Google Workspace logo

Google Workspace

AccessPeople
Access & Identity

Mycroft reads Google Workspace users, groups and admin roles to build the account inventory behind access reviews.

For companies without a separate identity provider, Workspace is where accounts are created and suspended, which makes it the workforce source of truth. 2-Step Verification enrolment, sharing settings and third-party OAuth grants are all tested.

How Mycroft connects to Google Workspace

How it connects
A super administrator authorizes Mycroft through Google OAuth against your Workspace domain.
What Mycroft can access
Read-only directory scopes for users, groups and role management, the read-only reports usage scope, and admin.directory.user.security, which Google uses for per-user security settings such as two-step verification state. Mycroft runs a pull model and does not write back.

Which controls Google Workspace evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Google Workspace to satisfy it. Collection runs on a schedule and every result is timestamped.

Google Workspace compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Google Workspace
SOC 2CC6.1Logical access controls restrict access to information assets.User, group and organizational unit inventory with admin role assignments and per-user 2-Step Verification enrollment.
SOC 2CC6.2Access is authorized before issuance and reviewed periodically.Account creation records matched to HRIS hire dates, plus the completed access review with reviewer decisions for every account.
SOC 2CC6.3Access is removed when no longer required.Suspension and deletion events with timestamps, reconciled against the HRIS termination date and the removal of downstream system access.
SOC 2CC6.7Transmission and movement of information is restricted.Drive external sharing settings per organizational unit, link-sharing defaults, and the inventory of third-party OAuth applications granted domain access.
ISO 27001A.5.16Identity management covers the identity lifecycle.Account status history (created, suspended, archived, deleted) with timestamps for every identity in the domain.
ISO 27001A.5.17Authentication information is managed securely.2-Step Verification enforcement policy per organizational unit, enrollment state per user, and password strength and reuse settings.
ISO 27001A.8.2Privileged access rights are restricted.Super administrator and delegated admin role holders with their 2-Step Verification state and last sign-in.
ISO 27001A.5.14Information transfer rules and controls are in place.Domain sharing configuration, allowed external domains, and Drive link-sharing defaults per organizational unit.
HIPAA§164.308(a)(3)Workforce access is authorized, supervised and terminated appropriately.Roster with employment status and suspension timestamps, matched to HR termination dates for every departure.
HIPAA§164.312(a)(2)(i)Unique user identification is assigned.Account inventory with shared, generic and role mailboxes flagged so they are handled as documented exceptions.

What Mycroft collects automatically

Gathered from Google Workspace on a schedule, dated and stored against the controls above.

  • User roster with suspension state, organizational unit, groups and last sign-in
  • 2-Step Verification enforcement policy and per-user enrollment
  • Super administrator and delegated admin role holders
  • Password policy: minimum length, reuse restrictions and enforcement
  • Drive external sharing and link-sharing defaults per organizational unit
  • Third-party OAuth applications granted access to the domain, with their scopes
  • Group membership and external members in groups
  • Account suspension and deletion timestamps for offboarding evidence

Manual work this removes

The tasks that disappear from someone's quarter once Google Workspace is connected.

  • Exporting the user list each quarter and distributing it to managers
  • Checking 2-Step Verification enrolment user by user
  • Reviewing which third-party applications hold domain-wide access
  • Confirming from admin logs that a leaver's account was suspended in time
  • Re-capturing sharing settings for each audit

Google Workspace and Mycroft: frequently asked questions

No. The Workspace connection is granted directory scopes only: read-only access to users, groups and role management, the read-only reports usage scope, and admin.directory.user.security for per-user security settings such as two-step verification state. There is no Gmail, Drive, Calendar or Chat scope.
For many small and mid-sized companies, yes. If Workspace is where accounts are created, where the second factor is enforced and what gets suspended on someone's last day, it is your identity source of truth and Mycroft treats it as such, supplying both the account inventory for access reviews and the workforce roster for personnel controls.
Through the suspension timestamp. Mycroft compares it to the termination date in your HRIS and to the removal time of every downstream account, producing a measured offboarding interval per departure. That is the number an auditor asks for under SOC 2 CC6.3 and HIPAA §164.308(a)(3)(ii)(C).
Because a marketplace add-on granted domain-wide Drive access is a data processor with standing access to your files, and it rarely appears in anyone's vendor register. Pulling the grant list turns a blind spot into a reviewable control under SOC 2 CC9.2 and ISO 27001 A.5.19.

We turn the compliance nightmare into a dream

Talk to us