Skip to content
Notis

Run a Cloudflare member review when a Drive item is shared

A new share can be a useful cue to check who has access to your Cloudflare account.

Trigger

File Shared (Permissions Added)

Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.

Action

List Account Members

Tool to list members of a given cloudflare account. use after confirming the account id.

Why this helps

Access reviews get deferred when they are separate from the event that reminds you to do them.

  • Use a Drive sharing event to prompt a Cloudflare membership check.
  • Receive the member list in your selected report channel.
  • Keep periodic access review from depending on memory.

Setup

Build it in a few focused steps.

  • 1Connect Google Drive and Cloudflare once in the Notis portal.
  • 2Create an automation in Automations, New Automation, or tell Notis what outcome you want from any channel.
  • 3In one instruction, ask Notis to list members for the Cloudflare account you specify when a Drive item is newly shared, then report the results for review.
  • 4Pick Google Drive File Shared as the trigger and choose where run reports go.
  • 5Test with one real sharing event.

Questions about this workflow

Does this remove Cloudflare members who should not have access?

No. The available action lists account members. A person must review the results and make any access changes separately.

Can the workflow infer which Cloudflare account to check?

Specify the account in your instruction or provide a reliable account choice in the request. The action needs an account identifier.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Google Drive to Cloudflare. A trigger fires from one place; an action lands in another.

Google Drive triggers

Cloudflare actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Create DNS record

Tool to create a new dns record within a specific zone. use after obtaining the zone id to programmatically add dns entries.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Create WAF List

Tool to create a new empty waf list for the account. use after confirming the account id. example: create list(account id="<id>", kind="ip", name="blocklist")

ActionInstant

Comment Added (Docs/Sheets/Slides)

Triggers when a new comment is added to Google Docs, Sheets, or Slides.

TriggerPolling

Create Zone

Tool to create a new zone. use after confirming account id when adding a domain to cloudflare.

ActionInstant

File Created

Triggers when a new file is created in Google Drive.

TriggerPolling

Delete DNS Record

Tool to delete a dns record within a specific zone. use after confirming zone and record ids. example: "delete dns record 372e6795... from zone 023e105f4ecef..."

ActionInstant

File Deleted or Trashed

Triggers when a file is moved to trash or permanently deleted in Drive.

TriggerPolling

Delete WAF List

Tool to delete a waf list. use when you need to remove a list after verifying no filters reference it. example: delete list(account id="<account id>", list id="<list id>")

ActionInstant

File Shared (Permissions Added)

Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.

TriggerPolling

Delete Zone

Tool to delete a zone. use after confirming the zone identifier to permanently remove a dns zone from your cloudflare account. example: delete zone(zone identifier="023e105f4ecef8ad9ca31a8372d0c353")

ActionInstant

File Updated

Triggers when a file's metadata or content changes in Google Drive.

TriggerPolling

List WAF Lists

Tool to fetch all waf lists (no items) for an account. use after confirming account id.

ActionInstant

Google Drive Changes

Triggers when changes are detected in a Google Drive.

TriggerPolling

List Account Members

Tool to list members of a given cloudflare account. use after confirming the account id.

ActionInstant

Connect any two apps with Notis in the middle.

Google Drive and Cloudflare, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Cloudflare.