top of page

Google Workspace Security for Small Businesses: What Should Actually Be Configured?

Sep 1
21 min read
Google Workspace security for small businesses covering Gmail security, Drive sharing, user access, Gemini security and device management

Google Workspace can become the center of a small business surprisingly quickly. Gmail handles company email. Google Drive becomes the place employees store and share documents. Docs and Sheets support day to day work. Calendars coordinate schedules. Phones and laptops remain connected to company information wherever employees happen to be working. Third party applications get connected through Google accounts, and now Gemini is becoming another part of that environment.


When everything works every day, it is easy to assume the environment must also be configured correctly.

Those are not the same thing.


A Google Workspace subscription gives a business access to identity, email, file sharing, administrative, device management, security, retention and increasingly AI controls. The capabilities available are not identical across every Google Workspace edition, and many of them still need to be deliberately configured, enforced, reviewed or maintained.


A company may have been using Google Workspace successfully for five years while still relying on many of the same security decisions that were made when it had three employees. Since then, people may have joined and left, files may have been shared outside the business, new applications may have been authorized, additional devices may have been connected and Google may have added capabilities that were never reviewed.


That is why Google Workspace security for small businesses should be treated as part of the overall IT environment, not simply as a question of whether Gmail and Google Drive are working.

“Google Workspace security is not about turning on every setting. It is about knowing who can access what, how company data is being shared, which controls your licensing actually includes and whether the configuration still matches the way your business operates.” — SNL-Tech Services

Is 2 Step Verification Actually Enforced?

One of the first things I want to understand in a Google Workspace environment is how employees authenticate.


There is an important difference between allowing employees to use 2 Step Verification and actually requiring it. If a business has ten employees and eight voluntarily configured a second authentication method, the remaining accounts may still depend primarily on passwords unless another control protects them.


Google requires 2 Step Verification for administrator accounts and gives Workspace administrators the ability to enforce it more broadly for users. Google supports several authentication methods, including security keys, Google prompts, authenticator applications and passkeys.


For a small business, I am less interested in whether someone can show me a screen saying 2 Step Verification is available than whether the protection is actually being enforced for the people who need it. Administrator accounts deserve particular attention, along with owners, financial users, people who can change payment information and employees with access to sensitive business or customer data.


Deployment and recovery matter too. A business should not discover during an emergency that its only administrator is locked out, recovery information is outdated or the person who originally controlled Google Workspace is no longer available.

That leads into another question that is just as important.


Who Actually Controls Google Workspace?

A surprisingly useful question for a small business owner is simply:

Who has administrator access to our Google Workspace environment?

Super Administrator access is powerful. It can affect users, applications, authentication, security settings, billing and the overall Workspace environment. That does not mean everyone who occasionally needs to perform an administrative task should have unrestricted control of the entire environment.


Google provides predefined and custom administrator roles so responsibilities can be assigned more narrowly. Someone who needs to manage users, for example, may not necessarily need every privilege available to a Super Administrator.


I also want the business itself to understand who ultimately controls the environment. If an outside IT provider, former employee, consultant or original business partner created Google Workspace, ownership and administrative access should not depend entirely on that person remaining available indefinitely.


This is not only a cybersecurity issue. It is also a technology ownership and business continuity issue.


If an employee leaves tomorrow, the company should know who can secure the account. If a domain or security setting needs to be changed, someone should know who has the authority and access to do it. If an IT provider relationship ends unexpectedly, the business should still maintain control of its own Google Workspace environment.


Should Company Files Be in My Drive or Shared Drives?

This is one of the most important Google Workspace questions for a growing small business.


My Drive is closely associated with an individual user's Workspace account. That can make sense for drafts, personal working documents and information that genuinely belongs in an employee's individual workspace.


Company information is different.


Google Shared drives are designed so the files belong to the organization rather than the individual employee who created them. If an employee leaves, information stored in an appropriately configured Shared drive remains with the organization instead of depending on the departing employee's account.


