๐ Lesson 4.2: Expiry, Restrictions & Ownership โ Sharing Under Control
Last lesson you learned who and what role. Now you learn the dials that put a share fully under your control: shares that expire, Viewers who can't download or copy, Editors who can't re-share, transferring ownership, cleanly removing access, handling access requests, and auditing everything you've shared. Some of these are free for everyone; a few are Workspace-only โ and we'll be honest about which is which.
๐ What You'll Learn
By the end of this lesson, you will be able to:
- Set an access expiration date so a share ends itself (a Workspace feature โ hedged)
- Restrict Viewers/Commenters from downloading, printing, or copying a file
- Turn off re-sharing so only the owner manages who has access
- Understand and perform a transfer of ownership
- Remove access and know what that does to existing links
- Handle pending access requests and audit what you've shared with the "Shared with me" and shared views
โฑ๏ธ Estimated Time: 40 minutes
๐ฏ Project: Add a restriction (no download) or an expiry to a shared file if your account offers it, review or transfer ownership on a file, and run a quick audit of what you've already shared.
In This Lesson
๐๏ธ From "Who Can Get In" to "Under Full Control"
In Lesson 4.1 you learned the two big decisions of sharing: who gets access (specific people vs a link) and what role they hold (Viewer, Commenter, Editor). That's enough to share safely. But real life has finer needs. You share a contract with a client โ but only want them to see it for a week. You send a sensitive PDF for review โ but don't want copies floating around. You add a collaborator as Editor โ but don't want them inviting their whole team without asking. And sometimes you're handing a project off entirely, and the file needs a new owner.
These are the control dials, and they turn sharing from "on or off" into something you shape precisely. Think of Lesson 4.1 as choosing who gets a key; this lesson is about how long the key works, what the key doesn't unlock, whether the key-holder can cut copies of the key, and how to hand over the whole building. It's the same "share on purpose" mindset, now with the fine adjustments that let you say exactly what you mean.
โ ๏ธ Honest heads-up: some of these are Workspace-only
A few controls in this lesson โ most notably access expiration dates and, on some files, certain restriction options โ are features of paid Google Workspace (business/education) editions, and may not appear on a free personal account. Others (like restricting download for Viewers, and turning off re-sharing) are widely available. Google also moves features between tiers and changes the menus over time. Rather than promise you'll see a specific button, we'll teach the concept and tell you where to look โ and if an option isn't in your dialog, that's expected, not a mistake on your part. When it matters, check Google's current Drive help pages for what your account offers.
โณ Access Expiration Dates (Workspace)
An access expiration date makes a share end itself. You give someone access, set a date, and when that date arrives their access quietly disappears โ no reminder to yourself, no cleanup, no "I really must unshare that eventually." It's perfect for time-boxed collaboration: a contractor on a three-month project, a client reviewing a proposal for two weeks, a candidate looking at materials during a hiring window.
You'll typically find it in the Share dialog: add or select a person, and near their role there's an option (often behind a small menu or the settings area) to set when their access expires. When the date passes, Drive removes them automatically. It's the tidiest possible way to say "you can see this, but not forever."
โ ๏ธ This one is usually Workspace-only
Access expiration is generally a Google Workspace feature and often applies to Commenter and Viewer roles rather than every situation. On a free personal account you may not see it at all. If it's missing, don't worry โ the manual equivalent is simple and free: set a reminder for yourself, and when the time comes, open the Share dialog and remove the person (covered below). Same result, one extra step. Because exactly which editions include it changes, check Google's current pages rather than assuming.
โ Why expiry is such a good habit
The biggest source of "how is that person still able to see this?!" is simply forgetting to unshare. Access piles up silently over years. An expiration date โ or a personal reminder if you don't have the feature โ turns "I'll clean it up someday" into "it cleans itself up." Time-boxing access is one of the most underrated security habits there is.
๐ซ Restrictions: No Download, Print, or Copy
By default, anyone you share with โ even a Viewer โ can usually download, print, or copy the file. That's fine for most things, but sometimes you want people to read a document without being able to walk away with their own copy. A confidential report, a draft you don't want circulated, pricing you'll show but not hand over. For these, there's a restriction, typically found behind the gear/settings icon in the Share dialog: an option along the lines of "Viewers and commenters can see the option to download, print, and copy" โ untick it, and those buttons disappear for them.
It's an excellent extra layer, and you should reach for it whenever a file is sensitive. But it's important to understand its honest limits, because over-trusting a control is its own kind of risk.
