Your Workspace tenant was configured to work, not to be secure. An audit measures the difference.
A read-only assessment of your Google Workspace tenant across admin roles, authentication, sharing, Gmail, OAuth grants, retention, alerting, and devices. You get a scored findings report, a remediation roadmap, and an admin hardening checklist. Remote-first anywhere in India, with on-site walkthroughs available in Hyderabad.

- 5-7 daysAssessment to report
- 70+Control checks
- Read-onlyAuditor access, zero changes
- Remote-firstDelivered across India
Read-only access, no changes, no disruption to your users.
The most common hesitation about a tenant audit is operational: will it break anything, and what are we handing over? The engagement is designed so the honest answer to the first question is nothing.
- You create a dedicated auditor account with read-only reporting privileges. We tell you exactly which delegated role to assign, and we never ask for super admin.
- The assessment reads configuration and reports. It changes no settings, installs nothing, and sends nothing to your users. Nobody outside the IT team should notice it happened.
- The auditor account is yours to suspend or delete the moment fieldwork ends. Access exists only for the days the assessment runs.
- Everything we observe is delivered to a named recipient list under NDA. Findings never leave that circle, and nothing from your tenant is reused anywhere.
Nine areas of your tenant, checked item by item.
Admin roles & super admin hygiene
How many super admins exist, whether they are separated from daily working accounts, whether delegated admin roles are used instead of blanket rights, and whether admin recovery options would survive a departure or a compromise.
2-Step Verification & passkeys
Whether 2SV is enforced rather than merely available, which verification methods are permitted, whether admins and high-value accounts are held to a stronger standard, and where passkeys or security keys can replace weaker factors.
Context-aware access
Whether sign-in policy considers device state, location, and IP context where your edition supports it, and whether the tenant relies on passwords alone for access decisions that deserve more scrutiny.
Drive sharing & external access
Default sharing settings, link-sharing scope, external sharing rules and warnings, files published to the web, shared drive membership, and a count of how much data is currently reachable from outside your domain.
Gmail security: SPF, DKIM, DMARC
Email authentication records checked and their enforcement state verified, plus forwarding rules, legacy IMAP and POP access, spam filter bypasses, and the attachment, link, and spoofing protections Gmail can apply before delivery.
Third-party OAuth app grants
Every application your users have granted access to Gmail, Drive, Calendar, or Contacts, enumerated with the scopes each one holds. Years-old tenants routinely carry grants for apps nobody recognises or still uses.
Vault retention & Alert Center
Whether retention rules and legal holds match your obligations where your edition includes Vault, and whether Alert Center rules are configured, routed to a human, and actually reviewed rather than accumulating unread.
Endpoint management posture
Which devices reach company data, whether mobile management is basic or advanced, whether screen locks and encryption are required, and what happens to synced data when a laptop or phone is lost or an employee leaves.
Licence edition feature gaps
What your current edition can and cannot enforce. Some controls that matter, such as context-aware access or Vault, are edition-gated, and the report separates what to configure now from what needs an edition decision first.
Three deliverables, written to be acted on.
Scored findings report
Every control check recorded with its current state, a severity score, and the evidence behind it. An executive summary up front gives leadership the position in two pages; the appendix gives your admin the detail.
- Per-area scores across all nine assessment areas
- Severity-ranked findings with evidence for each
- What is exposed today, quantified in numbers
- Two-page executive summary for non-technical readers
Remediation roadmap
Findings sequenced by risk reduction against user disruption. Quick, invisible wins first; changes that alter how people collaborate are batched with the communication they need to land without a revolt.
- Low-friction changes separated from disruptive ones
- Effort estimate and owner suggested per item
- 30, 60, and 90 day sequencing
- Edition-gated items flagged for a licence decision
Admin hardening checklist
A working checklist your administrator keeps after the engagement ends: the settings that matter, the state each should be in, and the review cadence that stops the tenant drifting back to where it started.
