Skip to content
Essential or OperateOne account or portfolio

Google Workspace management

Google Workspace, operated with owners, approvals and evidence.

We operate identities, Gmail, Drive, collaboration, application access and Google service change against an agreed baseline. Essential establishes the operating foundation. Operate keeps the queue, configuration and client-owned record current.

Do not send domain names, credentials, exports or administrative data through the public form. The access route and evidence location are agreed after scope approval.

2

Clear service levels

A fixed foundation or recurring operations

12

Named runbooks

Readable procedures your team can keep

Observe first

Controlled access

Production changes follow recorded authority

Client-owned

Operating record

Registers, evidence and handover stay with you

Workspace operations graph

One request. Every dependency visible.

Select a common request to see how business authority, directory structure, service policy, administrator privilege, verification and evidence remain connected.

Request

Authority

Directory

Service policy

Verification

Operating record

New starterExternal Drive accessThird-party appGmail routingDeparting user

Operational friction

Operational gaps appear between the Admin console, business owners and daily requests.

Google centralises configuration. It does not supply your ownership model, approval path or operating evidence. Those controls have to be designed and maintained.

Identity changes lose their authority

Joiners, movers, leavers, group membership and administrator access are often processed from messages. The technical action completes, but the business owner and decision record disappear.

Groups and organisational units carry policy without ownership

A change to an organisational unit, configuration group or inherited setting can affect several services. We record the dependency and owner before changing the structure.

Drive access outlives the project

Shared-drive managers leave, external collaborators remain and My Drive content follows individual ownership. The operating model connects access, ownership and lifecycle decisions.

Applications gain access outside the request queue

OAuth apps, Marketplace installations and domain-wide delegation can reach Workspace data. Each material grant needs a purpose, owner, scopes, approver and review date.

Google changes arrive without an operator

Workspace Updates, mandatory service announcements and service incidents can alter user behaviour or require action. Operate routes each relevant item to an owner and validation step.

Operating coverage

One operating surface across the Workspace account.

The scope follows the Workspace customer account, edition, internal ownership and service dependencies. Each separate account keeps its own administrator identities, evidence location and operating record.

Directory, groups and organisational units

Connect identity lifecycle, group membership, inherited policy and administrator access to named business authority.

  • User lifecycle and authoritative-source mapping
  • Group ownership and membership requests
  • Organisational unit and configuration-group dependency register
  • Named administrator accounts and delegated roles
  • Client-owned Super Admin recovery model

Gmail, Calendar, Meet and Chat

Run messaging and collaboration changes through one request and verification path.

  • Mailbox, alias, delegation and group-mail requests
  • Gmail routing and organisational setting changes
  • Calendar resource and delegation administration
  • Meet and Chat policy requests
  • Client-authorised Google support cases

Drive and shared drives

Keep organisational ownership, managers, external access and lifecycle decisions visible.

  • Shared-drive manager and business-owner assignment
  • External membership and sharing exceptions
  • Orphaned or ownerless collaboration-space review
  • My Drive transfer decisions during offboarding
  • Retain, archive or close authority

Applications, OAuth and API access

Treat third-party data access as an owned production decision rather than an installation click.

  • Accessed and configured application inventory
  • Third-party application approval workflow
  • Marketplace installation decisions
  • Domain-wide delegation register and scope review
  • Apps Script and service-account ownership record

Vault, audit and information governance

Implement client-approved information-governance decisions without presenting Vault as backup.

  • Retention implementation against client-approved schedules
  • Hold authority and custodian dependencies
  • Licence coverage and administrator privilege checks
  • Audit and investigation evidence where the edition supports it
  • Backup and recovery recorded as a separate control

Google change, health and licence operations

Give releases, mandatory announcements, incidents and edition dependencies a named operating route.

  • Workspace Updates relevance assessment
  • Mandatory service announcement routing
  • Workspace Status Dashboard incident coordination
  • Subscription and licence assignment reconciliation
  • Renewal, feature and edition dependency register

Client-owned operating record

The queue, decision and evidence stay connected.

The console is an operating model, not a live customer dashboard. It shows how material work is captured, authorised, verified and handed back.

Loading the interactive console

Administrative access

Scoped, attributable and recoverable by the client.

Google Workspace does not provide a complete read-only equivalent to Super Admin. The operating model uses narrower roles where available and records every task that requires higher privilege.

