How to Audit Who Has Access to Your Files
A practical, one-afternoon method for finding out who can open what: list the places, list the people, compare against need, fix, and record what you did.
An access audit answers one question: for each place your records live, who can open them today, and should they? You do it by listing the places, listing the people and links that can reach each one, comparing that against who actually needs access, and fixing the gap. Most small organisations can do a first pass in an afternoon, and it almost always turns up something uncomfortable.
Step 1: list every place records live
Not just the obvious system. Write down every location where client, staff or case material sits:
- The main records or case system
- Shared drives and cloud folders, including the ones "just for scanning"
- Shared mailboxes and personal inboxes used for work
- Messaging apps where files get sent
- Laptops, phones and USB drives
- Paper: cabinets, archive boxes, off-site storage
If you cannot list them, that is your first finding. Material in places nobody tracks cannot be audited, retained or deleted properly.
Step 2: list who can reach each place
For each location, pull the actual permission list rather than relying on memory. Include:
- Named users and what they can do (view, edit, share, delete)
- Groups, and who is in them now; groups quietly grow
- Shared links, especially "anyone with the link" links with no expiry
- External people: clients, contractors, former partners
- Service accounts and integrations that can read everything
- Administrators, who can usually see all of it
Step 3: compare against need
Build a simple table with one row per person and one column per location, and mark each cell "needs" or "does not need". The usual findings:
- Leavers still active. Someone who left months ago still has an account, or their personal email is still on a shared folder.
- Everyone sees everything. One big shared folder where the junior assistant can open HR files and the finance lead can open client evidence.
- Old links still live. A link sent to a client two years ago still opens the whole folder.
- Too many admins. Five people with full rights when two would do.
The principle is least privilege: access follows the matter and the role, not seniority or convenience. We go deeper on this in insider risk and access control for small teams.
Step 4: fix, starting with the worst
Remove leavers first, then expire open links, then narrow broad folders. Where a folder mixes material with different audiences, split it; permissions are only as fine as the containers they attach to. This is the practical case for organising records per matter rather than per department: when each matter is its own container, you can grant access to that matter alone. Document access rules for remote teams covers how to set the rules going forward.
Step 5: check what was actually opened
Permissions tell you who could look. Access logs tell you who did. If your systems record views and downloads, filter the last few months for unexpected patterns: someone opening files outside their work, bulk downloads before a resignation, a shared link opened from somewhere unexpected.
Step 6: record the audit and repeat it
Write down the date, what you checked, what you found and what you changed. That note is what you show a client, insurer or regulator who asks how you control access. Then put the next audit in the calendar: quarterly for sensitive material, at least annually for the rest, and always when someone leaves. The handover side of departures is covered in how to hand over a case when someone leaves.