What Drive Management does
Drive Management gives administrators a single place in Automate to see and manage the shared drives across their domain, browse the files inside them, and view an individual user's My Drive, without leaving Automate or signing in as the user.
It covers three areas:
- Shared Drives: an inventory of every shared drive in your domain, with settings, membership and drive-level actions.
- Files: browse and act on the files inside a shared drive.
- Users' My Drive: view an individual user's Drive content from their record in Directory.
Before you start
Three things need to be in place before Drive Management can be used.
1. CloudM Labs
A request needs to be submitted via CloudM Labs, which will need approving by CloudM. The this will allow you to switch on Settings > CloudM Labs > Drive Management for your domain.
2. Configure a domain-wide delegation service account
Drive Management uses a service account from your own Google Cloud project, rather than the default shared one. This gives it access to scopes that cannot be added to the default setup, and keeps the Drive API work for your domain in your own project.
Go to Settings > Domain Settings > Domain Wide Delegation, upload your service account, and run validation with the Drive Management option selected.
In the Google Admin console, the service account's client ID needs both of these scopes delegated to it:
https://www.googleapis.com/auth/drive,
https://www.googleapis.com/auth/cloud-identity.orgunitsThe Cloud Identity API also needs to be enabled in the Google Cloud project that hosts the service account.
Both scopes are required, and there is no fallback. The cloud-identity.orgunits scope is what allows a shared drive to be created or moved between organisational units. If it is missing, those two actions fail straight away rather than falling back to the default service account.
Credentials are cached, so after changing the service account or its scopes, allow a few minutes before testing.
3. Turn on shared drive sync
Enable Automatic Shared Drive Sync under Settings > Domain Settings > Domain Actions.
How syncing works
Shared drives are synchronised into Automate as part of your existing domain sync, under Settings > Domain Settings > Domain synchronisation, alongside users, groups and organisational units. Sync collects shared drive information such as name, organisational unit, and members and permissions.
The sync is one way. It reads information from Google Workspace and stores it in CloudM. Changes you make through CloudM are sent directly to Google as separate actions, rather than waiting for a sync.
There are two independent syncs:
| Sync | How often | What it updates |
|---|---|---|
| Domain Sync | Roughly every 48 hours | Users, groups, organisational units, and basic shared drive information such as name and image. |
| Per-Drive Details Sync | Roughly every 5 days per drive | Members, file count and public link count for that drive. |
When Domain Sync finds a new drive, its first details sync is normally picked up within about 20 minutes.
Manual Sync starts the Per-Drive Details Sync for one drive without waiting for its next scheduled run. A small drive usually finishes within seconds; larger drives, or busy periods when many drives are syncing, can take longer. With Automatic Shared Drive Sync enabled, your basic drive information and membership should already be current, so Manual Sync is mainly useful for refreshing file and public link counts sooner.
Three things that sound similar but do different jobs:
Refresh asks for the latest data already stored in CloudM. It does not contact Google Workspace.
Sync pulls data from Google Workspace into CloudM. It does not send CloudM data to Google.
Actions, such as creating, renaming or updating a drive, are sent straight from CloudM to Google Workspace as separate operations.
Shared drive sync only runs when a feature that needs it is switched on, so there is no additional load on domains that are not using Drive Management.
Shared Drives
A new Drive Management group appears in the Automate sidebar once the module has been enabled for your domain, containing a Shared Drives page that lists every shared drive in your domain.
- Search and filter by drive name, sync status and more.
- Configurable columns, so you choose what you see.
- Unmanaged shared drives alert, highlighting drives without a manager, with a one click filter to see just those.
- Sorting and pagination across the full list.
Shared drives with no manager are flagged. To review them, use More filters > Managers > Unmanaged.
Columns
Every column is configurable except the drive name, which is always shown.
- Drive name, always shown
- Managers
- Members
- Org unit
- Files
- Public links
- Size
- Sync status
- Created date
Searching, filtering and sorting
- Search by shared drive name.
- Filter by organisational unit and sync status.
- More filters for members, managers and permissions.
- Sort by drive name, members, managers, files or size.
- Results per page, choosing 10, 20 or 50 entries.
