there you can search actions like View, Edit, Download, Print, and sharing changes across your organization, filter by user, file, or event type, and spot external access. You need an admin account with the Audit & Investigation privilege, and by default the view shows the last seven days. Here is how to run a useful audit, and where the native tools stop.

Auditing Drive is really about answering three questions: who can see a file, who has done something to it, and whether anything left the organization. The Admin console answers the second and third well. The first, a full picture of current access across every file, is where it gets harder, and we will get to that. Put simply, Drive logs answer “who did what?” better than “who can access what right now?” For current access, check the file’s sharing settings, use Drive inventory or export where available, or use a domain-wide governance tool.

1. Open Drive log events

In the Admin console, go to Menu, then Reporting, then Audit and investigation, then Drive log events. This is the record of user activity in Drive, including files your users create in Docs, Sheets, and Slides and content they upload such as PDFs and Word files (Google Admin Help, “Drive log events”). You need an admin account with the Audit & Investigation privilege to search Drive log events.

[SCREENSHOT: Admin console > Reporting > Audit and investigation > Drive log events – SOURCE: Google Admin UI (we capture)]

One caveat up front: not all Drive activity is logged, and most Drive audit events are only recorded for files owned by users on supported editions (Google Admin Help). Treat the logs as a strong signal, not a guarantee that every action appears.

2. Filter to the events you care about

By default you see recent activity. Add filters to narrow it down: choose an Event name such as View, Rename, Create, Edit, Print, Delete, Upload, or Download, and combine filters with AND or OR (Google Admin Help). To investigate a specific person or file, filter by the actor’s email or the document title. The default range is the last seven days, which you can change.

[SCREENSHOT: Drive log events filter panel with Event name and user filters – SOURCE: Google Admin UI (we capture)]

Use this as a quick reference for what to filter on:

Audit goalFilter for
External sharingVisibility change, Target, Audience
Suspicious downloadsDownload, user, IP address
Data copied outside the organizationSource Copy with Copy Type = External
Unusual third-party app activityApp ID, App name, API method
Specific file investigationResource title or Document ID
Specific user investigationActor email

A starter audit, in five filters

If you just want a concrete first run, do these in order:

  1. Filter for visibility changes in the last 30 days.
  2. Filter for downloads on sensitive or externally shared files, and review anonymous or external activity where available.
  3. Review Source Copy events with Copy Type = External.
  4. Check activity on large or sensitive shared-drive folders.
  5. Export the findings for follow-up.

For larger audits, export results to Sheets, CSV, BigQuery, or your approved SIEM or logging workflow rather than relying only on the Admin console view.

3. Look for sharing and visibility changes

For an access audit, the useful signals are the sharing events. Drive logs record Visibility and Visibility change on an item, the Target whose access was changed, and the Audience for a visibility change (Google Admin Help). Filtering to these shows you when a file was opened up, to whom, and by whom, which is the heart of an access review.

4. Check what left the organization

Downloads and copies are how data actually leaves. Most downloads are logged, including files copied between Drive and a local device through Drive for desktop (Google Admin Help). To catch data copied out of your organization specifically, review Source Copy events with a copy type of External, which Google logs on the original file when someone outside your organization copies it to an external location (Google Admin Help).

5. Check third-party app access

If the concern is data leaving through a connected app, filter Drive log events by App name, App ID, or API method. Drive logs record the app that performed an action and, for downloads and content-access actions that happen through a third-party app, the API method used, such as drive.files.export (Google Admin Help). This helps you tell whether a connected app exported, downloaded, or accessed content, which ties directly into offboarding and OAuth cleanup.

6. Know how external users appear

When you audit sharing, external people show up as anonymous in the actor field, except when they view or edit a document that was explicitly shared with them as an individual or as part of a specific group (Google Admin Help). That is worth remembering before you conclude “no external access,” because some external activity is deliberately not attributed to a named person.

How long logs are kept

The default view shows the last seven days, but Drive log event data is retained for six months (Google Admin Help, “Data retention and lag times”). For longer retention or compliance workflows, export logs to BigQuery or another approved logging destination, which also lets you run larger queries than the console comfortably handles (Google Admin Help). One more timing note: Drive log events are generally near real time, a couple of minutes, but data can lag and in rare cases an event may be delayed or not reported (Google Admin Help).

Where the native audit stops

Two limits matter. First, not everything is logged: most Drive audit events are only recorded for files owned by users on supported editions, so activity on files owned by unsupported accounts may not appear (Google Admin Help). Second, and more important for an access review, log events tell you what happened to files, not a standing inventory of who currently has access to every file across the domain. The richer security investigation tool exists, but it is available only on supported editions, including Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus, and Cloud Identity Premium (Google Admin Help, “About the security investigation tool”).

Where available, Drive inventory export can help with a file inventory, but Drive log events remain activity history rather than a complete current permissions map. So the Admin console is excellent for “what changed” and “what left,” and weaker for “show me every over-shared and externally shared file right now, across everyone.”

Closing that gap

A point-in-time map of current access across every user is what most access reviews actually need, and it is the part native logs do not give you. Patronum gives admins domain-wide visibility of file access, surfaces externally shared and over-shared files across every user, and supports bulk remediation, so an access audit becomes something you can act on rather than just read. If external sharing is your main concern, our piece on Drive file governance and external sharing is a good next read.

FAQ

Where do I find the Google Drive audit log?
In the Admin console under Menu, then Reporting, then Audit and investigation, then Drive log events. You need an admin account with the Audit & Investigation privilege (Google Admin Help).

What Drive activity can I see in the logs?
Events such as View, Rename, Create, Edit, Print, Delete, Upload, and Download, along with sharing and visibility changes (Google Admin Help).

How do I see if files were shared externally?
Filter Drive log events for visibility changes and review the Target and Audience. External actors appear as anonymous unless a document was explicitly shared with them (Google Admin Help).

How do I know if data was copied out of my organization?
Review Source Copy events with an External copy type, which are logged on the original file when an outside user copies it to an external location (Google Admin Help).

Can I see who currently has access to every file?
Not directly from the logs. Drive log events show actions over time, not a standing inventory of current access. The security investigation tool is richer but available only on supported editions, including Frontline, Enterprise, and Education Standard and Plus, Enterprise Essentials Plus, and Cloud Identity Premium (Google Admin Help).

How far back do Drive logs go by default, and how long are they kept?
The view defaults to the last seven days, which you can change to a wider range. Drive log event data is retained for six months; for longer retention, export to BigQuery (Google Admin Help, “Data retention and lag times”).

Audit Drive access without the blind spots

Logs tell you what changed. For a live picture of who can access what across your whole domain, see how Patronum audits Google Drive access and lets you fix oversharing in bulk.

Sources

  • Google Admin Help, “Drive log events”: https://support.google.com/a/answer/4579696
  • Google Admin Help, “Data retention and lag times”: https://support.google.com/a/answer/7061566
  • Google Admin Help, “About the security investigation tool” (supported editions): https://support.google.com/a/answer/7575955
  • Google Admin Help, “About the audit and investigation tool”: https://support.google.com/a/answer/9725452
  • Google Drive Help, “Share files from Google Drive”: https://support.google.com/drive/answer/2494822