- Setting-by-setting hardening reference for your tenant
- Quarterly review cadence with named checks
- Joiner and leaver handling steps for Workspace
- Alert Center rules worth enabling and routing
Four reasons teams pick us to look at their tenant.
We run Workspace every day, not just audit it
GR IT deploys, migrates, and administers Google Workspace for businesses in Hyderabad and across India. The audit is informed by what breaks in real tenants, which is why the roadmap separates the changes users will never notice from the ones that need communication.
Evidence-backed, never opinion-backed
Every finding carries the configuration state we observed and where we observed it. Your team can verify each item themselves in the admin console, which makes the report a shared fact base rather than an outside opinion.
Reports both your admin and your board can read
A two-page scored summary for leadership, a full technical appendix for whoever holds the admin role. One engagement, two audiences, no translation work left for you to do in between.
We can fix what we find, but you are not locked in
Remediation is an optional, separately scoped follow-on. The roadmap is written so any competent administrator can execute it, including yours. We would rather earn the follow-on than force it.
How a Workspace audit maps to the frameworks Indian organisations answer to.
| Framework | What it expects | What the audit contributes | |
|---|---|---|---|
| DPDP Act 2023 | Reasonable security safeguards for personal data, and breach notification obligations | Evidence of access control, sharing restrictions, and retention on the tenant where employee and customer personal data actually lives | |
| CERT-In directions | Prompt incident reporting and retention of system logs for a rolling 180 days | Verification that audit logging is intact, Alert Center is routed to a human, and log retention supports an investigation | |
| ISO 27001 | Operating evidence for access control, cryptography, logging, and supplier controls in Annex A | Scored configuration evidence for the cloud collaboration platform, ready to drop into your ISMS evidence pack | |
| SOC 2 | Demonstrated control design and operation across the Trust Services Criteria | Findings and remediation records that show security controls on the productivity suite are designed, applied, and reviewed |
Six situations that prompt a Workspace security review.
Startups that grew into their tenant
A tenant created for five people now serves a hundred and fifty, carrying every default and every quick decision from the early days. Nothing has visibly broken, which is exactly why nobody has looked. Funding rounds and enterprise customers tend to force the look.
Agencies and client-facing teams
Design studios, marketing agencies, and consultancies share heavily with clients by design. The audit distinguishes deliberate external collaboration from files that are simply open to anyone with the link, and quantifies the second category.
Edtech and education on Workspace
Large user populations, student personal data under the DPDP Act, and open collaboration cultures make sharing defaults and group settings unusually consequential. The audit prioritises the controls that protect student data first.
Companies running Workspace alongside Microsoft 365
Mixed estates are common in India, one suite for email and another for files or Teams. Each platform gets audited on its own terms, and we run the Microsoft 365 equivalent as a separate engagement so neither tenant hides behind the other.
Organisations after an incident
A phished mailbox, a forwarding rule discovered months late, files found public that should never have been. The post-incident audit answers what the exposure actually was, what allowed it, and which settings close the path for good.
Teams preparing for DPDP or ISO 27001
Compliance programmes keep asking for evidence about the platform where the personal data actually lives. The audit produces that evidence in a form your consultant or auditor can use directly, before the formal assessment finds the gaps for you.
Where typical tenants stand, and what the audit measures against.
| Feature | Typical tenant Configured once at setup | Hardened baseline What the audit measures against |
|---|---|---|
2-Step Verification | Available, partially adopted | Enforced for all, stronger factors for admins |
Super admin accounts The accounts that control all organisational data. | Several, used for daily work | Minimal count, separated from daily accounts |
Drive link sharing default | Broad, often anyone-with-link | Restricted, external sharing deliberate and warned |
Files published to the web | Unknown count | Enumerated, reviewed, and controlled |
Email authentication | SPF only, or DMARC in monitoring mode | SPF, DKIM, and DMARC at enforcement |
Automatic forwarding & legacy IMAP/POP | Still enabled | Disabled tenant-wide |
Third-party OAuth grants | Accumulating unreviewed for years | Enumerated, trimmed, trusted-app list in place |
Alert Center | Default rules, nobody assigned | Rules tuned, routed to a named owner |
Device access to company data | Any device that signs in | Managed devices, screen lock and wipe enforced |
Review cadence | After incidents, if then | Quarterly, on a written checklist |
Six steps from scoping call to a hardened tenant.