Actions on the Shared Drives page
Refresh asks for the latest data already held in CloudM, so it is quick and does not contact Google.
The Create a shared drive button creates a new drive and sets its initial permissions. At least one user or group manager is required.
Selecting more than one drive lets you apply an action across all of them. Tick the drives you want and choose from update drive settings, add member, update org unit, or delete. Deselect all clears your selection.
Select the ellipsis menu on any row for that drive's actions:
- View Drive opens the drive's details page in Automate.
- Go to Drive opens the drive in Google Drive.
- Sync Now runs the Per-Drive Details Sync for that drive.
- Update drive settings, where sharing and access policies for that drive are set with Enabled and Disabled toggles.
- Update org unit, to move the drive into a different organisational unit.
- Manage members and roles, to update a member's role on the drive.
- Rename the drive.
- Delete the drive.
Viewing a shared drive
Selecting any column after the drive name opens a summary page for that drive, with three tabs:
- Overview, the drive's details.
- Security & policies, showing the organisational unit and the access settings for the drive.
- Members, where you can manage members and update a member's role.
Two further actions are available from this page: View Drive details takes you to that drive inside Automate, and Open shared drive opens it, with its content, in Google Drive.
Inside a shared drive
Select View Drive, or the drive name itself, to open the drive. The details page shows the drive's statistics and actions in the header, with folder and file browsing beneath.
Update drive settings is available as a button. The remaining actions are in the dropdown:
- Go to Drive opens the drive in Google Drive.
- Sync Now runs the Per-Drive Details Sync for that drive.
- Update org unit, to move the drive into a different organisational unit.
- Manage members and roles, to update a member's role on the drive.
- Export Drive exports the current columns and data.
- Rename the drive.
- Delete the drive.
Folders and files
Navigate folders using the breadcrumbs, scrolling continuously through large drives. You can search, filter and sort, and choose which columns to show. The Bin is available from every screen, so you can see what has been moved there.
Select the ellipsis menu on a folder for:
- Manage access for the folder
- Rename the folder
- Move the folder
- Copy link for the folder
- Move to bin
Select the ellipsis menu on a file for the same five actions, applied to the file.
Clicking a folder or file row opens its details panel, showing sharing settings and members, with permissions editable in place.
File information is read live from Google each time you browse. Nothing is copied into Automate, so what you see always reflects Google Drive at that moment.
Changes you make to shared drives and their permissions are recorded in your audit log.
Viewing a user's My Drive
A new My Drive tab has been added to Directory > Users. Open a user's record and select the My Drive tab to see their Drive content.
The page shows:
- The user's files, and how much storage they are using
- Folders and files shared with the user
- The Bin
- Total storage used
- Refresh, which asks for the latest data already held in CloudM rather than contacting Google
More actions and Edit user on this screen apply to the user record itself, not to My Drive.
Searching and filtering My Drive
Search by name, and choose the scope you are searching within:
- This folder shows only the items directly inside the folder you are viewing.
- All files shows a flattened view of files across the whole Drive, including files inside nested subfolders.
Any search or filter you apply uses the scope you have selected, either the current folder or the whole Drive.
- More filters for file type, link access, and modified or created date.
- Sort by name, modified, managers, created or size.
- Results per page, choosing 10, 20 or 50 entries.
My Drive columns
Every column is configurable except the name, which is always shown.
- Name, always shown
- Type
- Size
- Owner
- Sharing
- Last modified by
- Modified
- Created
Actions in My Drive
Select the ellipsis menu on a folder for:
- Manage access for the folder
- Rename the folder
- Move the folder
- Copy link for the folder
- Move to bin
Select the ellipsis menu on a file for the same actions, plus:
- Transfer ownership of the file to another user
Ownership transfer applies to individual files only. Google does not support transferring ownership of a folder along with its contents, so it is not offered for folders.
It also applies to My Drive only. Content in a shared drive has no individual owner because the organisation owns it, so ownership cannot be transferred there.
Things to be aware of
- Activity History appears in the drive actions menu and is reserved for a future release.
- File and public link counts refresh on the five day per-drive cycle. If you need current figures sooner, use Sync Now on that drive.
- Acting on several drives at once is done by selecting them in the list. Recommended actions that find every drive matching a condition are planned for a later release.