Free guide · Shared drives

A shared drive structure your whole team can use

It's Thursday afternoon. A funder needs last year's final report by Friday. The person who saved it is on vacation, and the drive has three files called "report final." This guide shows you how to set up folders, names and access so that never happens again, and so your drive is ready if you bring in AI later.

The short answer

Organize a nonprofit shared drive by what the work is, not who does it. Use six to ten top-level folders, like Governance, Finance, Programs, People, Fundraising and Communications, and go no more than three levels deep. Pick one naming pattern with dates written year first. Keep sensitive records in their own locked-down space. Give every folder an owner. Then start with one program, not the whole drive.

Get the free Shared Drive Toolkit →

Why this matters more now

A messy drive used to cost you time. Now it can also cost you trust.

Here's why. AI tools that connect to your files, like Microsoft Copilot or Google's Gemini, can read whatever the person using them is allowed to see. Microsoft says it plainly: Copilot only shows people data they already have permission to view, so it's important to set those permissions correctly (Microsoft).

That sounds safe, until you remember the folder someone shared with "anyone with the link" three years ago. Before AI, nobody stumbled onto it. With AI, a simple question can surface it in seconds.

So a tidy drive isn't just about finding things. It's the first step to using AI safely. And it pays off even if you never use AI at all.

It's also where a lot of nonprofits already use AI: organizing information is one of the most common uses, after communications and research (Imagine Canada and CCNDR, 2026).

The folder map

Organize by what the work is, not by who does it. People change jobs. The work stays.

Start with six to ten top-level folders. Number them so they always sort in the same order:

01 Governance · board, bylaws, minutes, policies
02 Finance · budgets, statements, audits
03 Programs · one folder per program
04 People · job descriptions, training, volunteers
05 Fundraising · grants, donors, events
06 Communications · newsletters, social, website
07 Operations · IT, office, contracts, insurance
Restricted · personnel files, participant records, incidents (separate, locked-down space)

Inside each program, keep it small. Three folders are enough to start:

  • 00 Intake for new files that still need a home.
  • 01 Working for drafts and useful material.
  • 02 Approved for final copies a named owner has signed off on.

Go no more than three levels deep. If people have to click five times to find something, they'll save it to their desktop instead.

Practical rule: Folder names don't set permissions. A folder called "Confidential" isn't private just because of its name. Access is set separately, and we'll get to that.

One naming rule

Pick one pattern and use it everywhere. Here's one that works:

Program_Type_YYYY-MM-DD_Status_v01

Beforereport final FINAL.docx
Sept report new v2.docx
budget (2).xlsx
AfterFood-Bank_Report_2026-09-30_Draft_v02.docx
Food-Bank_Report_2026-09-30_Approved_v03.docx
Finance_Budget_2026-27_Approved_v01.xlsx
  • Write dates year first (2026-09-30). Files then sort in time order on their own.
  • Use Draft or Approved instead of "final." There's only ever one Approved version.
  • Don't guess. If you don't know the date or status, leave it out and ask the owner.

Who sees what

This is the part that matters most, and the part most drives get wrong.

1Use shared drives, not personal ones

Files in someone's personal "My Drive" belong to that person. Files in a Google shared drive belong to the team, and they stay when someone leaves (Google). If important records live in a staff member's personal drive, move them before that person moves on.

2Lock down sensitive records

Personnel files, participant records, incident reports and legal files need tighter access than everything else. You have two options in Google:

  • A separate shared drive with only the people who need it. Use this when even other drive managers shouldn't see the files.
  • A limited-access folder inside a shared drive. Only people added directly can open it, but the drive's managers can still get in (Google).

If you use Microsoft 365, the same idea applies: keep sensitive records in their own site or library with their own members.

3Find the "anyone with the link" files

Search your drive for files shared with "anyone with the link" or with people outside your organization. Close the ones that don't need to be open. Do this before you turn on any AI tool that reads your files.

4Give every folder an owner

An owner decides what belongs there, who can see it and what gets approved. Write the owner's name in a simple list. When someone leaves, their folders get a new owner the same day.

How long to keep things

A tidy drive also means knowing what you can let go of. If you're a registered charity, the Canada Revenue Agency sets minimum times for some records:

RecordKeep at least
Board minutes, governing documents and bylawsAs long as you're registered, plus two years after
Financial statements and source documentsSix years from the end of the tax year they relate to
Copies of official donation receiptsTwo years from the end of the calendar year of the gift

Source: Canada Revenue Agency, Keeping adequate books and records. Records must be kept at an address in Canada on file with the CRA.

Many charities keep minutes and governing documents permanently. Funders, contracts and privacy laws can add their own rules, so write yours down in a short retention policy. And don't delete anything during a clean-up until its owner agrees.

This guide is general information, not legal or accounting advice. Check your funding agreements and ask your accountant before you set retention periods.

Where to start

Don't try to fix the whole drive in one weekend. It won't stick. Instead:

  1. Pick one program and its owner.
  2. Agree the folder map and naming rule for that program.
  3. Move ten working files with the owner watching. Leave anything unclear where it is, and ask.
  4. Test it. Ask a colleague to find a specific file before and after. If they can find it faster, it's working.
  5. Then do the next program.

Our free Shared Drive Toolkit walks you through this with practice files, a one-page rulebook and a tracker. It also shows how AI can suggest names and folders while a person stays in control.

Sources worth your time

Questions people ask

Should we use Google Drive or Microsoft SharePoint?

Use the one your team already lives in. Both can work well. What matters more is the folder map, the naming rule and who can see what. Moving platforms won't fix a messy structure.

How many top-level folders should we have?

Six to ten works for most nonprofits. Name them by function, like Finance or Programs, and number them so they always sort in the same order.

Should we delete old files?

Not during a clean-up, and not without the owner's OK. Some records must be kept for set periods. Write a short retention policy first, then archive or delete based on it.

What about files in staff members' personal drives?

Move organization records into a shared drive. Files in a personal drive belong to that person, which can cause problems when they leave.

Can AI organize our drive for us?

AI can suggest names and folders, which saves time. But a person should approve every move, and AI should never decide who can see what. Fix your permissions before you connect any AI tool to your files.

How do we keep it tidy once it's organized?

Give every folder an owner, keep a one-page rulebook, and use the Intake folder for anything that doesn't have a home yet. Check it once a month.

Free Shared Drive Toolkit

Start with one program.

Our free toolkit has practice files, a one-page rulebook, a tracker and a 90-minute session plan to organize one program with a colleague.

Get the free toolkit →See Connected Systems

Want help setting up a drive your whole team trusts? We connect the tools nonprofits already use and clean up their information, so they're ready for AI whenever they are. Book a Call →

If only one person can find it, it isn't organized yet.

Updated October 2026. This guide is general information, not legal or accounting advice. Written with AI assistance. Reviewed by a person.