Document control is the set of rules and tools that decide who can see, change, or share your files
When you work with a document editor, document control is what stops your roommate from opening a file you marked private, or prevents a coworker from changing the final version of a contract after you've signed off on it. It's the combination of permissions you set (who can view, edit, comment, or read), the version history that tracks who changed what and when, and the access logs that show who opened the file.
Document control matters for privacy because it's the difference between a file that lives in your account alone and a file that's exposed to people you didn't intend to share it with. It also matters for security: if someone gains access to your account, document control settings determine how much damage they can do and whether you'll know they were there.
Key Takeaways
- Document control includes three separate layers: who can access the file, what they're allowed to do with it, and whether you can see a record of their actions.
- Permission settings (view-only, edit, comment) are only as strong as the account security protecting them — a weak password or shared login undermines all of them.
- Version history and access logs let you detect unauthorized changes or unwanted viewing, but only if the editor actually records and shows them to you.
- Different editors handle document control differently: some let you revoke access when ready, others take hours; some show you every viewer, others hide that information.
- The most private choice isn't always the most controlled choice — a file you keep entirely offline has perfect control but zero recovery if your device fails.
The three layers of document control
Access control is who can open the file at all. You set this by sharing a link or adding specific email addresses. Some editors let you make a file "view-only" so people can see it but not read it; others let you set an expiration date so the link stops working after a certain day. The catch: once someone has the link or has been added to the file, revoking access takes time. Google Docs revokes access almost when ready. OneDrive can take up to 15 minutes. Some older systems take hours.
Permission control is what people can do once they're in. The standard options are view-only (read the file, nothing else), comment (read and leave notes but not change the text), and edit (read and change everything). Some editors let you lock specific sections so one person can edit the introduction but not the budget table. Others don't offer that granularity. If you share a file with edit access and someone deletes half of it, you can usually recover it from version history — but only if the editor keeps version history and shows it to you.
Audit control is whether you can see what happened. This means version history (who changed what, when), access logs (who opened the file and when), and read records (who downloaded a copy). Not all editors provide all three. Microsoft Word Online shows version history but not access logs. Google Docs shows both. Some privacy-focused editors show neither because they don't store that data — which is more private for the people viewing the file, but gives you no way to detect a breach.
Why document control fails in practice
The most common failure is account compromise. If someone gets your password, they can change your document control settings before you notice. They can add themselves as an editor, read your files, or change the permissions to make the document public. Document control settings protect against people you've intentionally shared with; they don't protect against someone who has taken over your account. That's why account security (a strong password, two-factor authentication) matters more than document control settings.
The second failure is social engineering. You share a file with someone you trust, and they forward it to someone else. Document control can't stop that — it only controls what the person you shared with can do within the editor. If they read the file and email it, the control is gone.
The third failure is that document control settings are straightforward to change by accident. You might set a file to "view-only" and forget that you also shared the folder it's in, which gives people edit access to everything in that folder. Or you might set a link to "anyone with the link can view" when you meant "only people I add can view." These are usually one-click fixes once you notice, but you have to notice.
What different editors actually offer
| Editor | when ready access revocation | View-only option | Version history shown to you | Access logs shown to you |
|---|---|---|---|---|
| Google Docs | Yes, seconds | Yes | Yes, with names and timestamps | Yes, shows who opened when |
| Microsoft Word Online | Yes, seconds | Yes | Yes, with names and timestamps | No |
| OneDrive | Takes 15 minutes | Yes | Yes | Limited |
| Nextcloud (self-hosted) | Yes, seconds | Yes | Yes | Yes, if you enable logging |
| Cryptpad | Yes, seconds | Yes | Yes, but encrypted | No, by design |
The table shows what's technically possible, but "possible" isn't the same as "straightforward to find." Google Docs access logs are buried three menus deep. OneDrive's access logs exist but don't show you every viewer. Nextcloud's logging is off by default and requires you to turn it on. If you need to see who opened a file and when, you have to check whether your editor actually shows you that information — and where.
