Cloud storage makes it possible to create, store and share files without keeping every document on one computer. A small business in Nairobi can send a proposal to a client in Mombasa, a distributed team can edit the same spreadsheet, and a student can access coursework from a phone, laptop or shared computer. These conveniences depend on two related ideas: file sharing and permissions.
File sharing determines who can access a file or folder and how they receive that access. Permissions determine what those people are allowed to do once they have access. Understanding the difference helps you collaborate efficiently while reducing accidental disclosure, unwanted changes and loss of control over important information.
What File Sharing Means in the Cloud
File sharing is the process of giving another person or group access to a digital file or folder. In cloud tools, the original file usually remains on a provider's online storage system rather than being copied manually to a USB drive or sent as a large email attachment. Examples of cloud storage and collaboration tools include Google Drive, Microsoft OneDrive, SharePoint, Dropbox and similar services.
Sharing may take several forms:
- Direct sharing with named people: You enter specific email addresses and invite those users.
- Sharing with a group: Access is given to a team, department or collaboration group managed by an organisation.
- Link sharing: You create a link that may work for selected users, anyone in an organisation or anyone who obtains the link, depending on the settings.
- Sharing a folder: People receive access to multiple files in one location, often with the same or related permissions.
- Publishing or embedding: A file is made available more broadly, such as a public document or a file displayed on a website.
Sharing does not automatically mean that recipients can edit a file. A file may be shared for viewing only, or users may be allowed to comment, download, edit or manage other users' access. Those actions are controlled by permissions.
What Permissions Control
Permissions are rules that define what an authenticated user can do with a file, folder or shared resource. The exact names vary between services, but most cloud tools provide a set of roles similar to the following:
Viewer or read-only access
A viewer can open and read a file but normally cannot change its contents. Depending on the service and the owner's settings, a viewer may still be able to download, print or copy the file. Read-only access is suitable when you want someone to review a quotation, policy or report without allowing direct editing.
Commenter or reviewer access
A commenter can usually add comments, suggestions or annotations without changing the main content directly. This is useful when a manager reviews a draft proposal or a client provides feedback on a design. Commenting is not the same as editing: a commenter may identify an error but may not be able to correct the text themselves.
Editor or contributor access
An editor can change the file. Depending on the tool, an editor may also be able to move, rename, delete or share the file. In some systems, editing a file and managing access are separate abilities; in others, a person with broad editing rights may have additional control. Always inspect the provider's description rather than assuming that every editor role works identically.
Owner or administrator access
An owner or administrator has the highest level of control. This may include changing permissions, transferring ownership, deleting the file permanently or managing settings for a workspace. Ownership is especially important when files belong to a business rather than to an individual employee.
Sharing Links: Convenient but Easy to Misuse
A sharing link is a web address that leads to a file or folder. Links are convenient because you do not need to enter every recipient's address. However, a link's safety depends on who is allowed to use it.
Common link settings include:
- Restricted: Only named users or approved members can open the resource.
- Organisation-only: People signed in to the same organisation's account can access it.
- Anyone with the link: Anyone who obtains the link may be able to open it, even if you did not intend to share it with them.
An unrestricted link can be forwarded, copied into a message, captured in a screenshot or exposed in an improperly secured system. It may also remain active after the original purpose has ended. For confidential documents, direct sharing with named users is generally easier to control than an open link.
Before sending a link, ask three questions: Who exactly needs access? Do they need to sign in? What can they do after opening it? If the answer to the last question is only “read”, do not grant editing rights merely because the tool offers them by default.
Files, Folders and Inherited Permissions
Cloud tools often apply permissions at more than one level. A person may be given access to an individual file, a folder containing that file, a shared drive or an entire team workspace. Access inherited from a higher-level folder can affect the file even when its individual settings appear limited.
For example, suppose a business creates a folder called Client Projects and gives the sales team editing access. A confidential pricing document placed inside that folder may automatically become available to every member of the sales team. Restricting the file itself may be possible, but the result depends on the service and the type of shared storage being used.
Folder sharing is efficient for ongoing teamwork, but it requires careful organisation. A useful structure separates information according to its audience and sensitivity. For example:
- Public information: Approved brochures, published images and materials intended for external audiences.
- Internal working files: Team plans, meeting notes and operational documents.
- Restricted files: Payroll records, customer information, contracts and confidential strategy documents.
Do not assume that hiding a file inside a vaguely named folder provides security. Access rules, not the folder name, protect the contents.
The Principle of Least Privilege
A strong permission practice is the principle of least privilege. It means giving each person only the access needed to complete a specific task, for only as long as necessary.
