Independent advisory · South Africa
Google Workspace security audit
The convenience that makes Google Workspace productive can also make access and sharing difficult to govern. Good security keeps collaboration visible and intentional.
What changes
Leadership gets a clearer basis for action.
- Clear control over administrator and user access
- Better visibility of external sharing and third-party connections
- Prioritised hardening actions that respect how teams work
- A governance baseline that can be maintained after the audit
Accounts and authentication
Assess two-step verification, account recovery, session controls, group design and joiner-mover-leaver processes.
Administrative control
Review super admin use, delegated roles, audit access and the resilience of critical administrator accounts.
Drive and data sharing
Examine external sharing defaults, shared drive governance, link exposure and controls around sensitive information.
Applications and devices
Review OAuth applications, marketplace integrations, endpoint controls and the trust granted beyond the core tenant.
How we work
A direct route from uncertainty to accountable action.
- 01
Map the environment
Understand organisational units, administrators, key workflows and the business tolerance for sharing restrictions.
- 02
Test the controls
Review configuration and evidence across identity, data, devices and connected applications.
- 03
Build the control plan
Separate urgent exposure from longer-term governance work and brief both leadership and technical owners.
Working principles
Clear about what you are buying.
- Independent of Google licence sales
- Controls assessed against your working context
- No blanket lockdown that disrupts legitimate collaboration
- A maintainable baseline, not a one-time score
