Keep a searchable log of Drive sharing changes
When new permissions are granted, capture the sharing change in ClickHouse.
Trigger
File Shared (Permissions Added)
Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.
Action
Execute ClickHouse Query
Execute a sql query in clickhouse and return the results. this is the primary action for querying data from clickhouse databases.
Why this helps
It takes extra effort to keep up with access changes when sharing activity is spread across files and folders.
- Create a queryable record of newly granted permissions.
- Review sharing changes alongside other operational data.
- Make access reporting less dependent on manual checks.
Setup
Build it in a few focused steps.
- 1Connect Google Drive and ClickHouse once in the Notis portal.
- 2Create an automation in Automations and enter a name, prompt, report channel, and trigger.
- 3Tell Notis to record each newly granted permission using available change details in your existing ClickHouse audit table; provide its schema.
- 4Choose the File Shared trigger and where run reports should go.
- 5Test with one real permission change and inspect the inserted record.
Questions about this workflow
What does the File Shared trigger detect?
It triggers when new sharing permissions are granted to a file or folder. Its change data includes the file's current permission set.
Can this report every historical permission?
The trigger is for newly granted permissions. It does not provide a complete historical audit by itself.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Google Drive to ClickHouse. A trigger fires from one place; an action lands in another.
Google Drive triggers
ClickHouse actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Execute ClickHouse Query
Execute a sql query in clickhouse and return the results. this is the primary action for querying data from clickhouse databases.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get Database Schema
Get comprehensive schema overview of an entire database including all tables and optionally their column definitions. essential for ai agents to understand the complete database structure in a single call.
Comment Added (Docs/Sheets/Slides)
Triggers when a new comment is added to Google Docs, Sheets, or Slides.
Get Table Schema
Get detailed schema information for a specific table including column definitions, types, keys, and optionally sample data. this is essential for ai agents to understand table structure before constructing queries.
File Created
Triggers when a new file is created in Google Drive.
List ClickHouse Databases
List all databases in the clickhouse instance. useful for discovering available databases before querying tables.
File Deleted or Trashed
Triggers when a file is moved to trash or permanently deleted in Drive.
List ClickHouse Tables
List tables in clickhouse databases. returns information about tables including their engine, size, and row count.
File Shared (Permissions Added)
Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.
File Updated
Triggers when a file's metadata or content changes in Google Drive.
Google Drive Changes
Triggers when changes are detected in a Google Drive.
Connect any two apps with Notis in the middle.
Google Drive and ClickHouse, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business ClickHouse.