Secure control
Named admins, strong sign-in and independent recovery.
Accounts · collaboration · recovery
Review the controls that protect a Workspace domain, record the evidence behind each answer and leave with a practical list of gaps and questions—not a confidence-inflating score.
Start the Workspace reviewA guided review, not an automated verdict
Check the current Admin console, reports, app access, sharing records, change history and recovery tests. Use “not checked” whenever the answer is an assumption.
A sensible review order
Start with super admins, 2-Step Verification and recovery. Then work outward through OAuth access, Drive and Groups sharing, mail routes, audit visibility and recoverability.
Named admins, strong sign-in and independent recovery.
Apps, groups, links, delegates and external users.
Logs, alert routes, retention and representative restores.
Important boundaries
Workspace editions and service features differ. The right configuration depends on the organisation's identity model, users, data, applications and obligations.
Test recovery before enforcing sign-in or context policies. Keep more than one individually assigned super admin available.
Retention rules govern supported data and can drive deletion. Design, test and approve them carefully; validate restore needs separately.
A checklist cannot establish legal or framework compliance without defined scope, evidence and accountable interpretation.
Google's administrator guidance
The checklist uses these first-party references for its most consequential questions. Revisit them during implementation because names, availability and edition support can change.
Common questions
No. It does not request an administrator sign-in or API permissions. You complete it using evidence from your authorised review.
Google recommends multiple super admin accounts managed by separate people so another administrator can act if one account is lost or compromised.
Vault is designed for information governance, retention, holds, search and export. Google states that it is not a data archive. Define restore requirements separately and test the chosen recovery method.
Not automatically. Availability, device management, user experience, bypasses and lockout risk need review. The checklist asks whether the complete access model is deliberate and tested.
Need help validating the answers?
ACA Tech Solutions can help UK teams review Google Workspace administration, identity, app access, sharing, audit and recovery, then sequence improvements around real business needs.