I tend to look at this as a business ownership question rather than simply a file organization question. If an employee creates an important client spreadsheet, project folder, operating procedure or contract document, does that information belong to the employee or to the business?


In most cases, the business needs continued access regardless of who originally created the information.


Shared drives give a company a clearer way to establish organizational ownership while still controlling which employees or departments can reach the information.

The structure still matters. Creating one Shared drive called Company Files and giving every employee access to everything does not solve an access control problem. A business may need different areas for accounting, management, human resources, operations, client work or other information based on who actually needs access.

The goal is not to create dozens of complicated Shared drives.

The goal is to make company ownership and employee access intentional.


Who Can Share Google Drive Files Outside the Business?

Small businesses need to collaborate with people outside their organization. Accountants may need financial documents. Attorneys may need contracts. Clients may need project information. Vendors, contractors and other professional advisers may need access to specific files.


The answer is usually not to block every form of external sharing.


The better answer is to understand and control it.


Google Workspace administrators can control external Drive sharing, and Shared drives can have additional restrictions. Depending on the environment and licensing, organizations can establish different sharing rules for different groups of users and place more restrictive controls around information that should not be broadly shared.


When SNL-Tech Services reviews an environment, I want to understand what employees are allowed to share, who can initiate external sharing, what information has already been shared outside the organization and whether those decisions still make sense.


A document shared with a contractor two years ago may still be accessible today even though the project ended eighteen months ago.


That type of access can accumulate quietly. Nothing appears broken. Employees continue working normally. The business simply loses visibility into who can still reach its information.

For organizations that collaborate extensively with outside parties, the goal should be a sharing model that allows legitimate work without giving every employee unrestricted control over company data.


Is Gmail Properly Protecting the Business Domain?

Google provides substantial Gmail security capabilities, but the Workspace Admin console is only part of protecting business email.


The company's domain should also have appropriate email authentication configured.

SPF helps identify systems authorized to send email using the business domain. DKIM digitally signs outgoing messages so receiving mail systems can validate that the message came from an authorized source. DMARC builds on SPF and DKIM and gives the domain owner a policy for how receiving mail systems should handle messages that fail authentication.


The important part for a small business is that email may come from more places than Google Workspace.


A website contact form, accounting platform, CRM, marketing application, ticketing system, scheduling platform or another cloud service may also send messages using the company's domain.


Email authentication therefore needs to reflect the entire sending environment.

DMARC should also be implemented deliberately. The objective is not to copy a DNS record from an online article, immediately move to the most restrictive policy and hope nothing legitimate stops working. The business first needs to understand which systems are legitimately sending mail using its domain.


Forwarding and routing deserve attention as well because configurations can remain in place long after anyone remembers why they were originally created.


A Google Workspace environment can therefore appear to be functioning perfectly from an employee's perspective while the business still has no clear understanding of how its domain, authentication, forwarding or administrative mail settings are configured.


What Third Party Applications Have Access to Google Workspace?

This is one of the areas I expect to become increasingly important as small businesses adopt more cloud applications, automation tools and AI platforms.


Employees frequently use Sign in with Google or authorize applications to interact with Gmail, Drive, Calendar or other Workspace information. The application may have been useful when it was originally authorized, but several years later nobody remembers why it was approved or what information it can still reach.


Google Workspace provides API controls that allow administrators to review applications that have accessed Workspace data and determine how those applications should be treated.


That does not mean third party applications are inherently unsafe. Many are legitimate products the business intentionally needs.


The problem is not knowing what is connected.


A connected application can sometimes continue to have access long after an employee has stopped actively using it. This is particularly important with AI, automation and productivity tools because much of their value comes from connecting them directly to Gmail, Drive, Calendar and other Workspace information.


A business should know which applications have been approved, which employees authorized them, what information those applications can access and whether that access

is still necessary.


Blocking one AI platform does not solve this problem either.


A company could carefully configure Gemini while still allowing employees to authorize unrelated AI applications to access Google Drive.