Super Admin recovery stays client-owned.

Routine work uses named, narrower administrator roles. A Super Admin task is an explicit exception, not the default operating route.

Observe before change

The baseline begins with inspection through scoped roles, exports or a client-led session where Google requires wider visibility. Administrative data moves only through an approved secure channel.

No routine Super Admin

Predefined or custom administrator roles are mapped to routine work. Where Google requires Super Admin, the client authorises a named task and window.

Named administrator identities

Shared administrator accounts are excluded. Each action remains attributable to an individual identity in the available administrator activity records.

Client-owned recovery

The client retains multiple protected Super Admin recovery routes managed by named people. ITSailor never becomes the only path back into the account.

No domain-wide delegation by default

A service account or OAuth client with domain-wide delegation requires a named owner, narrow scopes, recorded purpose, explicit approval and a review date.

High-impact authority stays with the client

Account deletion, data export, Vault changes, global sharing, domain-wide delegation, SSO and 2-Step Verification enforcement require explicit client authority.

Two operating levels

Build the foundation once. Keep it current when you need us to operate it.

Both levels leave a usable operating record. Operate starts with a scoped mobilisation so recurring work never rests on an unknown baseline.

A rich fixed-scope operating foundation

Workspace Operating Foundation

Essential

An internal IT team that inherited a growing Workspace account and needs one documented way to operate it.

Essential establishes the owners, authority, access model, service baselines, request paths and evidence needed to run Google Workspace. Approved foundational corrections can be applied in scope. Project-sized remediation stays visible in the backlog.

Included

  • Workspace account, domains, editions and service inventory
  • Named-owner and decision-authority matrix
  • Administrator role, Super Admin and recovery operating model
  • Directory, group, organisational unit and configuration-group ownership
  • Joiner, mover, leaver and licence decision paths
  • Gmail, Calendar, Meet and Chat request catalogue
  • Shared-drive ownership and external-sharing operating model
  • OAuth, Marketplace and domain-wide delegation register
  • Vault retention and hold authority matrix where licensed
  • Google change, service-health and support workflow
  • Current-state baseline, exceptions and ranked backlog
  • Twelve named runbooks, evidence templates, handover walkthrough and Exit Kit

Operating arc

  • Observe the current account and its dependencies
  • Agree owners, authority, scope and edition limits
  • Build the registers, baseline, runbooks and backlog
  • Apply explicitly scoped foundation changes
  • Verify the handover and access-removal route

Outcome

A documented Workspace account your own team or a successor provider can operate.

A recurring operating service

Managed Workspace Operations

Operate

An organisation that wants the Workspace queue, Google change cycle and operating evidence actively maintained.

Operate starts with a scoped mobilisation. We verify an equivalent operating foundation or build the missing elements, then run the agreed administration queue through named authority, scoped access, verification and evidence.

Included

  • Foundation mobilisation or equivalence review
  • Managed request queue and approved production windows
  • User, group, alias, licence and standard lifecycle administration
  • Shared-drive manager, membership and sharing requests
  • Gmail and collaboration configuration changes in the agreed catalogue
  • Third-party application request and API-access administration
  • Domain-wide delegation ownership and scope review
  • Workspace Updates and mandatory announcement assessment
  • Google service-incident and client-owned support-case coordination
  • Drift review against the agreed operating baseline
  • Administrator, application, ownership and external-access review coordination
  • Updated evidence pack, runbooks, backlog and Exit Kit
  • Optional account portfolio with separate access, baseline, evidence and owner per account
  • Service hours, response objectives, included capacity and escalation authority fixed in the SoW

Operating arc

  • Triage the agreed queue within the contracted service window
  • Assess, approve, apply, verify and record material changes
  • Review Google releases, incidents, access, ownership and licences
  • Refresh the baseline, backlog and client-owned evidence
  • Confirm access and handover readiness during operating reviews

Outcome

A Workspace account with a visible queue, named decisions and evidence for every material action.

Evidence pack

A handover built for the next operator.

Records are readable before they are technical. Every evidence entry can carry its owner, classification, approved readers, source window, retention and client-approved location.

A portfolio keeps a separate pack for each Workspace customer account. The portfolio index links records without creating one universal credential or evidence store.

Workspace operating baseline

WORKSPACE-OPERATING-BASELINE.md

Accounts, domains, editions, in-scope services, owners, current state, inherited dependencies, known exceptions and ranked operating backlog.