Consider a consultant who needs to review a business plan. Viewer or commenter access may be sufficient. Giving that person full editing access could allow accidental changes, deletion or further sharing. Similarly, a temporary project team may need access during a contract period but not indefinitely.
Least privilege does not mean making collaboration difficult. It means choosing the narrowest permission that supports the work. A practical decision sequence is:
- Identify the task the person must complete.
- Decide whether they need to read, comment, edit, download or administer the resource.
- Choose named-user access where the information is sensitive.
- Set an end date or remove access when the task is complete, if the tool allows it.
- Review whether inherited or additional permissions give more access than intended.
Common Risks in File Sharing
Accidental oversharing
A user may share an entire folder when only one document was required. This can expose unrelated files, previous drafts or personal information. Check the item name and location before selecting the share option.
Editing the wrong version
Downloading files, renaming them and sending multiple copies can create confusion about which version is current. Collaborative cloud documents often reduce this problem because users work from one shared source. When separate files are necessary, use clear names, dates or version labels and identify the official copy.
Uncontrolled downloads and copies
Even if a cloud file is later restricted, someone who previously downloaded, printed or copied its contents may still possess a separate version. Permissions reduce risk but cannot guarantee control over information after a recipient has legitimately viewed it.
Access through compromised accounts
If an account is taken over, an attacker may access every file available to that account. Use strong, unique passwords and enable multi-factor authentication where available. Be cautious with unexpected sign-in requests and links asking you to verify an account.
Former staff or inactive collaborators
Access can remain active after someone leaves a project or organisation. Businesses should use managed work accounts where possible, maintain an access list and remove people when their responsibilities change.
Confusing personal and organisational storage
A document created for an employer may be stored in an employee's personal account. This can complicate continuity, ownership and access when the employee changes roles. Organisations should establish clear rules about where business files belong and use shared workspaces for team-owned information.
A Safe File-Sharing Workflow
You can apply the following workflow to most cloud tools:
- Classify the file. Decide whether it is public, internal, confidential or highly restricted. Consider personal data, financial information, passwords, contracts and commercially sensitive material.
- Choose the correct storage location. Use an approved business workspace for organisational files and avoid storing sensitive work in an unmanaged personal account.
- Select recipients carefully. Check email addresses character by character. Similar names or autocomplete suggestions can lead to the wrong recipient.
- Choose the minimum permission. Select viewer, commenter or editor based on the task, not on convenience.
- Configure link settings. Prefer restricted access for sensitive materials. If a link must be used, check whether it can be limited to signed-in users or given an expiry date.
- Add context. Tell recipients what the file is, what action is required and whether they should avoid forwarding or downloading it.
- Review after sharing. Open the access panel later to confirm who can use the file. Remove old collaborators and replace broad links when they are no longer needed.
Practical Example: Sharing a Business Proposal
Imagine a Kenyan consultancy preparing a proposal for a potential client. The draft contains pricing, staff details and internal notes. The team could create a final client-facing copy that excludes internal comments, store it in the organisation's approved workspace and share it directly with the client's named contacts as viewers or commenters.
If the client needs to suggest changes, commenter access may be enough. If the client must complete specific sections, editor access may be appropriate, but the team should first remove internal material and preserve an earlier version. After the submission deadline, the consultancy can change the file to restricted access or remove the client's access, while retaining an internal record according to its own document-retention practices.
This example demonstrates an important habit: security is not just a setting applied at the moment of sharing. It includes preparing the correct file, selecting the right location, limiting access and reviewing access afterwards.
Applying This in Practice
Use this short checklist before sharing any cloud file:
- Am I sharing the correct file rather than the whole folder?
- Does the file contain information that should be removed before external sharing?
- Can each recipient be identified, or am I relying on an open link?
- Do recipients need to view, comment or edit?
- Can downloading, copying or printing be limited in this tool?
- When should access end?
- How will I confirm that the file is no longer shared with people who do not need it?
For teams, document a simple sharing policy. It can explain approved storage locations, acceptable link settings, treatment of confidential information, use of multi-factor authentication and the process for removing access. Short, understandable rules are more useful than a policy that employees cannot apply during ordinary work.
Key Takeaways
- File sharing gives people access to a cloud resource; permissions define what they can do with it.
- Use named-user or restricted sharing for confidential files whenever practical.
- Choose viewer, commenter or editor access according to the actual task.
- Remember that folder and workspace permissions may be inherited by individual files.
- Review links and collaborators regularly, especially after a project or staff role ends.
- Store business files in approved organisational workspaces rather than unmanaged personal accounts.
No comments yet.