That is one reason broader AI use, approved platforms, employee accounts and data handling are addressed through an AI Governance Assessment from SNL-Tech Services rather than treating every AI concern as simply a Google Workspace setting.


What About Employee Computers, Phones and Personal Devices?

Google Workspace is cloud based, but the devices accessing it still matter.

Employees may be reaching company Gmail, Drive and other Workspace information from company computers, personal laptops, smartphones, tablets and other devices depending on how the environment is configured.


Google provides mobile and endpoint management capabilities, but the available controls vary by Workspace edition. Some businesses may need relatively simple visibility and account controls, while others may need stronger device management, compliance requirements and restrictions around how company information is accessed.


A small professional office may not need the same device controls as a healthcare organization, financial services business, government contractor, law firm or company handling particularly sensitive customer information.


The important part is that the business makes the decision intentionally.

If company information is routinely downloaded to unmanaged personal computers, securing Google Workspace alone does not solve the entire problem.

Cloud security and device security are connected.


Can You See What Is Happening Inside Google Workspace?

Preventive controls matter, but visibility matters too.

Google Workspace provides administrative and activity information that can help a business understand what has occurred inside the environment. The exact reporting, alerting, investigation and security capabilities available depend on the Workspace edition.


The question I ask is not simply:

Does Google keep logs?

The more useful question is:

If something happened tomorrow, would anyone know where to look?


Imagine that an employee account becomes compromised. Could someone determine whether files were accessed or shared? Could the business review important administrator changes? Would anyone know where the appropriate information is located? Does anyone receive or review meaningful security alerts?


Logging that nobody knows exists provides much less practical value than logging connected to a documented response process.


This is where technology configuration begins to overlap with Incident Response Planning from SNL-Tech Services. The logs may provide important technical information, but the business still needs to know who investigates, who gets contacted, who has authority to make decisions and what happens next.


Does Google Workspace Back Up My Data?

This question deserves more than a simple yes or no answer.

Google provides native recovery, retention, availability and data management capabilities. Depending on the Workspace edition, businesses may also have tools such as Google Vault for retention and eDiscovery.


Those capabilities are useful.


They should not automatically be treated as identical to an independent backup and recovery strategy.


Consider a business that relies heavily on a Shared drive for active client work. An employee accidentally deletes a collection of important files, and nobody notices immediately.


The useful question is no longer whether Google has redundant infrastructure somewhere in its environment.


The business needs to know whether those particular files can be recovered, how far back recovery can go, how quickly the information can be restored, what happens if the deletion is discovered later and who actually knows how to perform the recovery.

The same issue applies to malicious deletion, compromised accounts, overwritten information or the need to restore data from a much older point in time.


For some small businesses, Google's native capabilities may meet the recovery requirements they have established. Another organization may decide that an independent

Google Workspace backup platform provides longer recovery history, additional separation, more granular restore options or a recovery model that better fits the business.

The right answer depends on the recovery requirement.


It should not be based on a blanket statement that every Google Workspace customer either does or does not need an additional backup.


What Happens When an Employee Leaves?

Employee offboarding is where several Google Workspace configuration decisions suddenly become connected.


The departing employee's account needs to be secured. Administrative privileges may need to be removed. Devices and active sessions may require attention. Email needs to be handled appropriately. Company files need to remain accessible. External sharing and connected applications may need to be reviewed.

A practical Google Workspace offboarding process may need to address:

  • Securing or suspending the departing employee's account

  • Removing administrative roles and unnecessary privileges

  • Reviewing active sessions and managed devices

  • Transferring important information stored in My Drive where appropriate

  • Confirming that company information stored in Shared drives remains accessible to the correct employees

  • Deciding how incoming email should be handled

  • Reviewing external file sharing

  • Reviewing third party applications and OAuth access

  • Changing shared credentials if the business still has any shared account practices

  • Documenting who becomes responsible for the employee's files, projects and business information

Shared drives make one part of this process much easier because company information stored there remains with the organization rather than depending on the departing employee's account.


