NAS permissions that do not become a liability
Shared drives fail slowly. Every exception is reasonable on the day it is made, and the result is a share where everyone can read everything.
30 April 20262 min readadmin
Almost every shared drive ends up in the same state: a folder structure nobody planned, permissions granted to individuals as favours, and an Everyone group that quietly has more access than anybody intended. Nothing went wrong on any single day. Each change was reasonable.
Why it drifts
The drift has one cause: permissions get granted to people rather than to roles. Somebody in accounts needs a file in the operations folder, so they are added to the operations folder. They move department, or leave, and nobody removes them — because nobody knows the grant was ever made.
Do that for four years and the permissions describe the history of who once asked for something, not who should have access today.
Groups, always
Permissions go to groups. People go into groups. That is the whole discipline, and it holds because it makes the two questions separable: what should this role reach, and who is in this role. The first changes rarely; the second changes constantly.
It also makes the audit possible. "Who can read the payroll folder" is answerable in one step when it is a group and requires walking every folder when it is a list of individuals.
Depth is the enemy
Set permissions near the top and let them inherit. Every level at which somebody breaks inheritance to make an exception is a level where the effective permission stops being predictable, and nested exceptions six folders deep are where the surprises live.
If a folder needs different access from its parent, that is usually a sign it belongs somewhere else in the structure rather than a sign it needs an exception.
Deny is a last resort
An explicit deny overrides allows, which makes it feel like a precise instrument. In practice it is the entry that causes the "I have permission but cannot open it" ticket that takes an afternoon, because the deny is inherited from a folder nobody thought to check.
Almost every case for a deny is better served by removing an allow.
The share that should not exist
Every NAS ships with a default public share and it should be the first thing removed. It is the folder that fills with things people meant to move later — which routinely includes scans of documents that were never supposed to be on a general share.
Review it once a year
Export the permissions, sit with whoever runs each department, and go through who is in each group. It takes an hour and it is the only thing that reverses the drift. Every leaver who still has access is found in that hour, and nowhere else.