Skip to content
FRP-129 Fraud & Financial Crime

What should be preserved from cloud-sharing settings?

Cloud-sharing settings can show who may access material, through what route and with what level of control.

Avoid this assumption: Recording the visible names is enough. Access may be granted through individuals, groups, organisations, public links, service accounts or inherited permissions.

Record the service, account, tenant, file or folder name, path, owner and provider-generated ID.

Capture every visible person, group, email address, account, role and permission level.

Record whether access is view-only, comment, edit, download, share, administer or own.

Preserve link-sharing settings, expiry dates, passwords, domain restrictions, invitation status and whether anonymous access is allowed.

Note whether permissions are direct, inherited from a parent folder or supplied through a group.

Capture any pending invitations, external-user warnings, disabled accounts or removed-user entries.

Do not expand, alter or test permissions merely to clarify what they do.

Record the whole sharing page first, then closer details.

If scrolling is necessary, preserve the starting position and the order in which entries appear.

Do not assume that having access proves a person viewed or changed the content. Sharing settings show capability, not necessarily activity.

Where attribution matters, provider audit records and other evidence will be required.

Preserve whether access is internal, external, anonymous, inherited or time-limited. Record any owner-transfer, download restriction or resharing option already visible.

Record the order shown and any warning attached to an external or public entry.

Operational takeaway

Preserve owners, users, groups, roles, links and inherited permissions exactly as shown, while keeping access capability separate from proof of actual use.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.