Google Workspace, governed properly
Who can see whatSharing policies, external access and shared drives configured around real teams and responsibilities.
Who can get inTwo-step verification, focused admin roles and group-based access configured for the organisation.
What happens on the way outA documented leaver process removes access and transfers or preserves business information as required.
GmailBusiness email on your domain, with routing, aliases, groups and delegated access configured around how the team works.
Drive & shared drivesShared drives keep team files under organisational ownership, with membership and external sharing managed centrally.
Meet & CalendarCalendars, resources, appointment schedules and external sharing settings configured for practical day-to-day use.
Identity & accessTwo-step verification enforced, admin roles kept small, and access granted by group rather than one account at a time.
Endpoint managementEndpoint and mobile management settings configured where supported by the selected Workspace edition and device platform.
Sharing & DLPExternal sharing and data protection controls configured where supported by the selected Workspace edition.
Mail authenticationSPF, DKIM and DMARC configured to improve mail authentication, reduce spoofing risk and support reliable delivery.
Backup & retentionGoogle Vault retention and independent backup options reviewed separately, with coverage based on business requirements and the selected Workspace edition.
Google Workspace governance review · kordan.sk
Sharing that needs attention
4 findingsReviewed 4 August
ItemExposureCorrection
How a Google Workspace migration runs
The exact sequence depends on the source system, data volume and usersWeeks before
Audit and pilotWe inventory accounts, aliases, mailbox sizes, calendars and file sources. The destination tenant is configured and a pilot group is used to test the planned process.
Friday
Bulk syncSupported mail, calendar, contact and file data is synchronised while the existing environment remains available.
Saturday
MX switchMail routing and DNS are changed during the agreed cutover window. Delivery and sign-in are checked before the new environment becomes primary.
Sunday
Delta and devicesA final synchronisation captures supported changes, and user devices are prepared using the agreed instructions or hands-on support plan.
Monday
Go-live supportNexys checks mail flow and access, supports users with sign-in or data questions and keeps the fallback plan available until the migration is accepted.
Google Workspace settings we review
Availability and defaults vary by Workspace edition and tenant historySettingOut of the boxHow we leave it
External sharingOut of the boxExisting tenant policyHow we leave itAccess limited to the business need
File ownershipOut of the boxPersonal My Drive contentHow we leave itTeam content moved to appropriate shared drives
Admin accessOut of the boxExisting administrator rolesHow we leave itRoles limited and documented
Two-step verificationOut of the boxCurrent enrolment statusHow we leave itEnforcement and recovery process agreed
Leaver processOut of the boxAd hoc account handlingHow we leave itAccess revoked and business data transferred or preserved
Mail authenticationOut of the boxExisting DNS recordsHow we leave itSPF, DKIM and DMARC aligned and monitored
How it's priced
Tenant setup, migration and governance projects are quoted against a written scope. Day-to-day administration can run as a monthly service. Workspace licences remain under the client organisation and its chosen billing arrangement.
Start with a Google Workspace review
We review administrators, user access, sharing, mail authentication and the joiner and leaver process, then explain which changes should come first.