Managed support
Outsourced Google Workspace administration
Outsourced Google Workspace administration hands user lifecycle, permissions, policy and reporting to an external named engineer working under a written authorisation matrix. It suits organisations between roughly twenty and three hundred seats, where the work is real but does not justify a full-time administrator.
| Good fit | 20–300 seats, no full-time Workspace admin |
|---|---|
| Model | Named primary engineer plus documented deputy |
| Price | From £9 per seat per month, minimum 15 seats |
| Control | Written authorisation matrix agreed at onboarding |
| Reporting | Monthly change log, quarterly posture review |
| Exit | 30 days' notice, full runbook handover included |
The work that fills the gap
Between twenty and three hundred seats there is a persistent awkwardness. Workspace administration is perhaps a day a week of genuine work, which is too much for an office manager doing it between other duties and too little to justify hiring for. The result is usually that it gets done reactively, by whoever is least busy, with no documentation.
Outsourcing that specific function gives you a named engineer who knows the tenant, works from a runbook, logs every change, and is backed by a deputy who can cover absence. The improvement over the status quo is generally not capability, it is consistency.
The authorisation matrix
Before we touch anything, we agree in writing who may request what. Access to finance shared drives requires the finance lead. Creating a super admin requires two named approvers. Anything affecting security policy requires a specific person and a written request rather than a phone call.
This matters because the realistic attack on an outsourced administrator is not technical. It is a convincing message from a name the engineer recognises, at a moment when the request seems reasonable. A matrix converts that into an escalation, which is exactly what you want to happen.
- Named approvers per change class, agreed at onboarding
- Two-approver rule for privilege escalation and security policy
- Every change logged with requester, approver and timestamp
- Monthly change log issued to your nominated owner
- Quarterly review of the matrix as people move roles
What stays with you
Super-admin ownership of the tenant stays with you, always. We work under delegated roles with the narrowest privilege set that lets the job be done, and there is at least one super-admin account under your sole control that we do not hold credentials for.
Billing ownership also stays with you unless you specifically want us to hold it. Keeping the commercial relationship with Google separate from the operational relationship with us means changing supplier does not require changing platform.
Leaving well
Thirty days' notice, and the handover pack is prepared in advance rather than assembled during the notice period. It contains the current runbook, the change log history, the authorisation matrix, the current configuration baseline and a list of open recommendations.
An outsourcing arrangement that would be painful to exit is a liability regardless of how well it is running today. We would rather be kept because the service is good than because leaving is hard.
What we see that others don't say
The control that makes outsourced administration safe is not the contract, it is the authorisation matrix: a written list of who may request which class of change, which turns social-engineering attempts against the administrator into an escalation rather than an incident.
What this doesn't cover
- We do not hold sole super-admin control of your tenant. At least one super-admin account stays exclusively yours.
- We do not manage endpoints, networks, or applications outside Workspace under this agreement.
- We do not execute requests from people outside the authorisation matrix, including urgent ones. That is the point of the matrix.
- We are not a replacement for an internal IT lead above roughly three hundred seats; at that size the right answer is usually to hire and let us support that person.
Questions we get asked
- What size organisation should outsource Workspace administration?
- Roughly twenty to three hundred seats. Below that the workload rarely justifies an agreement; above it, hiring an internal administrator and using external support for depth usually works out better.
- Do you take super-admin control of our tenant?
- No. We work under delegated admin roles with the narrowest privilege set required, and you retain at least one super-admin account we hold no credentials for.
- How do you stop someone social-engineering an access change?
- A written authorisation matrix agreed at onboarding names who may request each class of change, with a two-approver rule for privilege escalation. Requests from outside the matrix are escalated, never executed.
- What happens if we want to bring administration back in house?
- Thirty days' notice, and a handover pack containing the runbook, change log, authorisation matrix, configuration baseline and open recommendations. The pack is maintained continuously, not written at exit.
How this page is verified
Reviewed by Deepak Shukla, Founder, Pearl Lemon Cloud. Last checked .
- Delegated admin role capabilities reflect Google Workspace Admin Help documentation as of 2026-08-06.
- Pricing and notice terms are the Pearl Lemon Cloud service agreement as of 2026-08-06.
- Workload estimates derive from Pearl Lemon Cloud service-desk time records to 2026-08-06.
Sources you can check
Related pages
- DNS and mail records we maintain
- Microsoft 365 to Google Workspace moves
- Workspace for accountancy practices
- Generate a dated leaver checklist
- Retainer tiers and monthly floor
- London-based Workspace support desk
- The leaver process we run
- Baseline the tenant before we take it on
- Consultancy for one-off projects
Hand over the admin console
Named engineer, written authorisation matrix, monthly change log, thirty days' notice. Send your seat count and we will send terms.