How to audit permissions for Google Workspace
Auditing permissions in Google Workspace helps you identify who can access files, groups, mail, and admin controls before those rights become a security problem.
This guide explains how to review access systematically, what to look for in each Workspace service, and how to turn findings into a repeatable governance process.
Permission sprawl often starts quietly, with a shared folder, an inherited group, or an admin role granted for a temporary project.
The challenge is not just finding access, but understanding whether each permission still matches business need.
What a Google Workspace permissions audit should cover
A useful audit looks beyond Google Drive sharing links.
It should include identity, collaboration, and administrative control surfaces where access can expand without notice.
- User accounts: active users, suspended users, external collaborators, and service accounts.
- Google Drive and Shared drives: folder and file permissions, link-sharing settings, ownership, and inheritance.
- Google Groups: membership, posting rights, and groups used for access control.
- Admin roles: super admin, delegated admin, and custom roles.
- Gmail and routing settings: mailbox delegation, routing rules, and compliance access.
- Third-party apps: OAuth grants and Marketplace app permissions.
- Audit logs: evidence of permission changes and access events.
Start with an inventory of identities and roles
Before reviewing file shares or group memberships, build an inventory of all accounts and roles in your Google Workspace domain.
Use the Admin console to export user lists, role assignments, and group memberships so you can compare intended access against actual access.
Focus on three questions:
- Who is an active employee, contractor, or external collaborator?
- Which users have elevated privileges in Admin console?
- Which groups are being used as access containers for documents, shared drives, or applications?
This step matters because Google Workspace permissions are often inherited through groups and shared drives.
If a group contains a former employee or broad mailing list, every resource tied to that group may be exposed.
How to audit permissions for Google Workspace in Google Drive
Google Drive is usually the largest source of access risk because sharing is fast and flexible.
Audit both individual files and Shared drives, since each behaves differently.
Review sharing settings on sensitive files
Identify documents, spreadsheets, presentations, and folders containing financial, HR, legal, customer, or source code data.
For each item, check:
- Whether access is restricted to specific users or groups
- Whether link sharing is set to restricted, domain-wide, or public
- Whether editors can share the item with others
- Whether external users have direct access
- Whether ownership has changed from the original creator
Use Drive search and the details panel to inspect who has access.
For higher-risk data, remove “anyone with the link” access and replace it with named users or tightly controlled groups.
Check Shared drives and inherited access
Shared drives are governed by membership and role-based permissions, which makes them easier to manage at scale but also easy to overlook.
Review each Shared drive for:
- Membership list accuracy
- Manager versus content manager privileges
- External members or external sharing
- Whether the drive contains outdated project teams
- Whether a drive is still needed or should be archived
Because permissions inherit through folders and files, one overly broad Shared drive role can expose large volumes of content.
If a drive is no longer active, remove access and preserve only what the business needs.
Audit Google Groups used for access control
Google Groups often act as the backbone of access management in Workspace.
They can control file access, mailing lists, application access, and even some admin workflows, so group hygiene is critical.
For each important group, verify:
- Membership is current and approved
- Owners and managers are still assigned
- External members are justified
- Posting permissions match the intended use
- The group is not duplicated or abandoned
Pay special attention to groups that grant access to sensitive folders or Shared drives.
If a group has grown far beyond its original purpose, replace it with a smaller, role-based group.
Review admin roles and delegated privileges
Administrative permissions deserve the strictest review because they can affect every account and security setting in the tenant.
In Admin console, inspect both built-in roles and custom roles.
Look for:
- Super admins who no longer need full control
- Delegated admins with excessive scope
- Custom roles that include broader permissions than intended
- Temporary admin access that was never removed
- Accounts used for automation that also have human admin rights
Apply least privilege by assigning the narrowest role required for each job function.
For example, a help desk technician may need user reset privileges, but not security policy control or domain-wide configuration access.
How to check Gmail, routing, and mailbox access
Gmail permissions are easy to miss because they are less visible than Drive sharing.
Yet mailbox delegation, routing rules, and compliance-related settings can expose sensitive communications.
Audit the following:
- Mailbox delegates and who can read or send on behalf of a user
- Routing rules that forward mail outside the organization
- Automated forwarding to external addresses
- Groups or aliases receiving confidential correspondence
- Vault or retention-related access for compliance teams
If external forwarding is allowed, confirm it is approved and monitored.
Many security teams treat unsolicited forwarding as a sign of account compromise or data leakage.
Don’t forget third-party app permissions
OAuth-connected apps can gain access to Gmail, Drive, Calendar, Contacts, and more.
A permissions audit should include connected apps, especially those authorized by users rather than centrally approved by administrators.
Review app access for:
- Scopes granted to sensitive Google services
- Apps no longer in use
- Apps installed by former employees
- High-risk integrations with broad read/write access
- Marketplace apps that duplicate existing enterprise tools
Remove unnecessary grants and consider restricting app installation to approved publishers or internal allowlists.
This reduces the chance of shadow IT and unintended data exposure.
Use audit logs to validate permission changes
Reports and logs provide the evidence you need to understand how permissions changed over time.
In Google Workspace, audit logs can help you answer who granted access, when the change happened, and what object was affected.
Use logs to look for:
- New external shares on sensitive files
- Role changes in Admin console
- Group membership additions or removals
- Mailbox delegation changes
- Suspicious app authorizations
Trend analysis is especially useful.
A sudden spike in sharing changes or repeated permission edits on the same resource may point to process issues or malicious activity.
A repeatable workflow for permission audits
The most effective audits follow the same sequence each time, so findings are consistent and easy to compare.
- Export identities, groups, roles, and sharing reports.
- Identify high-risk data locations and privileged accounts.
- Review inheritance in Drive and Shared drives.
- Validate group membership and ownership.
- Check admin roles and delegated access.
- Inspect Gmail delegation and forwarding rules.
- Review third-party app permissions.
- Document exceptions, remediation steps, and owners.
Assign each issue a severity based on data sensitivity, exposure scope, and whether the access is externally reachable.
That makes it easier to prioritize remediation instead of treating every finding the same.
Best practices to keep permissions under control
An audit should lead to permanent improvements, not just a one-time cleanup.
To reduce future risk, combine technical controls with policy discipline.
- Use groups instead of individual users whenever possible.
- Apply least privilege to admin and app access.
- Require approval for external sharing on sensitive content.
- Review access on a fixed schedule, such as quarterly.
- Remove stale accounts, inactive groups, and unused drives.
- Log and approve temporary access with expiration dates.
- Standardize naming so resource ownership is easy to trace.
With these controls in place, Google Workspace permissions become easier to review, easier to defend, and less likely to drift out of policy.
Metrics that show whether the audit is working
Track a few clear metrics so you can measure improvement over time.
Useful indicators include the number of external shares removed, the percentage of privileged accounts reviewed, the number of stale groups retired, and the count of third-party apps revoked.
These metrics help security teams show progress and help business owners understand where access risks remain concentrated across Google Workspace.