โ ๏ธ A restriction discourages copying โ it can't truly prevent it
Turning off download/print/copy removes the easy buttons, and that genuinely stops casual copying. But a determined person who can see a document on their screen can still screenshot it, retype it, or photograph the screen. No sharing setting can change that โ it's true of every platform, not just Drive. So treat "no download" as a strong deterrent and signal ("this is not for redistribution"), not an unbreakable vault. The real protection for truly secret information is not sharing it with people you don't trust in the first place. Controls reduce accidents; they don't defeat determined misuse.
๐ก Restrictions pair beautifully with roles
The strongest "look but don't take" setup is Viewer + download/print/copy off. The person can read the file, but can't edit it, can't comment, and doesn't get an easy copy. That's about as locked-down as ordinary sharing gets, and it's perfect for showing sensitive material for reference. Layering role (Viewer) with restriction (no download) is control working the way it should.
๐ Disabling Re-Sharing by Editors
Here's the setting we flagged in the last lesson. By default, an Editor can re-share your file โ they can add other people and change access, all without asking you. That's often desirable (real collaborators managing their own team), but it also means giving one person Editor can quietly widen the circle far beyond who you chose. If you want to stay the sole gatekeeper, you turn re-sharing off.
The control lives behind the same gear/settings icon in the Share dialog, usually worded like "Editors can change permissions and share." Untick it, and now only the owner can add people or change roles. Editors can still edit the content freely โ they just can't hand out access. It's the classic move for "I want their help editing, but I decide who's in the room."
& change access themselves"] B -->|"OFF"| D["Only the OWNER can
add people or change roles"] C --> E["โ ๏ธ Circle can widen
without you choosing"] D --> F["โ You stay the sole gatekeeper
Editors still edit content freely"]
โ When to turn re-sharing off
Turn it off whenever the membership of a share matters as much as the content โ sensitive files, a fixed set of collaborators, anything where "who else can see this?" needs to stay your decision. Leave it on for open, trusted, team-owned collaborations where you want people to manage access themselves. As always: least privilege. If you don't need Editors to re-share, don't let them.
๐ Transferring Ownership
Every file has exactly one owner โ normally whoever created it. The owner sits above every role: they can do everything an Editor can, plus delete the file for everyone, and transfer ownership to someone else. Sometimes you genuinely want to hand a file over: you're leaving a project, someone else is taking the lead on a document, or a shared resource should really belong to the person who now maintains it.
To transfer ownership, you first share the file with the new person as an Editor, then in the Share dialog change their role to Owner (sometimes shown as "Make owner" or "Transfer ownership"). They may need to accept. Once done, they control the file โ including the power to remove you. So it's a deliberate, one-way-feeling step: give it real thought before you hand over the keys to the building.
โ ๏ธ Ownership transfer is a big, deliberate step
After a transfer, the new owner holds full control and could, in principle, remove your access entirely. Only transfer ownership when you truly mean to hand the file off. Also note: on Workspace accounts, ownership transfer often only works within the same organization, and an admin may govern it. And there's a cleaner answer for team files coming in the next lesson โ shared drives, where files belong to the team rather than any one person, so nobody has to "own" them at all.
๐ Definition โ owner vs Editor
It's easy to blur these, so: an Editor can change the file's content (and, unless you disable it, its sharing). The owner can do all of that and permanently delete the file for everyone, and transfer ownership. Deleting a file you own removes it for everyone it's shared with; an Editor removing it only takes it out of their own view. That extra power is why ownership is a separate, weightier thing than "top role."
๐งน Removing Access, Requests & Auditing
Removing access โ and what it does to links
Removing access is the reverse of sharing, and it's just as important. In the Share dialog, open the menu next to a person and choose Remove access โ they can no longer open the file, immediately. To make a link-shared file private again, set General access back to Restricted: the old link stops working for anyone who wasn't specifically invited. This is the crucial point โ changing the link setting to Restricted effectively kills the old public link. Anyone who had it, saved it, or was forwarded it is now locked out. That's your "undo" for an over-share, and it works instantly.
โ The fastest fix for "I over-shared something"
If you ever realize a file is more public than it should be, do this: open Share โ set General access to Restricted โ remove any specific people who shouldn't be there. Done. The link is dead, the list is clean. Knowing this is a two-click fix takes the fear out of sharing โ mistakes are completely recoverable.
Pending access requests
Sometimes someone opens a link they can't access and clicks Request access. You'll get an email, and can grant (choosing their role) or deny it. This is a genuinely nice safety pattern: instead of defaulting a file to public so nobody ever gets stuck, you can keep it Restricted and simply approve the specific people who ask. Treat each request like the three questions from Lesson 4.1 โ do I know them, do they need it, and what's the lowest role that works?
