
Google Workspace Administration
A tenant that nobody administers does not stay as it was configured. It drifts — quietly, in one reasonable decision at a time — and the drift is invisible until a leaver, an audit or a renewal makes it visible all at once.
None of this work is difficult. Provisioning a starter, removing a leaver properly, keeping groups current, checking the licence count against the actual staff list. It is simply work that stops happening the moment nobody owns it, and two years of not happening is what we are usually called in to unpick.
The work that keeps stopping
- person_addStarters provisioned properlyRight unit, right groups, 2SV enrolled
- person_removeLeavers removed in the right orderSuspend, delegate, transfer, then delete
- receipt_longLicence count against the staff listChecked before renewal, not after
- fact_checkSharing and access reviewedBefore the exceptions become the policy
Six ways an unmanaged tenant drifts
Not one of these is a mistake anyone made. Each is the accumulated result of reasonable decisions nobody revisited — which is precisely why they are invisible until something forces a look.
Accounts for people who left
Nobody deleted them, because deleting felt risky and nobody owned the decision. Each is a licence you are paying for and a credential that still works.
Groups that no longer match the team
A sales group containing two people who moved to operations and missing the three who joined last year. Mail goes to the wrong inboxes and nobody connects the two facts.
Forwards pointing at ex-employees
Set up for a handover that finished eighteen months ago, still quietly copying correspondence to an address the company no longer controls.
Sharing that widened one exception at a time
Each individual decision was reasonable. The cumulative position is that far more is shared externally than anyone would agree to if asked directly.
Admin rights granted and never reviewed
Someone needed to do one thing in 2023. They still have the access, and in several cases they no longer work here.
Storage filling with nothing anyone needs
Migrated archives, duplicate exports, abandoned project folders. Pooled storage means it eventually becomes everyone's problem at once.
Joiner, mover, leaver
Most organisations handle the first reasonably and the third eventually. The middle one is where access quietly accumulates until somebody has the keys to everything and nobody decided to give them.
Joiner
The easy one that still goes wrong
- check_circleAccount created to the agreed naming convention, not improvised
- check_circlePlaced in the right organisational unit, so policy applies automatically
- check_circleAdded to the groups their role needs — and only those
- check_circleShared Drive access by group membership rather than individual grants
- check_circleEnrolled in two-step verification before their first week ends
Mover
The one almost nobody handles
- check_circleAccess for the new role added — which everyone remembers
- check_circleAccess for the old role removed — which almost nobody does
- check_circleGroup membership updated on both sides of the move
- check_circleDelegated mailbox access reviewed against the new responsibilities
- check_circleOver several years, this is how people accumulate access to everything
Leaver
The one with a deadline
- check_circleAccount suspended immediately — before any other step
- check_circleMail delegated or forwarded to a named successor for a defined period
- check_circleDrive files transferred to the manager or the relevant Shared Drive
- check_circleRemoved from groups, aliases and delegated access
- check_circleDeleted or archived only once the transfers are verified
The leaver sequence is the one worth memorising, because the order matters more than the steps. Suspend first — it stops access immediately and destroys nothing. Delete last, and only once transfers are verified, because deletion is the single step that cannot be undone once the recovery window closes.
Six adjustments that reduce the bill
None involve downgrading anyone who needs their tools. These are the changes we make most often when taking over an account that has run unmanaged for a couple of years, and for many organisations they cover the cost of the administration itself.
Reclaim what leavers are still holding
The most common source of waste, and the easiest to fix. Licences stay assigned because removing one feels irreversible and nobody owns the call. A quarterly review against your actual staff list usually pays for the administration itself.
Archive rather than keep a full seat
Where a departed employee's mail has to be retained, some editions offer an archived-user licence that preserves the data at lower cost than an active seat. Availability depends on your edition, and it is worth asking before renewal rather than after.
Mix editions instead of levelling everyone up
There is no requirement that the whole organisation sits on the same tier. Putting the people who genuinely need the higher edition on it, and leaving the rest, is frequently the single largest saving available.
Stop paying for addresses that are not people
Shared addresses configured as full licensed accounts when a group would do. Licences are per person; a business that counted its addresses instead of its people is paying for the difference every month.
Right-size at renewal, not at random
Renewal is the point at which a committed licence count can actually come down. Reviewing real usage a month beforehand is worth more than any mid-term negotiation.
Clear storage before buying more of it
Old backups, duplicate exports and abandoned shared folders account for a surprising share of a Drive footprint. A clean-up sometimes removes the reason for an edition upgrade entirely.
What any of this is worth depends entirely on how far your current position has drifted, so we would rather look than estimate. Current India list prices are on our pricing page.
What actually needs attention in there
The console is not complicated — this is one of Google Workspace's genuine advantages over the alternatives. The difficulty is not finding the settings but knowing which ones drift, and how often to look at them.
Users and organisational units
Where accounts live, and therefore which policy applies to them. The structure decides how granular your control can ever be, so changes here are the ones worth thinking about before making.
Groups and aliases
Mailing groups people write to, security groups that grant access, and the aliases that route mail without consuming a licence. These drift faster than anything else in the console.
Security settings
Two-step verification enforcement, admin roles, session controls, third-party app access. Reviewed periodically rather than set once and forgotten.
Drive and sharing policy
External sharing rules, link-sharing defaults, Shared Drive membership and ownership. The place where quiet exceptions accumulate.
Devices and endpoints
Which devices hold company data and what you can do about one that goes missing. Depth varies by edition.
Reporting and audit logs
Who signed in, who changed what, how storage is actually being consumed. The data is there whether or not anyone looks at it.