Administrative access register

ADMIN-ACCESS-REGISTER.md

Named administrator identities, role privileges, scope, owner, purpose, 2-Step Verification requirement, approval and review result.

Change and exception ledger

CHANGE-AND-EXCEPTION-LEDGER.md

Request, owner, authority, role used, before and after state, reversal path, verification, evidence, residual risk and review date.

Service ownership register

SERVICE-OWNERSHIP-REGISTER.md

Authoritative sources, organisational units, configuration groups, business owners, delegated administrators and lifecycle decisions.

Shared-drive and external-access register

SHARING-AND-SHARED-DRIVES-REGISTER.md

Business owner, managers, membership model, external access, restrictions, exceptions, lifecycle state and next review.

Application and delegated-access register

OAUTH-AND-DWD-APP-ACCESS-REGISTER.md

OAuth client, Marketplace application or service account, data owner, scopes, affected users, access state, purpose and review decision.

Vault retention and authority matrix

VAULT-DECISION-REGISTER.md

Licensed services, approved retention instructions, hold authority, custodian dependencies, administrator privileges and legal-contact ownership.

Google change and service record

GOOGLE-CHANGE-AND-HEALTH-LOG.md

Workspace releases, mandatory announcements, service incidents, affected users, actions, stakeholder updates, support cases and closure notes.

Licence decision ledger

LICENCE-DECISION-LEDGER.md

Edition, assignment, business need, feature dependency, exception, renewal owner, decision and next review.

Twelve operating runbooks

runbooks/

Human-readable procedures for identity lifecycle, administration, Drive, applications, delegated access, Gmail, Vault, service change, incidents and transfer-out.

Exit Kit

EXIT-KIT.md

Current owners, access removal, baselines, registers, runbooks, open work, evidence locations and successor-provider handover.

Scope boundaries

Clear authority is part of the operating design.

The SoW names the account, services, request catalogue, client inputs, service window, capacity and escalation path. These boundaries prevent routine administration from quietly becoming an unlimited helpdesk or an incident-response promise.

Inside the agreed service

  • The selected Workspace account, domains, services and standard request catalogue
  • Named queue, change control, scoped administration, verification and evidence
  • Routine identity, group, collaboration, application and licence work agreed in the SoW
  • Google release, incident and client-owned support-case coordination during the contracted service window
  • Runbook maintenance, operating review, Exit Kit and access removal

Client authority and inputs

  • Authoritative HR, user, owner, group and licence information
  • Named requestors, approvers, legal contacts, risk owners and communication contacts
  • Appropriate Workspace editions, add-ons and support entitlement
  • Approved secure access, evidence location, change windows and user communication
  • Counsel-approved retention, preservation and release instructions

Separate project or provider

  • Unlimited end-user helpdesk, deskside support, hardware logistics or 24/7 on-call coverage
  • Continuous security monitoring, SOC, MDR, forensics, breach command or legal notification decisions
  • Migration, federation, major ChromeOS rollout, endpoint programme or broad hardening deployment
  • Backup and disaster recovery, legal advice, eDiscovery strategy or litigation decisions
  • Gemini rollout, adoption programme, custom Apps Script, add-on or integration development
  • Certification, regulator approval or a guarantee of Google service availability

Verifiable design basis

Claims tied to Google documentation.

Edition-dependent features are checked during scope. The page does not present Vault as backup, reseller status as proof or implementation evidence as certification.

Delivery

Founder-led

The person scoping the operating model remains directly involved in delivery.

Administration

Scoped and attributable

Named identities, narrow roles, explicit approvals and no shared administrator account.

Edition fit

Dependency recorded

Features are not promised when the selected Workspace edition or add-on does not provide them.

Exit

Client-owned

Registers, runbooks, evidence and handover records stay in the approved client repository.

Google Workspace Admin Help

Administrator privilege definitions

The privileges available to predefined and custom administrator roles, including edition-dependent controls and service-specific administration.

Open official source
Google Workspace Admin Help

Security best practices for administrator accounts

Google guidance on named administrator accounts, 2-Step Verification, separate routine accounts and multiple Super Admin accounts.

Open official source
Google Workspace Admin Help

Control which applications access Workspace data

Application access states, OAuth scopes, high-risk service access, user requests and API-control dependencies.

