What should I preserve before changing cloud permissions or sharing settings?¶
Before changing cloud permissions or sharing settings, preserve the current access state and the records showing how it was created.
Evidential caution: that tightening access has no evidential effect.
What this means¶
Changing permissions may remove visible recipients, invalidate links, end sessions, trigger notifications or create new audit events.
Where urgent harm requires immediate restriction, document why action took priority over full preservation.
Also consider whether another administrator, owner or linked service can restore access.
After the change, record the exact control used, time, account and observed effect.
Where urgent restriction is required, consider whether a temporary block, link disablement or account suspension preserves more evidence than immediate deletion of the permission structure.
Also identify whether access was granted through a group, role or inherited folder permission, because removing one visible entry may leave the underlying route active.
What to check or do next¶
- Start by recording the resource ID, owner, current permissions, external users, groups, link settings, expiry, download rights and any inherited access.
- Preserve screenshots and structured exports where available.
- Check the audit history for who created or changed the sharing and when.
- Record whether access is direct, group-based, inherited from a folder or granted through an application.
Evidential limits¶
Do not assume that removing permission deletes copies already downloaded or synchronised.
Where access is inherited through groups or folders, record the full permission chain. Removing one visible user may not remove the underlying route that granted access.
Operational takeaway
Preserve the pre-change sharing state and audit history before restricting access, and document the effect because permission changes can alter both the live environment and the evidence.