π Lesson 5.1: Sharing & Permissions
This is the moment Google Docs becomes something a typewriter, or even a desktop word processor, never could be: a document more than one person can hold at once. In this lesson you'll learn to share your work deliberately β with the right people, at the right level of access β and to review, tighten, and take back that access whenever you need to. Sharing is Docs' superpower, and doing it thoughtfully is what keeps it a superpower rather than a surprise.
π What You'll Learn
By the end of this lesson, you will be able to:
- Explain why real-time co-editing is the thing Google Docs does better than a traditional word processor
- Share a document with specific people and choose the right role β Viewer, Commenter, or Editor
- Share via a link and understand honestly why "anyone with the link" is convenient but risky
- Use advanced controls where available β expiring access, restricting copy/download/print, and limiting who can add others
- Review who has access, change someone's role, revoke access, and transfer ownership
β±οΈ Estimated Time: 45 minutes
π― Project: Share your course document safely β invite a specific person as a Commenter, generate a view-only link, then review the access list and remove what you don't need.
In This Lesson
The Superpower: One Live Document, Many Hands
Think about how documents used to travel. You wrote something, attached it to an email, and
sent it off. The other person opened their copy, edited their copy, and emailed
it back. Now there were two versions. Add a third person and you had report_final.docx,
report_final_JAN.docx, and report_final_v3_USE_THIS.docx floating around
three inboxes, and someone had to merge them by hand. Anyone who has lived that knows the special
dread of realizing two people edited the same paragraph in two different copies.
Google Docs deletes that entire problem. There is one document, living in the cloud, and everyone you share it with opens the same one. When your teammate types, you see their words appear. You see their cursor β a little colored bar with their name on it β moving through the text. Two, five, even dozens of people can read, comment, and write in the same document at the same moment, and it all just merges, live, with no "send" and no "merge" step at all. This is real-time co-editing, and it is the single biggest reason people reach for Docs.
A traditional desktop word processor is fundamentally a single-player tool with sharing bolted on afterward β you save a file, then figure out how to get it to someone. Docs is multiplayer by design: the document is a shared, always-current place rather than a file you pass around. That inversion is why a shared Doc so often replaces a messy email thread, and it's the whole reason Module 5 exists.
π§ Mindset
Stop picturing a document as a file you send and start picturing it as a room you invite people into. When you share a Doc, you're not mailing a copy β you're handing someone a key to the same room you're standing in. That mental shift makes every decision in this lesson obvious: who gets a key, what they're allowed to do inside, and how easily you can change the locks. Once you think in rooms and keys, sharing stops feeling risky and starts feeling deliberate.
Because it's a room and not a copy, sharing well is mostly about being intentional. The rest of this lesson is the practical craft of that: who you let in, what they can do, and how to check and change it later. We'll cover the conversations that happen inside a shared doc β comments and Suggesting mode β in Lesson 5.2. This lesson is about the door.
Sharing Options: People, Links & Roles
Every share you'll ever do is a combination of two questions: who can get in,
and what they can do once they're in. Google puts both in one place β the blue
Share button in the top-right of any document. Click it and the sharing dialog opens.
Everything below happens in that one panel.
Who: specific people vs "anyone with the link"
There are two fundamentally different ways to let someone in, and understanding the difference is the most important safety idea in this lesson.
- Share with specific people. You type email addresses into the
Add people and groupsfield. Only those exact accounts get access, and they usually have to sign in to prove they're that person. This is the named guest list β precise, revocable, and by far the safer default. - Share via a link β "anyone with the link". Under
General accessyou can switch fromRestrictedtoAnyone with the link. Now anyone who has the URL can open the document, no sign-in required. This is the open door with a sign that only some people can read β wonderfully convenient, and exactly as risky as it sounds.
What: the three roles
Whichever way you let people in, you assign them a role β the level of power they have inside the document. There are three, and they form a ladder from least to most capability.
| Role | Can do | Cannot do | Reach for it when⦠|
|---|---|---|---|
| ποΈ Viewer | Read the document; see its current contents | Change text, add comments, or leave suggestions | You're sharing finished work for reading only β a policy, a flyer, a read-me |
| π¬ Commenter | Read and add comments and suggestions | Directly change the text of the document | You want feedback but you keep control of the actual wording β reviews, drafts |
| βοΈ Editor | Read, comment, and freely change the content | Delete the doc (only the owner can) β and, if the owner switches that option off, re-share or change permissions (Editors can by default) | You're truly co-authoring β a shared plan, a team document, group notes |
π Definition
Least privilege: a simple security principle that says give each person the smallest amount of access that still lets them do their job β and no more. If someone only needs to read, they're a Viewer, not an Editor. If they only need to leave feedback, they're a Commenter. You can always raise someone's role in two clicks later; you can't as easily undo damage from access you handed out too generously. When in doubt, share lower and step up.
