File-sharing controls govern how documents move — who can share what, with whom, through which channels, and for how long. For employers the subject is really about one recurring event: workforce data leaving the system of record as a file, at which point every permission model behind it stops applying.
A payroll register inside the payroll platform is protected by roles, logging, and authentication. The same register exported and shared is protected by nothing except where the file happens to land.
Modern collaboration platforms make sharing effortless, and the effortless option is usually the broad one: "anyone with the link." A link created for one recipient works for every recipient — forwarded, pasted into a chat, sitting in an inbox indefinitely.
Most organizations have years of these links outstanding and no inventory of them. Each one attached to a file containing employee data is a small standing breach waiting for an audience.
The single highest-value configuration change available: set the default share to named people inside the organization, and make link-sharing an explicit choice with an expiry. Defaults do the work that policy reminders cannot.
Controls on the sanctioned platform only matter if the sanctioned platform is where sharing happens. The bypass channels are familiar:
The practical rule that addresses most of it: sensitive workforce data is shared as a link to a governed location, never as an attachment. The link respects permissions, can be revoked, and leaves an access trail. The attachment does none of those things.
Blanket restrictions fail predictably — work has to flow, and staff blocked by controls route around them through personal channels, which is the worst outcome available.
The workable posture is tiered to the data. Ordinary business documents share freely inside the organization. Confidential material — compensation, performance records, investigation files — shares to named individuals only. Restricted data — identifiers, banking details, medical information — ideally does not leave its system of record at all: the answer to "can you send me the file" is a link into the system where access is already controlled.
External sharing deserves its own tier: named recipients, expiring links, and — for the vendors who routinely receive workforce data — an agreed secure channel established once, rather than ad hoc attachments each cycle.
Sharing that cannot be seen cannot be governed. The platforms already record who shared what with whom; the gap is that nobody looks.
Worth reviewing on a schedule: externally shared files containing workforce data, link-shares older than some horizon, and the sharing activity of departing employees in their final weeks — bulk sharing to a personal address before a resignation has a recognizable signature, and the review is only useful if it happens before the person leaves.
Alerting on a few high-signal events — external shares from HR and payroll folders, unusually large downloads — converts the record into something closer to a control.
Shares are granted for tasks, and tasks end; the shares rarely do. Auditors keep access after the audit, contractors after the engagement, colleagues after the project. Expiring links and periodic access reviews on shared folders are the mechanisms that make sharing temporary by default rather than permanent by inertia.
Offboarding should include the question almost no checklist asks: what did this person share outward, and what was shared with them that should now be closed?
The written rule that works is short: workforce data stays in its systems; share links, not attachments; name your recipients; external sharing goes through the agreed channels; and when in doubt, ask the data's owner. Paired with defaults that make the right path the easy path, most of the exposure disappears without a single reprimand.
Employer's Guardian helps employers set data handling expectations and the policies that make them enforceable through employee handbook compliance.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.