Auditing what you've shared
Good sharing isn't just careful in the moment โ it's reviewed over time. Drive gives you views to see the state
of things. "Shared with me" in the left navigation shows files others have shared with
you. To find what you've shared with others, use Search โ search tools let you
filter by owner (for example owner:me) and by people you've shared with โ and open the Share dialog on important files to read their
access list directly. Periodically walking through your most sensitive files and asking "does this list still make
sense?" is the audit habit that keeps a Drive trustworthy for years.
access ends on a date"] A --> C["๐ซ Restrict
no download / print / copy"] A --> D["๐ No re-share
only owner manages access"] A --> E["๐ Ownership
hand the file off"] A --> F["๐งน Remove / audit
revoke & review over time"]
๐ก Build a 10-minute quarterly "share review"
Once a quarter, spend ten minutes on your most sensitive files and folders: open each Share dialog, read the access list, and remove anyone who no longer needs to be there. Check that nothing important is accidentally set to "anyone with the link." That tiny ritual is the difference between a Drive that quietly accumulates risk and one that stays clean and trustworthy. Put it on your calendar.
๐ฏ Project: Tighten & Audit Your Shares
This project puts the control dials in your hands and builds the audit habit. Because some features are Workspace-only, we've written it so every account can complete a meaningful version โ do the parts your account offers, and reason through the rest. Use the file you shared in Lesson 4.1's project as your working example.
๐๏ธ Add a control, review ownership, and audit
Objective: Apply at least one control to a shared file, understand ownership on your files, and run a first quick audit of what you've shared.
Instructions (about 15 minutes):
- (3 min) Open the Share dialog on your shared file and find the gear/settings icon. Try to add a restriction: untick "Viewers and commenters can download, print, and copy." If your account offers it, apply it; if you don't see it, note that and move on โ that's expected.
- (3 min) Look for an expiration date option on a shared person (Workspace feature). If it's there, set one a week out. If not, do the free equivalent: set a calendar reminder to remove that person's access on a chosen date.
- (2 min) If the file has an Editor, find the "Editors can change permissions and share" setting and turn it off, so only you manage access. Notice the Editor can still edit content.
- (3 min) Review ownership: confirm you're the owner of your own files (you'll see "owner" beside your name). You don't have to transfer anything โ just locate where "Transfer ownership / Make owner" would be, and read the warning it implies.
- (2 min) Practice the undo: on any test file, set General access to "Anyone with the link," copy the link, then immediately set it back to Restricted. Confirm you understand the old link is now dead.
- (2 min) Run a mini-audit: open "Shared with me", then use Search to find files you've shared. Pick your most sensitive shared file and read its access list. Does it still make sense?
๐ก Hint โ a personal "sharing audit" checklist
My sharing audit
- Most sensitive shared files:
1. ___ | who's on it? ___ | still correct? Y/N
2. ___ | who's on it? ___ | still correct? Y/N
- Any file set to "Anyone with the link" that shouldn't be? ___
- Anyone with access who no longer needs it? Remove them.
- Any Editor who could re-share but shouldn't? Turn it off.
- Reminder set for time-boxed shares? ___
Fix now: set General access to Restricted where needed,
remove stale people, tighten roles to least privilege.
If a control isn't in your dialog, write "not available on my account" next to it โ knowing what your account doesn't have is part of using it wisely.
โ Project Completion Checklist
- You explored the gear/settings icon and applied a restriction (or noted it's unavailable and set a manual equivalent)
- You set an expiry date or a calendar reminder to remove access later
- You know where re-sharing and ownership controls live and what they do
- You practiced the "set to Restricted" undo and understand it kills the old link
- You ran a first audit and confirmed your most sensitive share's access list still makes sense
๐ฏ Quick Quiz
Question 1: You shared a file as "Anyone with the link" and now want it private again. What's the reliable way to kill the old link?
Question 2: You turn off "download, print, and copy" for a Viewer on a confidential file. What's the honest limit of this control?
Best Practices for Sharing Under Control
โ Do's
- Time-box access. Use expiry (or a calendar reminder) so shares don't outlive their purpose.
- Turn off re-sharing when membership matters. Stay the sole gatekeeper for sensitive files.
- Pair Viewer with "no download" for sensitive reference files. Look, don't take.
- Audit quarterly. Ten minutes reading access lists keeps risk from piling up.