- 1
Scoping
1-2 days
A short call to capture user count, domains, editions in use, whether Microsoft 365 also exists in the estate, and any compliance driver such as DPDP readiness or ISO 27001. You get a written scope and timeline before anything starts.
- 2
Auditor access
Half a day
Your admin creates a dedicated read-only auditor account using the delegated role we specify. No super admin rights, no passwords shared, and the account is yours to suspend the moment fieldwork ends.
- 3
Assessment
3-4 days
We work through the nine areas and 70+ control checks against your live configuration, capturing evidence as we go. Zero settings changed, nothing visible to your users. If we find something critical, you hear about it the same day, not in the report.
- 4
Scored report
1-2 days
Findings are scored, prioritised, and written up as the three deliverables: the scored findings report, the remediation roadmap, and the admin hardening checklist. Internal QA before anything reaches you.
- 5
Walkthrough
1 session
A live read-out with your stakeholders, remote or on-site in Hyderabad. We take questions until the findings are understood, and we are direct about which items are urgent and which merely look dramatic.
- 6
Optional remediation
Scoped separately
If you want us to apply the roadmap, we scope it as a follow-on with explicit change control: low-friction changes first, disruptive changes batched with user communication. Your own team can equally run the roadmap without us.
What a Workspace audit involves, honestly stated.
Across admin, authentication, sharing, Gmail, OAuth, retention, alerting, devices, and licensing.
The same surface every time, so nothing is skipped because it looked fine from the outside.
For most tenants. Multiple domains or very large user counts sit at the longer end.
Scored findings report, remediation roadmap, admin hardening checklist. All yours to keep.
The audit is read-only. Remediation is a separate, explicitly approved piece of work.
A live read-out with your team, on video or in person for Hyderabad organisations.
What organisations ask before booking a Workspace audit.
Twelve questions to ask about your own tenant.
Access & admin
- How many super admins do we have?Most tenants have more than they can name.
- Is 2SV enforced for every account?Enforced, not just available.
- Do admins use passkeys or security keys?A stronger standard for high-value accounts.
- What happens to a leaver account on day one?Sessions, app passwords, and shared files included.
Data & email
- What is our default link-sharing scope?And who decided it.
- How many files are shared outside the domain?A number, not a feeling.
- Are SPF, DKIM, and DMARC all enforcing?DMARC in monitoring mode enforces nothing.
- Is automatic forwarding disabled?The classic persistence trick after a mailbox compromise.
Oversight
- When were OAuth app grants last reviewed?They accumulate silently for years.
- Who reads the Alert Center?Alerts nobody reads are decoration.
- Do retention rules match our obligations?Where your edition includes Vault.
- Can an unmanaged personal device sync company data?For most tenants, yes.
The engagements around this one.
Cybersecurity Audit & Compliance
The broader engagement: penetration testing, framework gap analysis, and certification support across ISO 27001, SOC 2, and CERT-In alignment.
Learn moreMicrosoft 365 Security Audit India
The same exercise on the other platform. If you run a mixed estate, audit both tenants on their own terms.
Learn moreManaged IT Services India
Continuous ownership of your IT after the audit: monitoring, patching, user support, and a 30-minute response SLA for managed clients.
Learn moreFind out what your Workspace tenant actually looks like.
A three-minute form and a short scoping call. We reply within 4 business hours, and the assessment itself changes nothing and disrupts nobody. Remote-first across India, on-site walkthroughs in Hyderabad.
Related Services
Explore more solutions that work great with this service