Skip to content
FRP-128 Fraud & Financial Crime

Could changing sharing permissions alert other users?

Yes. Changing cloud-sharing permissions may alert owners, collaborators, administrators or linked services.

Avoid this assumption: Removing access is a quiet containment step. Providers may send email, push or in-app notifications and create audit events.

The change may also remove a user’s access, alter shared links, stop synchronisation or cause them to react elsewhere.

Before changing permissions, preserve the file or folder name, path, owner, current collaborators, roles, link settings, organisation, timestamps and visible identifiers.

Capture the complete sharing screen before selecting any user or option.

Identify the actual risk. Is there ongoing deletion, unauthorised access, disclosure, fraud or safeguarding harm?

Consider whether provider preservation or specialist support should occur before the change.

Use the narrowest effective action. Removing one collaborator may be more proportionate than disabling every link or changing ownership.

Do not assume an unfamiliar collaborator is malicious. It may be a former employee, service account, group, contractor or automated integration.

If permissions are changed, record who authorised the action, who performed it, the exact time and the original and new access levels.

Capture every warning, confirmation, notification setting and audit reference.

Record any effect on current sessions, shared links, synchronised devices or visible content.

Record whether the permission is direct, inherited, group-based or supplied through a public link, because changing one route may leave another route active.

Record any remaining route.

Operational takeaway

Preserve the full sharing state before changing permissions, because the action may alert users, terminate access and rewrite the cloud audit trail.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.