The exact offboarding process will vary by business, but having it documented ahead of time is much better than determining all of it on an employee's final afternoon.

Offboarding is also one of the reasons administrator ownership, Shared drives and third party application visibility matter so much. Those settings may seem unrelated during normal operations, but they all become connected when someone leaves.


Does My Google Workspace Edition Include the Security Features I Think It Does?

This is another area where assumptions create problems.

Google Workspace Business Starter, Business Standard and Business Plus do not contain identical storage, endpoint management, retention, security and administrative capabilities. Google also continues to expand Gemini capabilities while reserving some more granular security and management features for particular higher tier editions.


I would not recommend that a small business try to memorize Google's entire licensing matrix because plans and included capabilities change over time.

What matters is understanding why licensing should be part of the security review.

Area

Why the Google Workspace Edition Matters

Authentication and identity

Available administrative and security capabilities can differ

Device management

More advanced endpoint controls are available in higher editions

Retention and eDiscovery

Google Vault availability depends on the Workspace edition

Security investigation

More advanced investigation capabilities are limited to certain editions

Data protection

Security and information protection features vary by subscription

Gemini and AI

AI capabilities and the granularity of administrative controls vary by edition

This is why SNL-Tech Services does not start a Google Workspace review by assuming every business needs a more expensive subscription.


The first question is what the business is actually trying to protect and manage.

Sometimes the right answer is simply configuring security capabilities the company is already paying for.


Other times there is a legitimate licensing limitation that needs to be considered before a particular retention, device management, security or AI control can be implemented.


Gemini Changes the Google Workspace Security Conversation

Gemini deserves more attention than simply asking whether employees are allowed to use AI.

Google has integrated Gemini much more deeply into Workspace, which means AI can interact with Gmail, Drive, Docs, Calendar, Chat and other company information depending on the user's permissions, Workspace edition and administrative configuration.

That makes the existing Google Workspace permission model more important, not less important.


It also means a small business should stop thinking about Gemini as one simple On or Off setting.

There are several administrative controls that affect different parts of the Gemini experience.


How Can a Small Business Control Gemini in Google Workspace?

One control is access to the Gemini app itself.

A Google Workspace administrator can control whether managed users can access the Gemini app and can apply different access settings to organizational units or configuration groups.


There is an important distinction.


Turning off the Gemini app does not automatically turn off Gemini features that may exist inside Gmail, Docs, Drive and other Google Workspace applications.

Google treats the Gemini app and Gemini functionality embedded within Workspace as different control areas.


A business could therefore believe it has disabled Gemini because employees cannot access the Gemini app while AI capabilities may still be available inside Workspace services depending on the organization's licensing and configuration.


Another important layer is Workspace Intelligence.

Google's current Workspace controls allow administrators on supported Business and Enterprise editions to decide whether Gemini can actively search particular Workspace data sources for additional context.

Those sources include:

  • Gmail

  • Drive and Docs

  • Calendar

  • Chat

This gives a small business a meaningful choice.

For example, the organization could allow employees to use certain Gemini capabilities while preventing Workspace Intelligence from actively searching Gmail or Drive and Docs for additional information.


There is an important limitation.


Turning off Drive and Docs as a Workspace Intelligence data source does not necessarily mean Gemini can never use Drive content.


If an employee specifically references a file the employee already has permission to access, Gemini may still be able to use that file. If the employee already has a Google document open and asks Gemini about the active document, that document may still provide context. That distinction matters.


The setting controls active search across the data source.

It does not remove the employee's underlying permission to the information.

Google also provides a separate control over whether the Gemini app can connect back into Workspace services such as Gmail, Drive and Calendar.

