Security
Google Workspace security
A Workspace security audit checks the admin console against a fixed control list: authentication, external sharing, OAuth app access, mail authentication, logging retention and leaver process. Findings arrive as a ranked list with an owner and a fix date, not a score.
Most Workspace tenants fail on the same four controls: unenforced 2-step verification, unreviewed third-party OAuth grants, Drive links shared to anyone with the link, and DMARC left at p=none years after it was published.
These pages describe what we check, what we change, and what remains your decision.
Pages in this section
- Google Workspace security auditA fixed-fee review of your Workspace tenant: admin roles, external sharing, OAuth apps, mail authentication and 2FA coverage, with a prioritised fix list.Duration: 5 working days from access being granted
- DMARC setup for Google WorkspaceConfigure SPF, DKIM and DMARC on Google Workspace and move to an enforcing policy without blocking legitimate mail from your own tools.SPF: One TXT record, include Google, under 10 DNS lookups
- Google Workspace offboarding, done without data lossOffboard a Workspace user without losing their files, mail or calendar: transfer ownership, archive the mailbox, revoke access and cut the licence cost.Correct first step: Transfer Drive ownership, not suspend
- Google Workspace backup and retentionWhy Vault is retention rather than backup, the deletion scenarios it cannot recover, and how to design Workspace retention that survives an audit.Gmail trash: 30 days, then unrecoverable by an administrator
What this doesn't cover
- An audit is not a penetration test and does not attempt to exploit anything.
- We do not sign compliance certifications; we produce the evidence your assessor asks for.
- Endpoint and network security outside Workspace is out of scope unless quoted separately.
Questions we get asked
- What does a Google Workspace security audit cover?
- Authentication and 2SV enforcement, admin role sprawl, external sharing defaults, OAuth and marketplace app grants, SPF, DKIM and DMARC alignment, log retention, and the leaver process end to end.
- How long does an audit take?
- Five working days for up to 250 users: two days of console review and log sampling, one day of interviews, two days of write-up and remediation planning.
Not sure which of these you need?
Send us the shape of your estate — seat count, current platform, and the deadline you are working to — and we will tell you which of these pages applies and what it costs.