I used to be the tech lead for the sharing and permissions side of a file storage service. In my experience with designing systems, participating in user studies, trying to problem solve with coworkers, and so on, this is an extremely hard problem to solve, because (as can be seen in the comments), there usually isn’t a right answer. Different people expect very different defaults, and get frustrated and upset when things don’t match their a priori expectations. The temptation is to solve these differing use cases with lots of configurability, precise descriptions, and lots of user education but users don’t read (usually), and rarely do they understand the tricky implications of different settings. Not only that, but mistakes they make in configuration or use will understandably cause them to be more scared of using your service.
I don’t think anyone has solved access control, not Facebook, Google, OneDrive, or even Apple.