The major control layers can therefore be thought about this way:

Google Workspace AI Control

What It Controls

What It Does Not Automatically Control

Gemini app access

Whether selected users can access the Gemini app with their managed Workspace account

Gemini functionality that may appear inside Gmail, Docs, Drive and other Workspace services

Workspace Intelligence

Whether Gemini actively searches Gmail, Drive and Docs, Calendar or Chat for additional context

Specific information the employee already has permission to access and deliberately references

Gemini app connections

Whether the Gemini app can connect back into Workspace services such as Gmail, Drive and Calendar

Other AI or third party applications connected through Google OAuth

Workspace permissions

Which files, emails and other information an employee is permitted to access

Whether those permissions are still appropriate for that employee

AI governance policies

What employees are allowed to do with AI and which tools are approved

The technical configuration inside Google Workspace

This is why I would not treat Gemini as one security setting.


A business could block the Gemini app while still allowing Gemini inside Workspace. It could allow Gemini but prevent Workspace Intelligence from actively searching Gmail or Drive. It could carefully configure Google's AI controls while employees are still allowed to connect another AI platform to company information through OAuth.

The controls work, but they solve different problems.


Do Gemini's Controls Actually Work?

Yes, within the boundaries they are designed to enforce.

The critical concept is that Gemini does not create an entirely separate permission system.

If an employee does not have permission to access a particular company file, enabling Gemini does not simply grant the employee access to that file.

The more important risk is the opposite situation.


Imagine an employee changed responsibilities three years ago but nobody removed access to a Shared drive containing information that employee no longer needs.

Without Gemini, that is already an access control problem.


Now imagine AI can help that employee search, summarize and connect information across the environment much more efficiently.

Gemini did not have to break a security control.

The employee already had access.

AI simply made that access more useful.


That is why configuring Gemini should never be treated as a substitute for reviewing existing permissions.

Gemini does not fix overly broad Google Workspace permissions. AI can make the consequences of those permissions more visible because employees can find and summarize information much more efficiently.

Before expanding Gemini, I would want the business to understand its Drive structure, Shared drive membership, external sharing, administrative access, inactive accounts and third party application access.


What About More Granular Gemini Controls?

Google currently gives certain higher tier Workspace editions more granular controls over where Gemini features appear.


For example, supported Enterprise editions can provide administrators with individual controls over Gemini functionality in Workspace services such as Gmail, Calendar, Drive, Docs, Sheets, Slides, Meet and Chat.


That level of control should not be confused with the Workspace Intelligence data source controls available to supported Business editions.

Even Google's more granular controls illustrate why the terminology matters.

Turning off a Gemini feature inside an application is not necessarily the same thing as restricting that application's data as an AI source.

Restricting the data source is not the same thing as correcting the employee's underlying file permissions.


Businesses should therefore evaluate Gemini controls based on the Google Workspace edition they actually use instead of assuming that every setting described in Google's documentation is available with every Business subscription.


Controlling Gemini Does Not Control Every AI Tool

This distinction is important enough that it should be addressed in the business's AI policy.

A company can carefully configure Gemini and still have employees using ChatGPT, Claude, another AI assistant, browser extensions, meeting transcription tools, automation platforms or applications that connect to Google Workspace through OAuth.

Gemini administration addresses Google's AI environment.

It does not establish the entire AI governance program for the business.


The organization still needs to decide which AI tools are approved, whether personal AI accounts are appropriate for business use, what company information employees may enter into prompts, which applications may connect to Google Workspace and when AI generated work requires human review.


The Google Workspace Audit focuses on the Google environment and the technical controls available within it. The AI Governance Assessment looks more broadly at AI tools, accounts, company information, workflows, policies and employee use across the business.


What Should Be Reviewed Before Expanding Gemini?

Before deeper AI adoption inside Google Workspace, I would want a small business to review at least the following areas:

  • Users and administrator access: Confirm who has access to Workspace and who still needs elevated privileges.

  • Shared drive membership: Make sure employees are not carrying unnecessary access forward from old roles or completed projects.

  • My Drive versus company owned information: Understand where important business information actually lives.

  • External sharing: Review company information already shared with people outside the organization.

  • Gemini app access: Decide which employees actually need access to the Gemini app.

