Google Workspace Review

For firms on Google Workspace who want a straight read on what the admin console enforces today, what Vault would genuinely recover, and which controls their edition simply doesn't offer.

View All Engagements

A fixed-scope read on how your Google Workspace is put together, covering admin role scope and the organizational unit tree, Drive general access defaults and target audiences, what Vault is and is not retaining, and how much history the admin console can still show you. Several of the controls a Google hardening guide will tell you to switch on, Context-Aware Access among them, are not offered on the Business editions at all, so we tell you which ones your edition can reach before you go hunting for a toggle that isn't there.

Duration
7 to 10 business days
Engagement
Review

Output

What you walk away with

A defined output, on paper or in your tenant. Yours to use whether the work continues with us or not.

Admin and OU findings

Who holds Super Admin, which prebuilt or custom roles are doing real work and at what scope, and whether your organizational unit tree can carry different policy for different teams or is one flat list.

Drive sharing picture

The general access setting new files inherit, how much work sits in Shared Drives against personal My Drive, whether target audiences are in use, and where external sharing has quietly stayed open.

Vault and logging reality check

What Vault covers across Gmail, Drive, Chat, and Meet, what your retention rules would purge if left alone, and the practical limits: most admin log events are kept for six months, and email log search reaches back only 30 days.

Edition gap list

The recommended controls your edition can actually apply, separated from the ones like Context-Aware Access that live on the Enterprise and Frontline tiers, so you can price the upgrade against the control it buys.

How It Works

How the work runs.

A short, defined sequence. Nothing in your tenant or domain changes until the scope and access are confirmed.

Console access

We confirm your edition, who holds Super Admin, and the reporting access we need to look without changing anything. The review is governed against the CIS Benchmark for the platform, so the findings sit against a published standard rather than against one consultant's checklist.

Identity and structure

We read admin role assignments and their scope, the organizational unit tree, 2-Step Verification enforcement, and how account recovery works for the admins themselves.

Drive and sharing

We go through general access defaults, Shared Drive membership, what individuals hold in My Drive, external sharing rules, and the link shares still live from years back.

Retention and logging

We compare Vault retention rules and holds against what you believe is being kept, and confirm how much history is still queryable.

Findings handoff

You get the findings, an order of work, and a clear note on anything your current edition cannot do at any price.

Best Fit

Sound familiar?

Everyone sits in one organizational unit, so any policy you write lands on the whole company at once

Super Admin became the easy answer and the prebuilt roles underneath it have never been used

Drive still creates files with a general access default nobody chose, and old link shares have never been counted

People treat Vault as a backup, when a retention rule that expires purges the data from Google for good

Someone left, their work stayed in My Drive, and the window to restore a deleted account is only 20 days

Frequently asked questions.

Who is Google Workspace Security and Governance Review for?

Google Workspace Security and Governance Review is built for firms running on Google Workspace, teams on Business Standard, Business Plus, or Enterprise, and owners facing a vendor security review.

How does this engagement start?

Every engagement starts with a short first call to confirm the situation, the decision owner, the access required, and whether this is the right engagement for what you actually need.

What happens after the first call?

Teclara confirms the scope, the access, and the timing. If the engagement is a fit, we agree on the work and start. If a different engagement fits better, we say so.

Ready to start?

Book the first call. We will confirm the situation, the access required, and the right way to move forward, with no obligation past that conversation.