Company files that actually belong to the company.
A private space for each person, organisation-owned Shared Drives for the work that has to persist, and the same permission model and audit trail as the rest of Cyril. Announced rather than available: the code is merged, the accessibility acceptance is not yet signed off.
What Drive does for you
My Drive and Shared Drives
Exactly one private space per staff member, created the moment their membership activates. Shared Drives are owned by the organisation, with Manager, Content Manager, Contributor and Viewer roles, so content stays put when contributors leave.
Sharing that shows its reach
Grants to people and departments inherit down the folder tree and can be stopped at any subtree, and search only ever returns what the caller could already open. Public links are off by default at organisation level; where policy permits them they carry expiry, optional passwords or one-time codes, download caps and immediate revocation.
Versions, Trash and Undo
Replacing a file writes a new immutable version rather than overwriting bytes, and any version can be restored. Trash is a place you browse, and bulk move, copy, delete and restore run with a preflight, an Undo, and a retry that cannot apply twice.
Retention and legal hold
Policy- and event-based retention rather than one blanket period for every file, with a seven-year template for Australian financial records included. Holds are scoped and access-neutral — they preserve evidence without handing anyone a new way to read it.
The files your mail, your policies and your audit log already know about.
Because Drive is part of the platform, an email attachment saves straight into My Drive, a Shared Drive or Marketing Assets — with the destination’s own permissions, quota, conflict rules and virus scanning applied, and provenance back to the message it came from. Compose can attach an existing Drive file, and access is re-checked at the moment the message is actually sent.
- Save a copy from Mail; attach from Drive when composing
- One permission model and one audit trail, not a storage-specific pair
- Malware scanning and storage plumbing shared with Assets, not duplicated
Turnover is a workflow, not a support ticket.
Shared Drive content never needs transferring, because the organisation already owns it. Deactivation freezes the leaver’s My Drive and opens an audited claim so an authorised admin can transfer it or let it expire. Getting into someone’s private files in an emergency is a separate permission again — step-up authenticated, with a stated reason, a time bound, and a record nobody can edit afterwards.
- Frozen, audited My Drive claim and transfer on deactivation
- Break-glass access is reasoned, time-bounded and dual-controlled where required
- Ordinary admin views show aggregate usage, never My Drive names or contents
Common Drive questions
No. Every batch of code is merged and deployed, but Drive ships fail-closed behind a tenant flag and stays there until a named human has completed the screen-reader acceptance pass. That evidence has not been recorded yet, so we are announcing Drive rather than offering it.
Not yet. The read-and-import adapters for both are built, but the production connections are off pending Google’s OAuth verification and Microsoft tenant and admin consent. When they open, they are import only: you browse the provider, copy what you want into Cyril, and the original is left exactly where it was.
No, and that is permanent rather than a gap in the roadmap. There is no two-way sync, no background mirroring, no writeback to the provider, and Cyril never deletes anything at the source. Importing is a deliberate act with a visible result, which is the only version of it we are willing to audit.
No native document authoring or real-time co-editing — Docs is where writing happens in Cyril. No desktop sync client or offline mount, and no AI retrieval over file contents until permission-aware search is proven end to end. External people get explicit shares or an upload-only File Request that lets them add a file without seeing what else is in the folder; a client-facing file workspace is not part of this release.
Be one of the first to use Cyril.
Join the waitlist for early access. We'll only email you when there's something real to share.