  • Workspace Intelligence sources: Decide whether Gemini should actively search Gmail, Drive and Docs, Calendar and Chat.

  • Gemini app connections: Determine whether the Gemini app should connect back into company Gmail, Drive, Calendar and other services.

  • Third party applications: Review OAuth access so another AI product does not have broad access while Gemini itself is tightly controlled.

  • Devices: Understand which computers and mobile devices employees use to access company information.

  • AI acceptable use: Document what employees are allowed to do with AI, what information should not be entered into AI systems and where human review is required.

The purpose is not to make AI unnecessarily complicated. It is to apply the same principle that should be used when connecting any powerful new business application to company information. Understand the environment first. Then decide how the technology should fit into it.


A Practical Google Workspace Security Review Checklist

If I were sitting down with a small business owner and trying to determine whether Google Workspace had ever really been reviewed, these are some of the questions I would start with:

  1. Is 2 Step Verification actually enforced for employees?

  2. Who has Super Administrator access?

  3. Is there appropriate administrative redundancy?

  4. Are former employees and unnecessary accounts still present?

  5. Is company owned information stored in Shared drives where appropriate?

  6. Are Shared drive permissions based on employees' current responsibilities?

  7. What information is currently shared outside the organization?

  8. Are SPF, DKIM and DMARC configured correctly for every legitimate system sending company email?

  9. Which third party applications have access to Gmail, Drive, Calendar or other Workspace information?

  10. What personal or unmanaged devices are accessing company data?

  11. Does anyone review security alerts and relevant activity information?

  12. Does the business know exactly how it would recover important Gmail or Drive information?

  13. Does the current Google Workspace edition provide the security and management controls the business expects?

  14. How are departing employees removed and their information transferred?

  15. Is Gemini enabled?

  16. Which Workspace information can Gemini actively search?

  17. Can the Gemini app connect back into company Workspace information?

  18. Are employees using other AI platforms outside Google's controls?

  19. Does the business have an AI acceptable use policy?

  20. When was the last time any of these settings were actually reviewed?

A business does not necessarily need a major technology overhaul because one of these questions produces an uncomfortable answer.


Sometimes the solution is fixing an old permission, enforcing a security setting, removing an unused application, moving company information into the appropriate location or documenting a process that was previously handled informally.

The first step is understanding what actually exists.


Google Workspace Working Does Not Mean Google Workspace Has Been Reviewed

A business can use Google Workspace successfully for years without ever having someone step through the environment and ask whether the original configuration still makes sense.


Employees get added. Employees leave. Files accumulate. External sharing expands. More applications are connected. Licensing changes. Google releases new security capabilities. Gemini becomes part of the environment.


Nothing has to be obviously broken for the configuration to deserve a review.

A Google Workspace Audit from SNL-Tech Services is designed to document how the environment is currently configured and review areas such as Gmail security, identity and administrator access, 2 Step Verification, Google Drive and Shared drives, external sharing, third party applications, device access, logging, retention, licensing and Gemini related controls that are relevant to the Workspace edition and business environment.

If Google Workspace is only one part of a larger technology environment that the business does not clearly understand, an IT Baseline Assessment from SNL-Tech Services may be a better starting point.


If the primary concern is whether technical security controls match what the business is being asked during a cyber insurance application or renewal, the Cyber Insurance Readiness Assessment from SNL-Tech Services addresses that question more directly.

The goal is not to make every Google Workspace environment identical.

The goal is to understand what your business has, what it actually needs and whether the technology is configured to support it.


Google Workspace Security FAQs

Is Google Workspace secure enough for a small business?

Google Workspace provides substantial identity, email, file sharing, administrative, device and security capabilities. The fact that those controls exist does not automatically mean every relevant control has been configured or that the configuration matches the way the business operates.

The appropriate security setup depends on the Workspace edition, users, devices, information being stored, sharing requirements and the risks the business is trying to manage.


Should every employee have 2 Step Verification?

For most businesses, employee accounts should be protected by more than a password. Google provides the ability to enforce 2 Step Verification and requires it for administrator accounts.

