
Google Workspace
AccessPeople
Access & Identity
Mycroft reads Google Workspace users, groups and admin roles to build the account inventory behind access reviews.
For companies without a separate identity provider, Workspace is where accounts are created and suspended, which makes it the workforce source of truth. 2-Step Verification enrolment, sharing settings and third-party OAuth grants are all tested.
How Mycroft connects to Google Workspace
- How it connects
- A super administrator authorizes Mycroft through Google OAuth against your Workspace domain.
- What Mycroft can access
- Read-only directory scopes for users, groups and role management, the read-only reports usage scope, and admin.directory.user.security, which Google uses for per-user security settings such as two-step verification state. Mycroft runs a pull model and does not write back.
Which controls Google Workspace evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Google Workspace to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Google Workspace |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | User, group and organizational unit inventory with admin role assignments and per-user 2-Step Verification enrollment. |
| SOC 2 | CC6.2 | Access is authorized before issuance and reviewed periodically. | Account creation records matched to HRIS hire dates, plus the completed access review with reviewer decisions for every account. |
| SOC 2 | CC6.3 | Access is removed when no longer required. | Suspension and deletion events with timestamps, reconciled against the HRIS termination date and the removal of downstream system access. |
| SOC 2 | CC6.7 | Transmission and movement of information is restricted. | Drive external sharing settings per organizational unit, link-sharing defaults, and the inventory of third-party OAuth applications granted domain access. |
| ISO 27001 | A.5.16 | Identity management covers the identity lifecycle. | Account status history (created, suspended, archived, deleted) with timestamps for every identity in the domain. |
| ISO 27001 | A.5.17 | Authentication information is managed securely. | 2-Step Verification enforcement policy per organizational unit, enrollment state per user, and password strength and reuse settings. |
| ISO 27001 | A.8.2 | Privileged access rights are restricted. | Super administrator and delegated admin role holders with their 2-Step Verification state and last sign-in. |
| ISO 27001 | A.5.14 | Information transfer rules and controls are in place. | Domain sharing configuration, allowed external domains, and Drive link-sharing defaults per organizational unit. |
| HIPAA | §164.308(a)(3) | Workforce access is authorized, supervised and terminated appropriately. | Roster with employment status and suspension timestamps, matched to HR termination dates for every departure. |
| HIPAA | §164.312(a)(2)(i) | Unique user identification is assigned. | Account inventory with shared, generic and role mailboxes flagged so they are handled as documented exceptions. |
What Mycroft collects automatically
Gathered from Google Workspace on a schedule, dated and stored against the controls above.
- User roster with suspension state, organizational unit, groups and last sign-in
- 2-Step Verification enforcement policy and per-user enrollment
- Super administrator and delegated admin role holders
- Password policy: minimum length, reuse restrictions and enforcement
- Drive external sharing and link-sharing defaults per organizational unit
- Third-party OAuth applications granted access to the domain, with their scopes
- Group membership and external members in groups
- Account suspension and deletion timestamps for offboarding evidence
Manual work this removes
The tasks that disappear from someone's quarter once Google Workspace is connected.
- Exporting the user list each quarter and distributing it to managers
- Checking 2-Step Verification enrolment user by user
- Reviewing which third-party applications hold domain-wide access
- Confirming from admin logs that a leaver's account was suspended in time
- Re-capturing sharing settings for each audit
Google Workspace and Mycroft: frequently asked questions
Does Mycroft read our Gmail or Google Drive contents?
Can Google Workspace replace a dedicated identity provider for compliance?
How does Workspace evidence offboarding?
Why does Mycroft inventory third-party OAuth apps?
We turn the compliance nightmare into a dream
Talk to us