The honest security note
Here's the part a lot of tutorials skip. Sharing is genuinely safe when you're deliberate, and genuinely leaky when you're not. A few honest truths:
- A link can travel. "Anyone with the link" doesn't mean "anyone I sent the link to." If a recipient forwards the email, pastes the URL in a chat, or it ends up in a shared calendar invite, everyone downstream has the same access. The link doesn't know or care who's holding it.
- Prefer named people for anything sensitive. A specific-people share is tied to real accounts you can see and remove. That traceability is worth a small amount of extra friction.
- Match the role to the trust. An "anyone with the link" set to Editor means any stranger with the URL can rewrite your document. That's occasionally what you want; usually it isn't. Link sharing at Viewer is much lower-stakes.
β οΈ Important Note: "Anyone with the link" is not the same as "public on the
web." The document won't show up in Google search results just from link sharing β but anyone
who obtains the link can open it. Treat the link itself as the credential. If it leaks,
access leaks with it, and the only fix is to change General access back to
Restricted or generate the link fresh. We return to privacy and sensitive data
properly in Lesson 8.2.
Transferring ownership
By default, the person who created a document owns it. The owner is the ultimate
authority β they can't be removed by anyone else, they control sharing, and their Drive storage holds
the file. Sometimes ownership needs to move: you're handing a project off, or you're leaving a team.
In the share dialog you can open the role dropdown next to an existing Editor and, where the
option is available, choose Transfer ownership. The other person confirms, and now
they hold the master key while you drop to Editor.
β οΈ Watch Out
Ownership transfer is a bigger deal than it looks. Once you transfer, the new owner controls the document β they could remove you, and the file now counts against their storage, not yours. On a personal Google account you can generally only transfer to someone in a similar account type, and on a Google Workspace account, transfers may be limited to people inside your organization. It's a deliberate, occasional action, not something to do casually.
Advanced Controls (Availability Varies)
Beyond who and what, Google offers a handful of finer controls for higher-stakes sharing. An
honest heads-up first: the exact set of advanced options depends on your account type and
changes over time. Some are only on paid Google Workspace editions; some appear
for everyone; Google adds and moves them. So learn the concepts β when you'd want each one β
and you'll recognize the control wherever it lives in the dialog. To find them, open
Share and look for a settings gear or an Advanced/details area within the
panel.
Expiring access
Sometimes you want to let someone in for now but not forever β a contractor for the length of a project, a reviewer for a week. Where available, you can set an expiration date on a specific person's access. When the date passes, their access quietly ends and you don't have to remember to revoke it by hand. This feature is typically a Workspace one, and it usually applies to Commenter and Viewer roles rather than full Editors.
Restricting copy, download & print
By default, anyone who can read a document can also copy its text, download it as a file, or print it β which means the content can leave your control entirely. For Viewers and Commenters, you can often turn on a setting (worded something like "Viewers and commenters can see the option to download, print, and copy", which you switch off) to remove those options. Be honest with yourself about what this does and doesn't do:
β οΈ Watch Out
Disabling download, copy, and print raises the friction, but it is not real security. A determined reader can still retype the words, take a screenshot, or photograph the screen. Treat these controls as a "please don't" fence, not a vault. For genuinely confidential material, the real protections are not sharing it with people you don't trust and using named, revocable access β not a checkbox.
Who can add others
By default, Editors can re-share a document and change its permissions β which means access can spread beyond the people you personally invited. For tighter control, look for a setting like "Editors can change permissions and share" and switch it off. Now only the owner controls the guest list, and Editors can edit content but not hand out keys. This is a small toggle with a big effect on how far a document travels.
π‘ A useful default for sensitive docs
When a document matters, a good, cautious baseline is: specific people only, each at the lowest role that works, with "Editors can change permissions" turned off, and β for reviewers β download/copy/print off and an expiration date if your account supports it. You can always loosen any of these in seconds; you can't un-leak a document that already spread.
Reviewing & Revoking Access
Sharing isn't a one-time action β it's a list you maintain. Documents outlive projects, people leave teams, and a link you generated for one purpose lingers. Making a habit of reviewing who has access is as important as being careful when you first share.
See who has access
Open the Share dialog on any document you own or can manage. Under
People with access you'll see the full guest list β every named person, their email,
and their role β and under General access you'll see whether the link is
Restricted or open to Anyone with the link. This one panel is your
complete picture of who can get in and what they can do. Reading it top to bottom is a 20-second
audit worth doing periodically on anything important.
Change someone's role
Next to each person's name is a role dropdown. Open it and pick a new role β bump a Commenter up to Editor because they've joined the writing, or drop an Editor to Viewer because the draft is finished. The change is instant; the next time that person loads the document, they have the new level of access.
