Google Drive's sharing model is the best free one ever built. That's the problem. It's so good at the easy ninety percent — anyone with the link, viewer or editor, share with a group — that teams don't notice the missing ten percent until a contractor still has access to a folder eighteen months after the engagement ended, or a client asks who opened the pricing deck and nobody can answer.
This post is about that ten percent: what Drive's permission model genuinely doesn't do, when it starts to matter, and what the alternatives actually offer.
TL;DR: Drive handles internal collaboration well. It gets thin at external sharing — no native password on a link, expiry tied to paid work accounts and shared drives, and per-file access history that effectively lives in admin-console reporting on higher editions rather than on the file itself. If those three gaps describe your week, NevTan Drive includes all three on every account, free ones included. Nextcloud and Box are the other serious answers, for different reasons.
First: are you sure you have a permissions problem?
Plenty of teams blame the tool for a process gap. Run these four checks before you shop.
Can you answer "who has access to this file right now?" in under a minute? Not who you shared it with — who can open it today, including anyone who got the link forwarded.
Does access to anything expire on its own? If every revocation depends on someone remembering, you don't have access control, you have good intentions.
Can you prove who opened a specific file last quarter? Not whether it's technically logged somewhere — whether the person who needs the answer can get it without filing a ticket.
Can you share something externally that recipients can view but not download? And is that enforced, or just a setting that discourages it?
Two or more failures means the tool is the constraint. One failure is usually a training issue, and switching platforms won't fix it. If you want a structured version of this, the sharing and permissions documentation walks through what each control is actually for.
Where Google Drive's model gets thin
To be fair about what's genuinely good first: role inheritance down a folder tree, group-based sharing through Google Groups, and domain-restricted sharing are all solid, and the Workspace admin console gives large orgs real levers — DLP rules, trust rules between domains, target audiences. For internal collaboration among people who all have accounts, it's hard to beat.
The strain shows at the boundary of your organization.
No native password on a share link. As of Google's published documentation in late 2026, protecting a Drive link with a password isn't a built-in option — the access decision is the link itself plus whatever account restrictions you've set. Marketplace add-ons and workarounds exist; none is a first-party control. For an NDA'd document going to a counterparty, "whoever holds this URL" is a weaker gate than most legal teams assume it is.
Expiry is conditional. Google has expanded access expiration meaningfully, including expiry on shared-drive items and on the Viewer role for folders, but it's tied to paid Workspace editions — Business, Enterprise, Education, Nonprofit and Frontline per Google's own announcements — and not something a personal account gets. If half your team is on a free account, expiry isn't in your workflow. Check Google's current plan comparison before you take my word for the edition boundaries; this one moves.
Access history lives in the admin console, on higher editions. Drive has version history for everyone, which tells you what changed. That isn't the same as an access log, which tells you who opened it and when. Detailed Drive audit reporting sits in admin reporting on upper editions — which means the person who needs the answer during a client audit is usually not the person who can run the report.
Viewer still means downloader by default. You can disable download, print and copy for viewers and commenters, and it works, but it's a per-file toggle people forget. The default is permissive.
None of this makes Drive a bad product. It makes it a product optimized for a company where everyone has an account on the same domain — which is exactly what Google is.
The alternatives, and who each one is for
NevTan Drive — when the controls shouldn't be a tier
The design decision here is simple: password-protected links, expiring links, Viewer/Commenter/Editor roles, and a per-file audit log are on every account including free ones. A paid plan adds storage and nothing else.
That matters more than it sounds. The common failure mode isn't that a company can't afford the enterprise edition — it's that the three people who most need link expiry are the contractor, the freelance designer and the client, none of whom are on your plan. When the control is universal, it's actually used.
The audit log sits on the file rather than in an admin console, so the account manager answering a client's question looks at the file and sees every share, permission change and access event. The editors are the other half of it: PDFs, documents, spreadsheets and presentations edit in the browser and save back in their original format, so a protected file never has to leave the controlled environment to be worked on. When it's ready for signature it hands off to NevTan Sign without a download in between, and Drive shares one storage pool with NevTan Mail rather than metering separately.
Honest trade-off: it's a younger product than Workspace, with a smaller third-party integration ecosystem. If your workflows depend on a long tail of Marketplace apps, test that first. Side-by-side against Google Drive.
Nextcloud — when the files must stay on your hardware
Self-hosted, open source, and the permission model is the most granular of anything here: per-share passwords, expiry, upload-only drop folders, file access control rules by group, device or time. If you're in a jurisdiction or sector that requires data residency you control, this is the honest answer.
Trade-off: you're now running infrastructure. Upgrades, backups, scaling and performance tuning are yours. Teams routinely underestimate this and end up with an unpatched server, which is a worse security posture than the SaaS they left. Comparison here.
Box — when compliance is the purchase
Box has spent fifteen years selling to regulated industries and it shows: governance, retention policies, legal hold, classification labels, and granular external-collaboration controls. If your buying committee includes a compliance officer with a checklist, Box answers most of it out of the box.
Trade-off: priced accordingly, and the editing story is thinner than its storage story.
Dropbox — when the sync client is the point
Nothing beats Dropbox's desktop sync for reliability, and that's a real requirement for teams moving large media files. Password-protected and expiring links exist but have historically sat on the business tiers rather than the entry plans, so check which plan you'd actually be on. Comparison here.
Microsoft OneDrive — when you're already paying for 365
Password and expiry on links are included, and the Entra ID integration gives you conditional access policies that are genuinely strong. Trade-off: it's a component of a suite, not a standalone product, and mailbox storage is metered separately from file storage. Comparison here.
A short evaluation script
Don't demo. Run your own documents through each candidate for an afternoon:
Share a file externally with a password and a seven-day expiry. Note how many steps, and whether it's available on the plan you'd actually buy.
Share the same file view-only and try to download it from the recipient side.
Open the file's access history and find out who viewed it. Time how long that takes, and note whether a non-admin could do it.
Remove one person's access and confirm the link they were sent is now dead.
Edit the file in place — a PDF, a spreadsheet — and confirm it saved back in its original format without a download round trip.
Step 3 eliminates more products than the other four combined.
Choosing
Mostly internal collaboration, everyone on one domain, no external sharing of sensitive material? Stay on Google Drive. It's genuinely good at that and switching costs you more than you'll gain.
Sharing regularly with clients, contractors or counterparties who aren't on your plan? The gaps are real, and you want password, expiry and per-file access history to be universal rather than conditional on edition — which is the case NevTan Drive is built around.
Hard data-residency requirement and an ops team? Nextcloud. Compliance officer on the buying committee? Box. Large media files over a desktop sync client? Dropbox. Already deep in Microsoft 365? OneDrive, and don't overthink it.
Try the controls, not the pitch
Everything described above — password-protected links, expiry, Viewer/Commenter/Editor roles, and a per-file audit log — is on the free NevTan Drive account. Nothing in this list is a tier.
Upload one real document, share it with a password and a seven-day expiry, open the log, and see whether it answers the question you'd actually be asked.
Create your free account · See all features · Compare every option