The exact authentication method may vary, but the important part is knowing whether the requirement is actually enforced rather than assuming employees voluntarily enabled it.


How many Google Workspace Super Administrators should a small business have?

There is no single number that is right for every business, but the organization should avoid both extremes.

Giving many users unrestricted Super Administrator access creates unnecessary privilege. Depending entirely on one administrator creates a different business continuity risk.

Google supports more limited administrator roles for many routine tasks, which can help reduce unnecessary unrestricted access.


Should company files be stored in Shared drives?

Information that belongs to a team or to the business is often a good candidate for Shared drives because Shared drive content belongs to the organization rather than an individual employee.

My Drive can still be appropriate for individual working files. The important part is intentionally deciding which information belongs to the company and who should have access.


Can Google Workspace administrators control external sharing?

Yes.

Google Workspace provides administrative controls over external Drive sharing, and Shared drives can have additional restrictions.

The right configuration should balance collaboration with clients, vendors and outside advisers against the need to keep company information appropriately controlled.


Can administrators block third party applications from accessing Workspace data?

Yes.

Google Workspace provides API controls that allow administrators to review and control applications that request access to Google Workspace information.

This is increasingly important as businesses adopt more automation and AI applications that request direct access to Gmail, Drive, Calendar and other company services.


Does Google Workspace include backup?

Google provides native recovery, retention, export and availability capabilities, and certain Workspace editions include Google Vault.

Those capabilities are not automatically the same as an independent backup strategy.

A business should determine how far back information may need to be recovered, how quickly recovery needs to happen and whether Google's native capabilities meet those requirements.


If I turn off the Gemini app, is Gemini completely disabled?

Not necessarily.

The Gemini app and Gemini functionality inside Google Workspace are controlled separately. Turning off access to the Gemini app does not automatically remove Gemini features from Gmail, Docs, Drive or other Workspace services where those capabilities are available.


Can I stop Gemini from searching company email and files?

For supported Workspace editions, administrators can use Workspace Intelligence settings to control whether Gemini actively searches Gmail, Drive and Docs, Calendar or Chat as contextual data sources.

That does not necessarily prevent a user from asking Gemini about a specific document or information that the user already has permission to access.


Can Gemini see files an employee normally cannot access?

Gemini does not create a separate permission system that automatically gives an employee access to restricted Workspace information.

The bigger concern is whether the employee's existing permissions are appropriate. If someone already has access to information they no longer need, AI can make locating and summarizing that information much easier.


Does controlling Gemini solve AI governance for a small business?

No.

Gemini controls govern Google's AI environment. Employees may still use other AI platforms or connect third party applications to Workspace information.

A broader AI governance process should address approved tools, accounts, company information, employee use, integrations, policies and human review.


Can a Google Workspace Audit help with cyber insurance?

A technical review can help document controls such as 2 Step Verification, administrative access, email security, device protections, sharing and logging that may be relevant during cyber insurance discussions.

When the primary goal is evaluating the technology behind questions on an insurance application or renewal, SNL-Tech Services also offers a Cyber Insurance Readiness Assessment.


Does a Google Workspace Audit certify compliance?

No.

A technical review can identify and document controls that may relate to regulatory, contractual, customer or insurance requirements, but it does not make a legal determination or certify that a business complies with a particular law or regulation.


Related SNL-Tech Services Resources

Review Gmail security, administrator access, Google Drive and Shared drives, external sharing, third party applications, device controls, licensing, logging, Gemini settings and other relevant areas of your Workspace environment.


Review the AI tools, accounts, company information, workflows, policies and controls surrounding AI use in your business.


Establish a documented understanding of the broader IT environment when Google Workspace is only one part of the technology your business relies on.


Review and document technical controls that may be relevant to a cyber insurance application or renewal.


Build a practical incident response plan around your technology, employees, vendors, responsibilities, communications and recovery priorities.



Additional Resources

Comments


bottom of page