Check what one person has shared outside the company
One request lists the files somebody has shared beyond the organisation. It is the question to ask when an account has been compromised or somebody is leaving.
Asking what somebody has shared externally lists the files reachable by people outside the organisation. Nothing is changed by asking.
Two situations make this urgent: an account that may have been compromised, and somebody leaving on bad terms. In both, what left matters more than what was deleted.
A separate question covers what happened recently across the client, which is the one to ask when you do not yet know whose account is involved.
Before you begin
Have the person’s email address.
Know which question you are asking. What one person has shared, and what sharing happened across the client recently, are different requests with different answers.
Ask Avvi
- Open chat and check the client.
- Ask what the person has shared externally. For example: what has jane@example.com shared outside the company?
- Read the list.
- To see recent sharing activity across the client instead, ask for the sharing audit for the period.
Avvi returns the externally reachable files it can see for that person.
Good to know
External sharing is not the same as a file being sent. A shared link can be forwarded to anybody, so the list is about reachability rather than about who has actually opened something.
The client-wide sharing audit answers who shared what and with whom, and reaches back seven days at most whatever period you ask for. Its default is the last day.
Verify it worked
Compare the list against what the person’s role would explain. A designer sharing artwork externally is normal; a finance account sharing spreadsheets is not.
For a compromise, remember the audit cannot reach further back than seven days. An intrusion older than that cannot be answered this way, and an empty result is not evidence of nothing.
If something doesn’t look right
If the list is empty for somebody you expect to share regularly, confirm the client and the person, and consider that they may share through a team site rather than their own files.
If a client-wide audit returns nothing on its first run, wait rather than concluding. Collection may have started only moments before.
If a file appears that should not be shared, stopping the sharing is a separate request.
If you need who opened something rather than what is reachable, that is beyond what this list covers.
To escalate, open a support conversation from the Help drawer with the client, the person and the period.
FAQ
Q: Does asking change anything?
A: Not for the person. The first client-wide audit may switch on audit collection for that tenant.
Q: Does this show who opened the files?
A: No. It shows what is reachable from outside.
Q: How do I stop one of them?
A: Removing a share is a separate request and has its own page.