Skip to content
Notis

Review new Drive shares for suspicious domains

New sharing permissions can expose unfamiliar links. Have Notis check the domains against DNSFilter threat intelligence.

Trigger

File Shared (Permissions Added)

Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.

Action

Suggest Domain Threat

Tool to suggest a fqdn as a potential threat. use after identifying a suspicious domain to verify its threat categorization.

Why this helps

Manually inspecting every newly shared document for risky links creates more security follow-up to track.

  • Surface suspicious domains in files that have just been shared.
  • Reduce manual link review after permission changes.
  • Keep security review close to the sharing event.

Setup

Build it in a few focused steps.

  • 1Connect Google Drive and DNSFilter once in the Notis portal.
  • 2Create an automation in Automations, New Automation, and give it a clear name.
  • 3In one instruction, ask Notis to inspect links in the changed file and suggest domains that appear suspicious.
  • 4Choose Google Drive File Shared as the trigger and select a report channel.
  • 5Test with one real newly shared file and review the run report.

Questions about this workflow

Does this block a domain automatically?

No. The available DNSFilter action suggests a domain as a potential threat; it does not create a block rule.

What starts the automation?

A new sharing permission on a Google Drive file or folder.

Will it inspect every file already shared?

No. This trigger responds to newly granted sharing permissions.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Google Drive to Dnsfilter. A trigger fires from one place; an action lands in another.

Google Drive triggers

Dnsfilter actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Create IP Address

Tool to create a new ip address in dnsfilter. use after confirming the target network id exists.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get Application Category

Tool to get basic information of a specific application category. use when you need details for a given application category id.

ActionInstant

Comment Added (Docs/Sheets/Slides)

Triggers when a new comment is added to Google Docs, Sheets, or Slides.

TriggerPolling

Get Billing Information

Tool to retrieve basic billing information for an organization. use when you need to obtain billing details for reporting or automation tasks.

ActionInstant

File Created

Triggers when a new file is created in Google Drive.

TriggerPolling

Get Category

Tool to get basic information of a specific category. use when you need to retrieve details for a category by its id.

ActionInstant

File Deleted or Trashed

Triggers when a file is moved to trash or permanently deleted in Drive.

TriggerPolling

Get IP Address

Tool to get basic information of the specified ip address. use when you need to fetch metadata for a particular ip after authentication.

ActionInstant

File Shared (Permissions Added)

Triggers when new sharing permissions are granted to a file or folder. Uses Drive's `changes.list` endpoint with inline `permissions` in the `fields` mask so each change carries the file's current permission set provider-atomically. We diff that against `seen_permission_keys` to identify newly added grants. Drive page tokens are the primary cursor; if Drive rejects a stored token, the trigger raises `PollingTriggerError` without clearing state rather than silently re-baselining and dropping events. Limitation: truly ephemeral permissions (added and revoked between two polls without any other file modification in between) are not detected. Drive Activity API would catch those but requires an additional OAuth scope and a different payload contract.

TriggerPolling

List All Categories

Tool to list all categories including internal categories. use when you need the complete set of filtering categories.

ActionInstant

File Updated

Triggers when a file's metadata or content changes in Google Drive.

TriggerPolling

List All IP Addresses

Tool to list all user-associated ip addresses. use when you need a comprehensive list of all ip address entries in your organization.

ActionInstant

Google Drive Changes

Triggers when changes are detected in a Google Drive.

TriggerPolling

List All MAC Addresses

Tool to list all mac addresses with basic information. use when you need to retrieve all mac address entries in your organization.

ActionInstant

Connect any two apps with Notis in the middle.

Google Drive and Dnsfilter, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Dnsfilter.