Who touched what across all property Drives, in real time. Drive Activity API push → audit log. Spot stale templates, surface naming-rule violations, catch unintended share-outs before owner data leaves the org.
Peaks 9–12 + 2–4 PM · normal pattern · no anomalies
Pre-approved external sharing only to: AGF (legal), Carr Riggs & Ingram (CPA), Sterling Insurance, Reserve Advisors, KONE, current contracted vendors. Anything else → manager review.
"Owner Roster," "Bank Recs," "Tax Returns," "Personnel," "Records Requests" cannot be link-shared even by managers. Hard block at the policy layer.
External shares default to 30-day auto-expire unless extended. Email reminder to grantor 3 days before expiry. Stops the "still shared with the previous CPA in 2019" leak.
Mass file access patterns flagged: e.g., one user pulling 200 files in 5 minutes, downloads spiking outside business hours, access from new IP/location. Sends to ops director.
Property files require YYYY-MM-DD descriptive name.ext per Ops Manual §IV. Validator flags violations in real-time. 14 currently flagged for cleanup.
Files like "untitled," "copy of," "FINAL_v3" age into a "review queue." Managers triage in monthly cleanup pass — the Drive doesn't bloat to unsearchable.
| Property | Files | Activity 7d | External shares | Naming fails | Stale templates | Health |
|---|---|---|---|---|---|---|
| Plaza Tower | 18,420 | 284 | 4 | 2 | 11 | healthy |
| Plaza Tower (Staff) | 2,840 | 62 | 0 | 0 | 3 | healthy |
| TCC Front Desk | 1,420 | 38 | 0 | 0 | 1 | healthy |
| Centerville Square | 4,820 | 54 | 1 | 0 | 4 | healthy |
| Lakes at Killearn | 3,940 | 22 | 2 | 1 | 9 | watch |
| Magnolia Grove | 2,180 | 14 | 0 | 4 | 18 | cleanup needed |
| Other 64 drives | 108,240 | — | — | 7 | — | — |
The forensics scramble after "did anyone share this externally?" Quarterly Drive audits that take 6 hours. The "we lost the file" panic resolved only by combing the trash. Files inadvertently still shared with consultants from 2018.
Google Drive Activity API push notifications · Cloudflare Access SSO identity · Ops Manual §IV.3 Naming Conventions + Records Discipline.