Tech Geum team administering a Google Workspace tenant
Google Partner · Authorized Reseller

Google Workspace Administration

A tenant that nobody administers does not stay as it was configured. It drifts — quietly, in one reasonable decision at a time — and the drift is invisible until a leaver, an audit or a renewal makes it visible all at once.

None of this work is difficult. Provisioning a starter, removing a leaver properly, keeping groups current, checking the licence count against the actual staff list. It is simply work that stops happening the moment nobody owns it, and two years of not happening is what we are usually called in to unpick.

The work that keeps stopping

  • person_addStarters provisioned properlyRight unit, right groups, 2SV enrolled
  • person_removeLeavers removed in the right orderSuspend, delegate, transfer, then delete
  • receipt_longLicence count against the staff listChecked before renewal, not after
  • fact_checkSharing and access reviewedBefore the exceptions become the policy
What happens without it

Six ways an unmanaged tenant drifts

Not one of these is a mistake anyone made. Each is the accumulated result of reasonable decisions nobody revisited — which is precisely why they are invisible until something forces a look.

person_off

Accounts for people who left

Nobody deleted them, because deleting felt risky and nobody owned the decision. Each is a licence you are paying for and a credential that still works.

groups

Groups that no longer match the team

A sales group containing two people who moved to operations and missing the three who joined last year. Mail goes to the wrong inboxes and nobody connects the two facts.

alternate_email

Forwards pointing at ex-employees

Set up for a handover that finished eighteen months ago, still quietly copying correspondence to an address the company no longer controls.

folder_shared

Sharing that widened one exception at a time

Each individual decision was reasonable. The cumulative position is that far more is shared externally than anyone would agree to if asked directly.

admin_panel_settings

Admin rights granted and never reviewed

Someone needed to do one thing in 2023. They still have the access, and in several cases they no longer work here.

storage

Storage filling with nothing anyone needs

Migrated archives, duplicate exports, abandoned project folders. Pooled storage means it eventually becomes everyone's problem at once.

User lifecycle

Joiner, mover, leaver

Most organisations handle the first reasonably and the third eventually. The middle one is where access quietly accumulates until somebody has the keys to everything and nobody decided to give them.

person_add

Joiner

The easy one that still goes wrong

  • check_circleAccount created to the agreed naming convention, not improvised
  • check_circlePlaced in the right organisational unit, so policy applies automatically
  • check_circleAdded to the groups their role needs — and only those
  • check_circleShared Drive access by group membership rather than individual grants
  • check_circleEnrolled in two-step verification before their first week ends
swap_horiz

Mover

The one almost nobody handles

  • check_circleAccess for the new role added — which everyone remembers
  • check_circleAccess for the old role removed — which almost nobody does
  • check_circleGroup membership updated on both sides of the move
  • check_circleDelegated mailbox access reviewed against the new responsibilities
  • check_circleOver several years, this is how people accumulate access to everything
person_remove

Leaver

The one with a deadline

  • check_circleAccount suspended immediately — before any other step
  • check_circleMail delegated or forwarded to a named successor for a defined period
  • check_circleDrive files transferred to the manager or the relevant Shared Drive
  • check_circleRemoved from groups, aliases and delegated access
  • check_circleDeleted or archived only once the transfers are verified

The leaver sequence is the one worth memorising, because the order matters more than the steps. Suspend first — it stops access immediately and destroys nothing. Delete last, and only once transfers are verified, because deletion is the single step that cannot be undone once the recovery window closes.

The money

Six adjustments that reduce the bill

None involve downgrading anyone who needs their tools. These are the changes we make most often when taking over an account that has run unmanaged for a couple of years, and for many organisations they cover the cost of the administration itself.

person_off

Reclaim what leavers are still holding

The most common source of waste, and the easiest to fix. Licences stay assigned because removing one feels irreversible and nobody owns the call. A quarterly review against your actual staff list usually pays for the administration itself.

archive

Archive rather than keep a full seat

Where a departed employee's mail has to be retained, some editions offer an archived-user licence that preserves the data at lower cost than an active seat. Availability depends on your edition, and it is worth asking before renewal rather than after.

tune

Mix editions instead of levelling everyone up

There is no requirement that the whole organisation sits on the same tier. Putting the people who genuinely need the higher edition on it, and leaving the rest, is frequently the single largest saving available.

label

Stop paying for addresses that are not people

Shared addresses configured as full licensed accounts when a group would do. Licences are per person; a business that counted its addresses instead of its people is paying for the difference every month.

calculate

Right-size at renewal, not at random

Renewal is the point at which a committed licence count can actually come down. Reviewing real usage a month beforehand is worth more than any mid-term negotiation.

trending_down

Clear storage before buying more of it

Old backups, duplicate exports and abandoned shared folders account for a surprising share of a Drive footprint. A clean-up sometimes removes the reason for an edition upgrade entirely.

What any of this is worth depends entirely on how far your current position has drifted, so we would rather look than estimate. Current India list prices are on our pricing page.

The admin console

What actually needs attention in there

The console is not complicated — this is one of Google Workspace's genuine advantages over the alternatives. The difficulty is not finding the settings but knowing which ones drift, and how often to look at them.

manage_accounts

Users and organisational units

Where accounts live, and therefore which policy applies to them. The structure decides how granular your control can ever be, so changes here are the ones worth thinking about before making.

groups

Groups and aliases

Mailing groups people write to, security groups that grant access, and the aliases that route mail without consuming a licence. These drift faster than anything else in the console.

shield_lock

Security settings

Two-step verification enforcement, admin roles, session controls, third-party app access. Reviewed periodically rather than set once and forgotten.

folder_shared

Drive and sharing policy

External sharing rules, link-sharing defaults, Shared Drive membership and ownership. The place where quiet exceptions accumulate.

devices

Devices and endpoints

Which devices hold company data and what you can do about one that goes missing. Depth varies by edition.

history

Reporting and audit logs

Who signed in, who changed what, how storage is actually being consumed. The data is there whether or not anyone looks at it.

