Access Management: Limit the Google staff who can take support actions related to your data

To use Access Management, you need the Google Workspace Assured Controls Plus add-on. For details, contact your sales representative.

If you purchased Assured Controls and the Assured Support add-on prior to June 17, 2024, you will still have access to Access Management

You can use Access Management for Google Workspace to limit the Google staff who can take support actions related to your organization's data. You can apply Access Management policies to everyone in your organization or set different policies for a department or group. Or, you can use Assured Controls rules to apply restrictions to data based on classification labels.

Available Access Management policies

  • No preference—Does not limit support personnel
  • U.S. Google staff in a U.S. location—U.S. Google staff is defined as U.S. Persons in a physical U.S. location.
  • CJIS-authorized and IRS 1075-authorized Google staff in a U.S. location—This limits support actions to only U.S. persons in a U.S. physical location who have completed appropriate background checks. (Ensure your state has completed onboarding with Google Workspace before using this option. Contact your sales representative for more information.)
  • EU Google staff in EU locations or, if necessary, non-EU Google staff via virtual desktops in EU locations—This limits support actions to EU staff in EU locations. If necessary, non-EU Google staff may access data through virtual desktops that are located in EU locations.

About Google staff access

Requirements for using Access Management

To use the Access Management feature, you need the Google Workspace Assured Controls Plus add-on. To realize the full benefits of Access Management, users assigned to Assured Controls must be on Google Workspace Frontline Plus or Enterprise Plus, as Access Management events are surfaced in the Access Transparency dashboard.

For administrators managing Google Workspace Frontline Plus or Enterprise Plus Edition: Individual organizational units can have users at multiple subscription levels. If you use Access Management and set a policy for specific organizational units, that policy will apply only to users within organizational units that have an Assured Controls Plus license.

Apply an Access Management policy to specific departments or groups

  1. In the Google Admin console, go to Menu and then Data and then Compliance and then Access Management.

    Requires the Assured Controls Plus add-on

    You must be signed in as a super administrator for this task.

  2. Click User-based scoping.
  3. (Optional) To apply the setting only to some users, at the side, select an organizational unit (often used for departments) or configuration group (advanced).

    Group settings override organizational units. Learn more

  4. For Limit support actions on covered data to these personnel, select one of the Access Management policy options.
  5. Click Save. Or, you might click Override for an organizational unit.

    To later restore the inherited value, click Inherit (or Unset for a group).

Apply Access Management policies based on departments, groups & data classification labels

  1. In the Google Admin console, go to Menu and then Data and then Compliance and then Access Management.

    Requires the Assured Controls Plus add-on

    You must be signed in as a super administrator for this task.

  2. For Rule-based scoping, click Assured Controls rules to open the rule creation wizard.
  3. Assign policies based on departments, groups, and data classification labels. For details, go to Assured Controls rules for Access Management & Access Approvals.

Note: Policy conflicts can arise during setup. For details on how they are resolved, go to Policy conflict resolution.