When you're choosing an editor, look at the row that matters most to you. If you need to revoke access when ready and see who's been in the file, Google Docs checks both boxes. If you want encryption so the editor itself can't see your files, Cryptpad does that — but you lose access logs. There's no editor that does everything, so you're choosing what trade-offs you can live with.
The trade-off between control and privacy
More document control usually means more data about your files is being stored and shown to you. Google Docs knows exactly who opened your file and when because it logs that. Cryptpad doesn't know — the file is encrypted so thoroughly that even Cryptpad's servers can't see who's inside. That's more private for you and the people you share with, but it means you can't see an access log if you need one.
Similarly, a file you keep entirely offline (stored only on your computer, never synced or shared) has perfect control — nobody else can access it. But if your hard drive fails, it's gone. A file in Google Drive is less under your control (Google can see it, can be subpoenaed, could theoretically be hacked) but is backed up automatically and recoverable if your device fails.
There's no setting that gives you both perfect privacy and perfect control. You choose which matters more for each file. A tax return might warrant offline storage. A shared project plan might be worth the trade-off of cloud backup and access logs.
How to set document control for different situations
For a file only you need to see: store it offline or in a private folder that you don't share. If you do store it in the cloud, make sure the default sharing setting is "private" and that you haven't accidentally shared the folder it's in.
For a file you're sharing with one person: add that specific person by email rather than creating a shareable link. Set their permission to the minimum they need (view-only if they're just reading, comment if they're giving feedback, edit only if they're making changes). Check the access log afterward to confirm they opened it.
For a file a team is editing together: use an editor that shows version history clearly (Google Docs and Word Online both do this well). Set a rule that people should comment rather than edit directly when possible, so you have a record of who suggested what. Check version history weekly to catch unauthorized changes early.
For a file with sensitive information: consider whether it needs to be in the cloud at all. If it does, use an editor that supports password-protected downloads or view-only links with expiration dates. Revoke access as soon as the person no longer needs it.
What to check before you share a document
Before you hit share, open the sharing settings and confirm three things. First, who can access it — is it a specific person, a group, or "anyone with the link"? Second, what can they do — view, comment, or edit? Third, does the editor show you access logs, and if so, have you checked them recently?
If you're using a link (rather than adding specific people), check whether the link is view-only. Many editors default to edit access on links, which means anyone who gets the link can change the file. That's usually not what you intend.
If you're sharing a folder rather than a single file, remember that the folder's permissions explore to everything in it. You might think you're sharing one document but actually be sharing ten. Take the extra 30 seconds to share the specific file instead of the folder.
Frequently Asked Questions
Can someone edit my document without me knowing?
Yes, if you've given them edit access and don't check version history. That's why version history matters: it shows you who changed what and when. Google Docs and Word Online both keep detailed version history by default. If you share a file with edit access, check the version history tab weekly to catch changes you didn't expect.
What happens if I revoke someone's access — do they lose the file?
They lose access through the editor, but if they downloaded a copy before you revoked access, they still have that copy. Document control only controls what happens inside the editor. If you need to prevent someone from keeping a copy, don't give them read permission in the first place, or use an editor that doesn't allow downloads (some view-only links prevent this).
Is it safer to keep documents offline or in the cloud?
Offline is safer from unauthorized access — nobody can hack into a file that isn't on the internet. Cloud storage is safer from loss — if your computer fails, the file is still there. For highly sensitive documents (financial records, medical information), offline storage is usually the better choice. For documents you need to access from multiple devices or share with others, cloud storage with strong document control settings is usually more practical.
Can I see if someone shared my document with a third person?
Only if the editor shows you access logs. Google Docs does. Word Online doesn't. If you're concerned about this, add people by email rather than sharing a link — that way, you control exactly who has access. With a shareable link, you can't see who has it or who they've shared it with.
What's the difference between "view-only" and "comment-only"?
View-only means they can read the document but can't make any changes or leave notes. Comment-only means they can read it and leave comments or suggestions, but their comments don't change the actual text — you have to accept each change. Edit means they can change the text directly. Use comment-only when you want feedback but want to review each change before it's final.