What should be preserved from cloud-sharing settings?¶
Record every owner, user, group, link and inherited permission with its role, scope, restrictions and provider identifiers.
Map capability accurately¶
Capture service, tenant, object ID, path and owner. Preserve view, comment, edit, download, share, administer and ownership roles plus invitations, expiry, passwords, domains and anonymous access.
Distinguish direct, inherited, group and public-link routes. Record external warnings, disabled accounts and resharing controls.
Do not test permissions¶
Capture the whole page and order before scrolling. Do not expand or alter entries merely to clarify them.
Sharing shows capability, not actual access or editing. Provider audit records are needed for activity and personal attribution.
Key takeaway
Preserve the full sharing topology while keeping technical access capability separate from evidence that the access was used.