Open official source
Google Workspace Help

Control API access with domain-wide delegation

Google describes domain-wide delegation as powerful access and recommends narrow scopes, named ownership and regular review.

Open official source
Google Workspace Learning Centre

Shared-drive ownership and access

Shared-drive files belong to the organisation, persist when members leave and follow manager, membership and sharing restrictions.

Open official source
Google Vault Help

Google Vault FAQ

Google states that Vault is not a backup or archive tool and does not provide automated recovery from exports.

Open official source
Google Vault Help

How retention works

Retention and holds can preserve or purge supported data. Google warns that incorrect retention rules can cause irreversible deletion.

Open official source
Google Workspace Help

Protect your business with Context-Aware Access

Context-Aware Access capabilities, supported services and edition requirements that must be checked before scope.

Open official source
Google for Developers

Admin SDK Reports API overview

Activity and usage reports for supported Workspace services, including administrator and third-party access events.

Open official source
Google Workspace Admin Help

Check Google Workspace service status

Current and historical Workspace service incidents and the operating information available through the status dashboard.

Open official source
Google Workspace Updates

Official Workspace release feed

Google's administrator-facing announcements for new features, controls, rollout timing and edition availability.

Open official source
Google Workspace Admin Help

Export organisation data

The Super Admin, 2-Step Verification, timing, scope and storage requirements for organisation-wide data exports.

Open official source

Questions before scope

The operating model should be clear before access is granted.

These answers define what Operate is, where client authority remains and which Workspace capabilities depend on edition or add-ons.

Do you replace our internal IT team?+

No. Essential gives the internal team a documented operating model. Operate can own the agreed recurring queue while business authority and strategic decisions remain with the client.

Is Operate an unlimited end-user helpdesk?+

No. The SoW defines the accounts, services, standard request types, service window, included capacity, response objectives, escalation path and overflow treatment. End-user helpdesk and deskside support are separate.

What administrator access do you need?+

Routine work uses named accounts with predefined or custom administrator roles. Super Admin is reserved for tasks Google does not expose through a narrower privilege and requires explicit client authority.

Do you make changes without approval?+

Only documented standard changes may use standing authority. High-impact actions and exceptions require a named client approver before production work begins.

Is Google Vault a backup service?+

No. Google states that Vault is an information-governance and eDiscovery tool, not a backup or archive system. It has no automated restore capability. Backup and recovery are scoped separately.

Can you define our retention or legal-hold policy?+

No. The client and its counsel define retention, preservation and release authority. We can translate approved instructions into configuration, runbooks and evidence where Vault is licensed.

Do you keep our Super Admin recovery accounts?+

No. Recovery remains client-owned. Google recommends multiple Super Admin accounts managed by different people and separate accounts for routine activity.

Are Vault, Context-Aware Access, DLP and the investigation tool always included?+

No. Availability depends on the selected Workspace edition, add-ons and account type. Essential records edition gaps. Major deployments remain separate projects.

Can you manage several Workspace accounts?+

Yes. Each account keeps separate administrator identities, access authority, baseline, evidence location and local owner. No universal credential is reused across the portfolio.

What happens during a Google outage?+

Operate checks the Workspace Status Dashboard and relevant alerts, records impact, coordinates the client-owned support case where authorised and updates named stakeholders during the contracted service window. ITSailor cannot repair Google's service or guarantee availability.

Does Operate include security incident response?+

No. A client-triggered and pre-authorised containment action can be written into a runbook and the SoW. Continuous monitoring, investigation, forensics, breach command and 24/7 response remain separate.

Can this evidence certify GDPR, DORA, NIS2 or ISO 27001 compliance?+

No. The operating record can support agreed control-to-evidence mapping. It is implementation evidence, not legal advice, certification, assurance or regulator approval.

What remains if we stop Operate?+

The current baseline, access register, ownership records, change and exception ledger, application register, Vault matrix, Google change record, runbooks, backlog, evidence locations and access-removal confirmation remain in the Exit Kit.

Who actually performs the work?+

Delivery is founder-led. The SoW names the delivery and client roles without inventing a larger service team. If retained specialist coverage or an external provider is required, that dependency is stated before the scope is signed.

Make every Workspace action leave a useful record.

Scope one Workspace account or a portfolio. Each account keeps its own authority, access, baseline, evidence and exit path.