One-Time Administrative Setup
Step 1: Enable External Sharing Policies (Admin Console)
Log into the Google Admin Console (
admin.google.com) using an Administrator account.Go to Apps > Google Workspace > Drive and Docs > Sharing settings.
Under Sharing outside of [Your Organizational Unit] , set the policy to ON.
Check the box: "Allow users to send sharing invitations to people outside your organization who aren't using a Google Account". Click Save.
Go to Directory > Groups (or Group Settings) and ensure "Allow members outside your organization" is enabled globally.
Step 2: Create and Secure the Board Google Group
Instead of managing permissions file-by-file, access will be granted through a single centralized group.
In the Admin Console, go to Directory > Groups and click Create group.
Enter Group Name (e.g.,
Board Directors) and Group Email (e.g.,board-directors@yourdomain.co.ke).Configure Group Labels
[✓] Mailing(CHECK): Configures the group to receive distribution emails and Drive permissions.[ ] Security(UNCHECK): Leave unchecked. Applying the Security label enforces restrictive policies that block personal email addresses (@gmail.com,@yahoo.com) from joining.[ ] Locked(UNCHECK): Leave unchecked to allow direct membership management in the Admin Console.
Configure Access Settings
Who can join the group: Select Only invited users (prevents internal employees from self-joining).
Allow external members: Toggle ON.
Allow admins to add external members: Toggle ON.
Allow users to add external members: Toggle ON (allows group owners or the Board Secretary to add directors).
Set Access Permission Grid
Under Who can post, select
[✓]Group owners and Group managers. . (This allows only the Board Secretary, ICT administrators, or designated owners and managers to send updates to the group address without needing to be added as regular members of the group ).Leave Who can view members and Who can view conversations restricted to Group Owners, Managers, and Members only.
Configure Security Settings (Member Restrictions)
Select No restrictions.
Crucial Note: Do not leave "Restrict membership" selected, as the default rule (
member.customer_id == groupCustomerId()) blocks external personal email addresses from being added.
Click Create Group, then add your external directors' personal email addresses as Members.
Step 3: Create and Lock Down the Shared Drive (IRM Setup)
Open Google Drive using a Business Standard or Business Plus account.
Select Shared drives on the left panel, click New, and name it Board Minutes & Governance.
Click Manage members (top right) and add
board-directors@yourdomain.co.kewith the role of Viewer.Click the Gear icon (Settings) in the top right of the Shared Drive header to apply Information Rights Management (IRM) controls:
[✓] Allow people outside of [Your OU] to access files(Checked).[X] Allow people who aren't shared drive members to access files(Unchecked - prevents unauthorized public link sharing).[✓] Allow content managers to share folders(Checked).[X] Commenters and viewersunder "People who can download, copy, and print" (UNCHECKED - Enforces Anti-Download/Print/Copy).
Click Done.
(Optional): Executive Board Portal (Google Sites Overlay)
If you prefer an executive dashboard layout rather than a standard folder list:
Go to
sites.google.comand create a blank site named Board Executive Portal.Embed the Board Minutes & Governance Shared Drive folder on the main page using Insert > Drive.
Click the Share with others (Person icon) at the top:
Draft Settings: Click the dropdown next to Draft and set to Restricted (or Remove Link) so domain users cannot modify the portal layout.
Published Settings: Set General Access to Restricted.
Add Members: Type
board-directors@yourdomain.co.keand assign the role of Published Viewer.
Click Publish. Directors will access all meeting materials directly through the portal URL.
Phase 3: Day-to-Day Operations & Workflow
Step 4: Publishing New Reports and Minutes
Upload the meeting report or minutes directly into the Board Minutes & Governance Shared Drive.
To notify directors, right-click the file or folder, click Share, and enter
board-directors@yourdomain.co.ke.Keep "Notify people" checked, add a message (e.g., "Q3 Financial Reports and Meeting Minutes are available for review"), and click Send.
Directors receive an email with a direct secure link - zero heavy attachments hit their inboxes.
Step 5: Executive Director Viewing Experience
The director clicks the document link in their email inbox.
They sign in using their personal email account credentials.
The file opens in their browser in View-Only mode:
File download buttons are hidden/disabled.
Printing functions are blocked.
Text selection and copying (
Ctrl+C) are disabled.
Step 6: Instant 1-Click Offboarding
When a director's term ends, go to Admin Console > Directory > Groups > Board Directors > Members.
Remove their personal email address from the group.
Result: Their access to the Google Site, the Shared Drive, and all current, historical, and future board files is revoked immediately across all devices.
Summary of Benefits
No Extra Costs: Uses capabilities already active in your Google Workspace license stack.
No Inbox Clutter: Files remain centrally hosted in your secure cloud.
Complete Data Control: Prevents local saving, forwarding, or printing of sensitive board materials.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article