Sectors
Google Workspace for accountancy practices
Accountancy practices on Google Workspace need one shared drive per client rather than per service line, secure document exchange that does not rely on emailed attachments, retention that satisfies statutory record-keeping periods, and access controls that hold up during busy-season temporary staffing.
| Client files | One shared drive per client, named to client code |
|---|---|
| Document exchange | Named-account sharing or portal, not attachments |
| Retention | Keyed to statutory period from year end |
| Temporary staff | Expiry date at creation, restricted org unit |
| Bank details | Never changed on email instruction alone |
| Common exposure | Client data in personal My Drive folders |
One drive per client, not per service line
Service-line structure looks tidy and creates a problem: a client's audit team, tax team and advisory team each hold partial context, and cross-team access is granted ad hoc until everybody can see everything. Client-based drives make the access question explicit and answerable.
The overhead is real. A practice with four hundred clients has four hundred drives, which needs a creation process tied to client onboarding and an archival process tied to disengagement. Both are automatable, and neither is optional at that scale.
Stop exchanging documents by email attachment
Emailed attachments are the mechanism behind most invoice fraud aimed at accountancy clients, and they are also how client data ends up in mailboxes with no retention control. Named-account sharing on a client drive, or a portal, removes both problems at once.
The objection is always that clients find it harder. Sometimes true, and the honest response is that the friction is worth it for anything containing financial data or personal information. A short client-facing guide, sent at onboarding rather than mid-engagement, removes most of the resistance.
- Named external accounts on the client drive, reviewed at year end
- Link sharing disabled at domain level for anything client-related
- Bank detail changes verified by call-back on a previously known number
- Outbound mail authenticated with DMARC at enforcement
- Client-facing guide issued at onboarding, not during a deadline
Busy-season staffing and account expiry
Temporary staff arrive in volume and leave quietly. If accounts are created without an end date, they persist, and each one is a live credential against client financial data held by someone who no longer works with you.
Set the expiry at creation, put temporary staff in their own org unit with tighter external sharing and download controls, and review the list at the start of the following month. It takes minutes and it removes the single largest access risk in a practice tenant.
Retention for statutory records
Statutory retention runs from a client's year end or filing date, not from when a document was created. Workspace retention rules are configured against org units and time, so satisfying the obligation depends on an archival step that moves closed years into a retained location.
The pattern that works is an archive org unit per retention period, an archival step in the year-end process, and an annual verification that the archive contains what the practice management system says it should.
What we see that others don't say
Busy season is the security event in this sector: practices onboard temporary staff in January and rarely reclaim their access in February, so the highest-value control for an accountancy tenant is an account expiry date set at creation rather than any policy applied afterwards.
What this doesn't cover
- We are not your practice management or tax software. Workspace holds documents and mail; workflow belongs in your practice system.
- We do not advise on statutory retention periods. We implement the periods your compliance lead confirms.
- We do not integrate with every accountancy platform. Where no supported integration exists we will say so rather than build something fragile.
- Anti-money-laundering identity verification is a process and software question, not a Workspace configuration question.
Questions we get asked
- How should an accountancy practice structure Google Drive?
- One shared drive per client, named to the client code, with creation tied to onboarding and archival tied to disengagement. Service-line structure leads to ad hoc cross-team access that nobody can audit.
- What is the safest way to exchange documents with clients?
- Named external accounts on the client's shared drive, or a portal. Emailed attachments carry both fraud risk and retention problems, and link sharing should be disabled at domain level.
- How do we manage busy-season temporary staff?
- Set an account expiry date at creation, place temporary staff in a dedicated org unit with tighter sharing and download controls, and review the list in the first week of the following month.
- Does Google Workspace meet accountancy retention requirements?
- It can, with Vault retention rules and an archival step that moves closed years into a retained org unit. The product supports it; the process step is what practices most often omit.
How this page is verified
Reviewed by Pearl Lemon Cloud security desk, Workspace security and compliance reviewers. Last checked .
- Retention rule and org unit behaviour reflect Google Workspace and Vault documentation as of 2026-08-06.
- Busy-season access observations are Pearl Lemon Cloud audit findings across professional-services tenants to 2026-08-06.
- This page describes technical configuration and is not regulatory or tax advice.
Sources you can check
Related pages
- Statutory retention and restore testing
- Workspace for charities and nonprofits
- Exporting mail and Drive from Google Vault
- Estimate transfer hours for your mailbox count
- Book a Workspace audit for your practice
- Authenticate outbound mail against invoice fraud
- Audit a practice tenant
- Workspace for law firms
- Outsource practice administration
Harden your practice tenant
We restructure client storage, close the busy-season access gap, and get outbound mail authenticated before the next filing deadline.