Google Workspace Setup: Secured Docs Repository

Modified on Mon, 31 Aug at 11:47 AM

One-Time Administrative Setup


Step 1: Enable External Sharing Policies (Admin Console)


  1. Log into the Google Admin Console (admin.google.com) using an Administrator account.

  2. Go to Apps > Google Workspace > Drive and Docs > Sharing settings.

  3. Under Sharing outside of [Your Organizational Unit] , set the policy to ON.

  4. Check the box: "Allow users to send sharing invitations to people outside your organization who aren't using a Google Account". Click Save.

  5. Go to Directory > Groups (or Group Settings) and ensure "Allow members outside your organization" is enabled globally.




Step 2: Create and Secure the Board Google Group


Instead of managing permissions file-by-file, access will be granted through a single centralized group.

  1. In the Admin Console, go to Directory > Groups and click Create group.

  2. Enter Group Name (e.g., Board Directors) and Group Email (e.g., board-directors@yourdomain.co.ke).

  3. Configure Group Labels

    • [✓] Mailing (CHECK): Configures the group to receive distribution emails and Drive permissions.

    • [ ] Security (UNCHECK): Leave unchecked. Applying the Security label enforces restrictive policies that block personal email addresses (@gmail.com, @yahoo.com) from joining.

    • [ ] Locked (UNCHECK): Leave unchecked to allow direct membership management in the Admin Console.

  4. Configure Access Settings

    • Who can join the group: Select Only invited users (prevents internal employees from self-joining).

    • Allow external members: Toggle ON.

    • Allow admins to add external members: Toggle ON.

    • Allow users to add external members: Toggle ON (allows group owners or the Board Secretary to add directors).

  5. Set Access Permission Grid

    • Under Who can post, select [✓] Group owners and Group managers. . (This allows only the Board Secretary, ICT administrators, or designated owners and managers to send updates to the group address without needing to be added as regular members of the group ).

    • Leave Who can view members and Who can view conversations restricted to Group Owners, Managers, and Members only.

  6. Configure Security Settings (Member Restrictions)

    • Select No restrictions.

    • Crucial Note: Do not leave "Restrict membership" selected, as the default rule (member.customer_id == groupCustomerId()) blocks external personal email addresses from being added.

  7. Click Create Group, then add your external directors' personal email addresses as Members.




Step 3: Create and Lock Down the Shared Drive (IRM Setup)


  1. Open Google Drive using a Business Standard or Business Plus account.

  2. Select Shared drives on the left panel, click New, and name it Board Minutes & Governance.

  3. Click Manage members (top right) and add board-directors@yourdomain.co.ke with the role of Viewer.

  4. Click the Gear icon (Settings) in the top right of the Shared Drive header to apply Information Rights Management (IRM) controls:

    • [✓] Allow people outside of [Your OU] to access files (Checked).

    • [X] Allow people who aren't shared drive members to access files (Unchecked - prevents unauthorized public link sharing).

    • [✓] Allow content managers to share folders (Checked).

    • [X] Commenters and viewers under "People who can download, copy, and print" (UNCHECKED - Enforces Anti-Download/Print/Copy).

  5. Click Done.




(Optional): Executive Board Portal (Google Sites Overlay)


If you prefer an executive dashboard layout rather than a standard folder list:

  1. Go to sites.google.com and create a blank site named Board Executive Portal.

  2. Embed the Board Minutes & Governance Shared Drive folder on the main page using Insert > Drive.

  3. Click the Share with others (Person icon) at the top:

    • Draft Settings: Click the dropdown next to Draft and set to Restricted (or Remove Link) so domain users cannot modify the portal layout.

    • Published Settings: Set General Access to Restricted.

    • Add Members: Type board-directors@yourdomain.co.ke and assign the role of Published Viewer.

  4. Click Publish. Directors will access all meeting materials directly through the portal URL.


Phase 3: Day-to-Day Operations & Workflow


Step 4: Publishing New Reports and Minutes


  1. Upload the meeting report or minutes directly into the Board Minutes & Governance Shared Drive.

  2. To notify directors, right-click the file or folder, click Share, and enter board-directors@yourdomain.co.ke

  3. Keep "Notify people" checked, add a message (e.g., "Q3 Financial Reports and Meeting Minutes are available for review"), and click Send.

  4. Directors receive an email with a direct secure link - zero heavy attachments hit their inboxes.


Step 5: Executive Director Viewing Experience


  1. The director clicks the document link in their email inbox.

  2. They sign in using their personal email account credentials.

  3. The file opens in their browser in View-Only mode:

    • File download buttons are hidden/disabled.

    • Printing functions are blocked.

    • Text selection and copying (Ctrl+C) are disabled.


Step 6: Instant 1-Click Offboarding


  1. When a director's term ends, go to Admin Console > Directory > Groups > Board Directors > Members.

  2. Remove their personal email address from the group.

  3. Result: Their access to the Google Site, the Shared Drive, and all current, historical, and future board files is revoked immediately across all devices.


Summary of Benefits

  • No Extra Costs: Uses capabilities already active in your Google Workspace license stack.

  • No Inbox Clutter: Files remain centrally hosted in your secure cloud.

  • Complete Data Control: Prevents local saving, forwarding, or printing of sensitive board materials.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article