The security settings in particular are covered in their own right on our Google Workspace security page, including which controls need a higher edition.

Who should actually be doing this
All three are legitimate and we will tell you which one fits. The failure mode is not choosing the wrong model — it is believing you are doing one of them when in fact nobody is doing any.
In-house
Suits
You have someone whose job genuinely includes this, with time to do it.
Works because
Fastest response, full control, no external dependency.
Breaks when
It is nobody's priority until it is urgent, and it leaves with that person. Most small organisations think they are doing this and are in fact doing nothing.
Managed
Suits
No internal owner, or one who has better things to do.
Works because
The standing work actually happens on a schedule rather than when someone remembers.
Breaks when
Requires us to hold enough access to act, and a named person on your side who can make decisions.
Hybrid
Suits
Someone internal handles day-to-day, with help for the rest.
Works because
Your team does joiners and password resets; we handle structure, security review, licence hygiene and anything unfamiliar.
Breaks when
Needs the split written down. Where it is assumed rather than agreed, both sides think the other is doing the review.
What stays yours
Handing administration to an outside party is a reasonable thing to be cautious about. These are the commitments that make it safe, and they hold whether or not anyone asks about them.
- task_alt
The super-admin accounts are yours, throughout and without exception
- task_alt
We hold whatever delegated access you are comfortable granting — including none
- task_alt
Every decision that changes policy or removes access is yours to approve
- task_alt
Documentation is handed over and kept current, so you are never dependent on us to understand your own setup
- task_alt
You can end the arrangement and keep working, because nothing is configured in a way only we understand
Google Workspace administration — common questions
helpWhat does Google Workspace administration actually include?
expand_more
The standing work that keeps a tenant matching the organisation it serves. New starters provisioned to the agreed convention and the right organisational unit. Leavers suspended, their mail delegated and their files transferred before anything is deleted. Groups, aliases and delegated access kept current as roles change. Licence count reviewed so you stop paying for people who left. Security settings and sharing policy reviewed periodically rather than set once. Storage housekeeping before it becomes urgent. None of it is difficult; all of it stops happening the moment nobody owns it.
helpHow is administration different from support?
expand_more
Support is reactive — you contact us because something is wrong: mail not delivering, a user locked out, access broken, a leaver's files unreachable. Administration is proactive: the standing work that stops most of those calls happening in the first place. Most organisations need some of both. A useful signal is that if you find yourself raising the same category of problem every quarter, the answer is usually not faster support but administration that is currently missing.
helpWe have an IT person already. Do we need this?
expand_more
Possibly not, and we would rather say so. If someone's job genuinely includes Workspace administration and they have the time, in-house is the fastest arrangement and we are not going to beat it. The question worth asking honestly is whether the periodic work is actually being done — when was the licence count last reviewed against the staff list, when was the connected-apps list last examined, is there a written leaver process. Where the answer is that it happens when someone remembers, that is not in-house administration; it is an intention.
helpWhat is the single most common thing you find?
expand_more
Accounts belonging to people who left. They persist because deleting one feels irreversible and nobody owns the decision, so each becomes both a licence you are paying for and a credential that still works. The second most common is the mover problem — someone changes role, gains the new access and keeps the old, and over several years accumulates access to almost everything without anyone granting it deliberately.
helpWill you have access to our email?
expand_more
Only the administrative access you grant, and that is a decision you make rather than a condition of the service. Some clients grant a delegated admin role so we can act quickly; some grant access only when there is a specific task; some keep everything in-house and use us for review and advice. All three work. The super-admin accounts remain yours throughout, and every change that removes access or alters policy is yours to approve.
helpWhat happens to a departing employee's mail and files?
expand_more
The sequence matters more than the individual steps. Suspend the account first, which stops access immediately without destroying anything. Delegate or forward their mail to a named successor for a defined period. Transfer their Drive files to their manager or into the relevant Shared Drive. Remove them from groups, aliases and any delegated access. Only then delete or archive, and only once the transfers are verified. Doing it in the wrong order is how correspondence gets lost, and deleting first is the mistake that cannot be undone after the recovery window closes.
helpCan you take over administration of a tenant somebody else set up?
expand_more
Yes, and it is a large share of what we do. The first piece of work is usually documenting what is actually configured — organisational units, groups, admin roles, sharing policy, connected applications, dormant accounts. That audit is frequently the most valuable part of the engagement, because it turns a system nobody fully understands into one with a written description.
helpHow is this priced?
expand_more
Scoped and quoted separately from licences, based on user count and how much of the work you want handled rather than advised on. We quote it as an explicit line rather than folding it into a licence rate, so you can see what it costs and decide whether it is worth it. The requirement call and the quote are free.
Related pages
Google Workspace Support
The reactive half — what breaks, and who to call when it does.
Google Workspace Security
The controls an administration review keeps in good order.
Google Workspace Implementation
The initial build that administration then maintains.
Google Workspace Backup
What Google recovers and for how long — and why Vault is not a backup.
Find out how far yours has drifted
Tell us roughly how many users you have and who handles this today. We will go through what is actually configured — dormant accounts, group membership, sharing, connected apps, licence count against your real staff list — and tell you what is worth changing.
- check_circle
A written leaver process, so accounts stop accumulating
- check_circle
Licence count checked against your actual staff list
- check_circle
Groups, aliases and delegated access brought current
- check_circle
Your super-admin accounts stay yours throughout
We administer tenants for businesses across Kerala and the rest of India. Or call +91 99467 89916 or email admin@techgeum.com.