โ Don'ts
- Don't treat "no download" as a vault. It deters casual copying; it can't stop screenshots. Trust the person, not just the setting.
- Don't transfer ownership casually. The new owner can remove you โ do it only when you truly mean to hand off.
- Don't assume every control is on your account. Some are Workspace-only; check what you actually have.
๐ก Pro Tips
- The two-click over-share fix โ set to Restricted, remove stale people โ makes mistakes fully recoverable. Knowing it removes the fear.
- Keep sensitive files Restricted and use "Request access" to approve people individually, rather than defaulting to public so nobody gets stuck.
๐ Learning Journal
Keep a learning journal as you work through this course โ a separate document, a note, or a Google Doc right in the Drive you're organizing. After each lesson, take a few minutes to write down:
- Key concepts you learned
- Techniques that clicked for you
- Questions or confusion points to revisit
- Ideas you want to try in your own Drive
- Your progress and feelings about learning this โ including where your confidence grew
โ๏ธ This lesson's prompt: Which control matters most for the way you actually use Drive โ expiry, no-download, no-reshare, or the audit habit? Was there anything you shared in the past that you'd now time-box or lock down? And how did it feel to learn that an over-share is a two-click fix โ does knowing you can always undo it change how confident you feel about sharing?
๐ Lesson Summary
๐ Key Takeaways
- Access expiration dates end a share automatically on a chosen date โ great for time-boxed collaboration (usually a Workspace feature; the free equivalent is a reminder plus manual removal).
- Restricting download/print/copy stops casual copying, but can't defeat screenshots โ it's a strong deterrent, not a vault. Pair it with Viewer for "look, don't take."
- Turning off re-sharing keeps you the sole gatekeeper: Editors can still edit content, but only the owner manages who has access.
- Ownership sits above every role (delete for everyone, transfer). Transfer is deliberate and, on Workspace, often within-org only.
- Removing access and setting General access to Restricted instantly kills an old public link โ the two-click undo for an over-share. Audit your shares periodically.
๐ What You've Accomplished
You've moved from "I can share" to "I share exactly what I mean, and I can take it back." You know the control dials โ expiry, restrictions, re-sharing, ownership โ and, just as importantly, their honest limits and which are Workspace-only. You practiced the over-share undo and ran your first sharing audit. That combination of precise control and calm recoverability is what makes advanced sharing feel powerful instead of nerve-wracking.
โ Common Questions at This Stage
Why don't I see the expiration date or some restriction options?
Almost certainly because they're Google Workspace (paid business/education) features and you're on a free personal account โ or Google has moved them between tiers, which it does. This is normal and not a mistake on your part. Everything essential to safe sharing works on the free tier; for the extras, the manual equivalents (reminders, removing access) get you the same outcome. Check Google's current pages for exactly what your edition includes.
If I remove someone's access, do they lose the copies they already made?
No โ and this is important. Removing access stops them opening the original from now on, but if they already downloaded it, copied it, or made their own version while they had access, that copy is theirs and out of your control. This is exactly why the honest limit of "no download" matters, and why the real safeguard is being thoughtful about who you share sensitive things with in the first place.
Should I transfer ownership, or is there a better way for team files?
For a one-off handoff (you're leaving, someone else now maintains a doc), transferring ownership is right. But if files really belong to a team rather than a person โ and should survive people coming and going โ there's a cleaner answer: shared drives, where the team owns the files collectively and no single person's departure orphans them. That's exactly where we go next.
๐ญ Looking Ahead
In the next lesson โ Lesson 4.3: Shared Drives vs My Drive, and Security Best Practices โ we zoom out to the two homes your files can live in: My Drive (files you own) and shared drives (files the team owns), when each wins, and then a proper security checklist โ least privilege, public-link caution, phishing and fake-share awareness, and 2-step verification. It's the capstone of the whole sharing module.
โ Before the Next Lesson
- Complete the project โ apply at least one control and run your first sharing audit
- Set a calendar reminder for a quarterly 10-minute share review
- Write your Learning Journal entry for this lesson
๐ Additional Resources
- Share files from Google Drive (Google Support)
- Stop, limit, or change sharing (Google Support)
- Google Drive on Google Workspace โ what's included
๐ Encouragement for the Journey
You now hold the fine controls that most people never learn exist โ and you know their honest limits, which is even rarer. Sharing under control isn't about locking everything down; it's about saying exactly what you mean and being able to take it back. That's mastery, and it's yours. One more sharing lesson to go, and it's the one that ties it all together. ๐๏ธ