Remove a person
In that same dropdown, choose Remove access (sometimes shown as
Remove). That person can no longer open the document at all. This is the direct,
surgical way to take back a single key β use it the moment someone no longer needs access.
Shut off the link
Removing named people does nothing about an open link. If General access is
set to Anyone with the link, that door is still open to anyone holding the URL,
regardless of your named list. To close it, switch General access back to Restricted.
Now only your named guest list works, and every stray copy of the link stops functioning.
β Pro Tip
When you're done collaborating on something sensitive, do a quick two-step
close-out: (1) set General access back to Restricted so no stray links
work, and (2) remove any named people who no longer need it. Thirty seconds now saves you the
unpleasant surprise of discovering months later that an old draft is still open to a link you
forgot about. Version history (Lesson 5.3) even lets you see who touched what, so nothing is
lost by tightening up.
then pick a role"] B -->|"A link"| D["Set anyone with the link
then pick a role"] C --> E["Assign role: Viewer or Commenter or Editor"] D --> E E --> F["π₯ Collaborators access the same live document"] F --> G["Owner reviews the list
changes roles or removes access anytime"]
Workspace vs Personal Account Differences
How much freedom you have to share depends heavily on which kind of Google account you're signed in with. This is one of the most common sources of "why can't I share this?" confusion, so it's worth understanding β though the specifics vary by organization, so treat this as the shape of things rather than a rulebook.
| Aspect | Personal Google account (free) | Google Workspace account (work / school) |
|---|---|---|
| Who sets the rules | You do β you control your own sharing | Your organization's admin sets policies you can't override |
| Sharing outside your domain | Freely, to any email address | May be restricted, warned about, or blocked by admin policy |
| "Anyone with the link" | Usually available | May be limited to your organization, or disabled entirely |
| Advanced controls (expiry, restrict copy) | Some available, some not | More available; some may be enforced for you |
| Ownership transfer | Limited to similar account types | Often limited to people inside your organization |
The practical takeaway: if you're on a work or school account and a sharing option is missing or a share is blocked, you probably haven't done anything wrong β an admin has set a policy. On a personal account, the choices are yours, which means the responsibility for sharing thoughtfully is yours too.
β οΈ Watch Out
Documents in a Google Workspace account you use at a job or school are generally owned by the organization, not by you personally, even if you created them. If you leave, you may lose access. Keep genuinely personal writing in a personal account, and keep work in the work one. Mixing them is how people lose documents they cared about.
Best Practices for Safe Sharing
β Do's
- Default to specific people. A named guest list is safer, traceable, and easy to revoke. Reach for links only when convenience genuinely outweighs the risk.
- Practice least privilege. Give the lowest role that does the job β Viewer for reading, Commenter for feedback, Editor only for true co-authors. Step people up later if needed.
- Audit access periodically. Open the Share dialog on important documents now and then, read the list, and remove anyone who no longer needs in.
- Close out finished projects. Set General access back to Restricted and remove stale collaborators when the work is done.
β Don'ts
- Don't set "anyone with the link" to Editor unless you truly mean "any stranger can rewrite this." That combination is behind a lot of vandalized documents.
- Don't treat download/copy/print restrictions as security. They're friction, not a vault; sensitive content shouldn't rely on them.
- Don't share sensitive data via a link and assume it stays with the recipient. Links travel; use named people.
- Don't transfer ownership casually. The new owner can remove you and the file leaves your storage. It's a deliberate hand-off, not a convenience.
π‘ Pro Tips
- Add a short note in the share dialog when you invite someone ("Draft for your feedback by Friday β you're a Commenter"). It sets expectations and reduces confusion about their role.
- Share to a group or mailing list when a whole team needs access β then adding or removing one person is managed in one place, not per document.
π― Project: Share a Document Safely
Time to do the real thing β deliberately, and with a clear picture of who can do what. You'll use the course document you've been building. If you'd rather practice on a throwaway, make a quick blank document first; sharing is completely non-destructive to learn, and you can revoke everything at the end.
ποΈ Share, then review and tighten
Objective: Share your document with one specific person as a Commenter, generate a view-only link, then review the access list and remove access you don't need β so you finish having done a full sharing life-cycle, not just clicked "Share".
Instructions (about 15 minutes):
- (2 min) Open your document and click the blue
Sharebutton in the top-right. - (3 min) In
Add people and groups, type the email of a real person you trust β a friend, family member, or a second account of your own. Set their role to Commenter. Add a short message like "Draft β would love your comments." Send it. - (3 min) Under
General access, switch fromRestrictedtoAnyone with the link, then set the link's role to Viewer. UseCopy linkand paste it somewhere just to see the URL β this is the "open door" style of sharing. - (3 min) Now review: read the
People with accesslist and note each person's role. This is your audit view. Confirm the named person is a Commenter and the link is Viewer, not Editor. - (2 min) Tighten up: switch
General accessback toRestrictedso the link no longer works, proving you can close a door you opened. - (2 min) Optional cleanup: on the named person's dropdown, choose
Remove accessto end the whole exercise, or leave them as a genuine reviewer if you actually want feedback.