The security settings in particular are covered in their own right on our Google Workspace security page, including which controls need a higher edition.

Reviewing the Google Workspace admin console
Three arrangements

Who should actually be doing this

All three are legitimate and we will tell you which one fits. The failure mode is not choosing the wrong model — it is believing you are doing one of them when in fact nobody is doing any.

badge

In-house

Suits

You have someone whose job genuinely includes this, with time to do it.

Works because

Fastest response, full control, no external dependency.

Breaks when

It is nobody's priority until it is urgent, and it leaves with that person. Most small organisations think they are doing this and are in fact doing nothing.

handshake

Managed

Suits

No internal owner, or one who has better things to do.

Works because

The standing work actually happens on a schedule rather than when someone remembers.

Breaks when

Requires us to hold enough access to act, and a named person on your side who can make decisions.

balance

Hybrid

Suits

Someone internal handles day-to-day, with help for the rest.

Works because

Your team does joiners and password resets; we handle structure, security review, licence hygiene and anything unfamiliar.

Breaks when

Needs the split written down. Where it is assumed rather than agreed, both sides think the other is doing the review.

Control

What stays yours

Handing administration to an outside party is a reasonable thing to be cautious about. These are the commitments that make it safe, and they hold whether or not anyone asks about them.

  • task_alt

    The super-admin accounts are yours, throughout and without exception

  • task_alt

    We hold whatever delegated access you are comfortable granting — including none

  • task_alt

    Every decision that changes policy or removes access is yours to approve

  • task_alt

    Documentation is handed over and kept current, so you are never dependent on us to understand your own setup

  • task_alt

    You can end the arrangement and keep working, because nothing is configured in a way only we understand

Google Workspace administration — common questions

help

What does Google Workspace administration actually include?

expand_more

The standing work that keeps a tenant matching the organisation it serves. New starters provisioned to the agreed convention and the right organisational unit. Leavers suspended, their mail delegated and their files transferred before anything is deleted. Groups, aliases and delegated access kept current as roles change. Licence count reviewed so you stop paying for people who left. Security settings and sharing policy reviewed periodically rather than set once. Storage housekeeping before it becomes urgent. None of it is difficult; all of it stops happening the moment nobody owns it.

help

How is administration different from support?

expand_more

Support is reactive — you contact us because something is wrong: mail not delivering, a user locked out, access broken, a leaver's files unreachable. Administration is proactive: the standing work that stops most of those calls happening in the first place. Most organisations need some of both. A useful signal is that if you find yourself raising the same category of problem every quarter, the answer is usually not faster support but administration that is currently missing.

help

We have an IT person already. Do we need this?

expand_more

Possibly not, and we would rather say so. If someone's job genuinely includes Workspace administration and they have the time, in-house is the fastest arrangement and we are not going to beat it. The question worth asking honestly is whether the periodic work is actually being done — when was the licence count last reviewed against the staff list, when was the connected-apps list last examined, is there a written leaver process. Where the answer is that it happens when someone remembers, that is not in-house administration; it is an intention.

help

What is the single most common thing you find?

expand_more

Accounts belonging to people who left. They persist because deleting one feels irreversible and nobody owns the decision, so each becomes both a licence you are paying for and a credential that still works. The second most common is the mover problem — someone changes role, gains the new access and keeps the old, and over several years accumulates access to almost everything without anyone granting it deliberately.

help

Will you have access to our email?

expand_more

Only the administrative access you grant, and that is a decision you make rather than a condition of the service. Some clients grant a delegated admin role so we can act quickly; some grant access only when there is a specific task; some keep everything in-house and use us for review and advice. All three work. The super-admin accounts remain yours throughout, and every change that removes access or alters policy is yours to approve.

help

What happens to a departing employee's mail and files?

expand_more

The sequence matters more than the individual steps. Suspend the account first, which stops access immediately without destroying anything. Delegate or forward their mail to a named successor for a defined period. Transfer their Drive files to their manager or into the relevant Shared Drive. Remove them from groups, aliases and any delegated access. Only then delete or archive, and only once the transfers are verified. Doing it in the wrong order is how correspondence gets lost, and deleting first is the mistake that cannot be undone after the recovery window closes.

help

Can you take over administration of a tenant somebody else set up?

expand_more

Yes, and it is a large share of what we do. The first piece of work is usually documenting what is actually configured — organisational units, groups, admin roles, sharing policy, connected applications, dormant accounts. That audit is frequently the most valuable part of the engagement, because it turns a system nobody fully understands into one with a written description.

help

How is this priced?

expand_more

Scoped and quoted separately from licences, based on user count and how much of the work you want handled rather than advised on. We quote it as an explicit line rather than folding it into a licence rate, so you can see what it costs and decide whether it is worth it. The requirement call and the quote are free.

Find out how far yours has drifted

Tell us roughly how many users you have and who handles this today. We will go through what is actually configured — dormant accounts, group membership, sharing, connected apps, licence count against your real staff list — and tell you what is worth changing.

  • check_circle

    A written leaver process, so accounts stop accumulating

  • check_circle

    Licence count checked against your actual staff list

  • check_circle

    Groups, aliases and delegated access brought current

  • check_circle

    Your super-admin accounts stay yours throughout

We administer tenants for businesses across Kerala and the rest of India. Or call +91 99467 89916 or email admin@techgeum.com.

call