Practical guide

Give feedback reviewers only the access their task needs

Last materially reviewed 2026-10-01

Quick answerReview the form, response store, exports and integrations as separate places data can travel.
What to know

Map the viewing task

A person who summarizes aggregate themes may not need names or every original response. A person resolving an individual issue may need a different authorized view. Define the work before choosing a role. Avoid shared passwords and broad access granted merely to make a demonstration easier. This guide does not perform permission changes.

What to know

Check connected copies

Google’s documentation notes that later permission changes between a form and its linked response sheet do not automatically stay synchronized. More generally, exports and integrations can create separate copies with their own access. Closing a form or removing one collaborator does not prove every downstream copy is inaccessible.

What to know

A fictional review arrangement

A small service team keeps original responses in an approved restricted location and shares a brief containing counts and non-identifying themes for a process meeting. An individual support case remains in its designated channel. The team verifies actual access rather than relying on a folder name such as “Private.”

What to know

Review when the task changes

When a reviewer leaves or a collection ends, check the appropriate access and retention process. Do not delete records blindly or treat this page as legal retention advice. Keep the minimal useful record of who can review what, and escalate sensitive-data requirements to the responsible specialist.

What to know

Inspect the receiving view

Where authorized, verify the actual reviewer’s permitted view rather than assuming an invitation or role label proves the arrangement. A person may see a board but not an export, or a spreadsheet but more columns than intended. Keep the observation specific and avoid broad security claims. Access review is also separate from deciding how long records should be retained. Use the organization’s applicable policy and responsible advice for retention, disclosure and any sensitive-response handling.

Continue when useful

Next: Identity choices

Not asking for a name does not, by itself, prove anonymity.

Open Identity choices →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. Google Forms response storage — Merchant documentation · support.google.com · Merchant-controlled · checked 2026-10-01
  2. Yay! Forms response board — Merchant documentation · yayforms.com · Merchant-controlled · checked 2026-10-01