π‘ Hint β a checklist to talk yourself through it
Sharing walk-through
WHO gets in?
- Specific person -> typed their email, set role = Commenter
- A link -> General access = Anyone with the link, role = Viewer
REVIEW (the audit)
- People with access: name + role each looks right
- General access line: is it Restricted or a link?
TIGHTEN
- General access -> back to Restricted (link stops working)
- Remove anyone who no longer needs access
Rule of thumb: lowest role that works, named people over links.
If a control you expected is missing, you may be on a work/school account with admin policies β that's normal. The concepts are the same wherever the buttons live.
β Project Completion Checklist
- You shared with a specific person and set them to Commenter (not Editor)
- You created an "anyone with the link" share and set it to Viewer
- You reviewed the full access list and could read each person's role
- You switched General access back to Restricted to close the link
- You know how to remove a named person's access in one step
π― Quick Quiz
Question 1: You want a colleague to give feedback on your draft without changing the actual wording. Which role should you give them?
Question 2: Why is "anyone with the link" riskier than sharing with specific people?
π Learning Journal
Keep a learning journal as you work through this course β a separate document, a note, or a page in the document you're building. After each lesson, take a few minutes to write down:
- Key concepts you learned
- Techniques that clicked for you
- Questions or confusion points to revisit
- Ideas you want to try in your own documents
- Your progress and feelings about learning this β including where your confidence grew
βοΈ This lesson's prompt: Think of a document you'd genuinely want to share with someone β for feedback, for reading, or to co-write. Who would you invite, and at which role? Would you use named people or a link, and why? Write down one moment from your own life where a shared Google Doc would have replaced a messy email thread β and note your honest comfort level with sharing: excited, cautious, both?
π Lesson Summary
π Key Takeaways
- Real-time co-editing is Docs' superpower: one live document many people hold at once, replacing emailed copies and manual merges. Think "a room you invite people into," not "a file you send."
- Every share answers two questions: who gets in (specific people vs anyone with the link) and what they can do (Viewer, Commenter, Editor).
- Practice least privilege β the lowest role that works β and prefer named people to links for anything sensitive, because a link can travel.
- Advanced controls (expiring access, restricting copy/download/print, limiting who can re-share) add caution but aren't foolproof security; availability varies by account.
- Sharing is a list you maintain: review the access panel, change roles, remove people, and switch General access back to Restricted to close a link.
π What You've Accomplished
You've turned "Share" from a mystery button into a deliberate skill. You can invite the right people at the right role, generate a link when it's warranted, honestly weigh the trade-offs, and β just as importantly β review and take back access whenever you need to. That's the whole life-cycle of a shared document, and it's the foundation for everything else collaboration can do.
β Common Questions at This Stage
If I remove someone, can they still see the version they already read?
They lose access to the live document immediately, and they can't reopen it. However, if they had download/copy/print enabled and already saved or copied the content, that copy is theirs β which is exactly why sensitive material shouldn't rely on read-only restrictions. Revoking access stops future access; it can't reach back and un-copy what already left.
Does the person I share with need a Google account?
For specific-people sharing, they generally need to sign in to a Google account matching the email you invited, which is what makes access traceable and revocable. With "anyone with the link," a sign-in often isn't required β part of why that method is more convenient but less controlled. Details vary by account type and Google's current settings.
What's the difference between sharing and just sending a copy?
Sharing gives access to the one live document β everyone sees the same current
version. Sending a copy (via File > Make a copy or an email attachment) creates a
separate document that no longer stays in sync. Use sharing for collaboration; use a copy
when you deliberately want someone to have their own independent version.
π Looking Ahead
In the next lesson β Lesson 5.2: Comments, Suggesting Mode & Real-Time Co-Editing β we go inside the shared room. Now that people can get in, you'll learn the conversations that happen there: leaving comments and @-mentioning teammates, proposing changes in Suggesting mode that the author can accept or reject, and the etiquette of writing alongside others without stepping on their work.
β Before the Next Lesson
- Successfully share and then un-share a practice document, so the whole cycle feels routine
- Decide on the real person (or second account) you'll collaborate with in the next lesson
- Write your Learning Journal entry for this lesson
π Additional Resources
- Google Docs Help Center (Google Support)
- Share files from Google Drive (Google Support)
- Google Docs on Google Workspace β overview
π Encouragement for the Journey
You just unlocked the thing that makes Docs special β and you did it the careful way, thinking about keys and rooms instead of clicking blindly. Deliberate sharing is a genuine professional skill, and you now have it. Next, we step through the door and learn to collaborate inside the room. π€