To use Assured Controls Rules with Access Approvals, you need the Google Workspace Assured Controls or Assured Controls Plus add-on. To use this rule with Access Management, you need the Google Workspace Assured Controls Plus add-on. For details, contact your sales representative.
As an administrator, you can use Assured Controls rules to require Google staff to get approval or meet location and credential requirements before accessing your organization’s data. Creating a rule allows you to specify policies for data based on their classification labels. You can use rule-based policies for data instead of applying a single policy to your entire organization or a department or team.
Key benefits of rule-based policies
- Targeted support protection—By using classification labels, you apply policies only to the specific data that needs it. This targeted approach protects sensitive data without unnecessarily slowing down support-resolution times.
- Centralized management—You can apply both Access Management and Access Approvals protections at the same time. This joint enforcement keeps your settings in sync and allows you to update policies in one place, reducing the potential for errors compared to managing separate policies. For details, go to Access Management or Access Approvals.
About resource owner scope
Rules protect data based on who owns the resource (the user account or shared drive), not who accesses it. If you restrict a rule to a specific department or group, the restrictions apply strictly to data owned by users or shared drives within that department or group.
Create a rule
-
In the Google Admin console, go to Menu
Rules
Create rule
Assured Controls.
You must be signed in as a super administrator for this task.
- For Select actions, check any of the following boxes:
- To limit which Google staff can take support actions based on their location and credentials, check the Apply Access Management policy box.
- To require admin approval before Google staff can take support actions, check the Apply Access Approvals policy box.
- Click Next.
- For Configure actions, configure the settings for your selected policies:
- For Apply Access Management policy, select which Google staff can
take support actions:
- U.S. Google staff in a U.S. location
- CJIS-authorized and IRS 1075-authorized Google staff in a U.S. location
- EU Google staff in EU locations or, if necessary, non-EU Google staff via virtual desktops in EU locations
- (Optional) To change how regional rule conflicts are resolved, click Edit location priority. For details, go to Set up location priority for rule conflicts.
- For Apply Access Approvals policy, review the policy details. No additional setup is required.
- For Alerting, review the tracking details. To receive notifications in the Alert Center when this rule is triggered, you must later create an activity rule using Access Transparency log events as a data source condition.
- For Apply Access Management policy, select which Google staff can
take support actions:
- Click Next.
- For Conditions, define the criteria that your data must meet to trigger
the rule:
- Resource owner—Choose whether to Apply to all of your organization or select Specify org units or groups to apply to specific departments or teams.
- Content—Click Add Condition, select Classification label, and
choose your desired attribute label.
Note: If you need to create labels first, go to Get started as a classification labels admin.
- Click Next.
- For Review, enter a name and an optional description.
- For Status, select Active (or leave it inactive if you want to test the rule and monitor logs first) and then click Save rule.
Automate labeling with data protection rules
You can use data protection rules to create and enforce data loss prevention (DLP) policies that handle data labeling automatically:
- Set up a data protection rule to scan data for sensitive information, such as a credit card or tax number, and configure it to automatically apply a specific classification label when it finds a match. For details, go to Apply classification labels to Drive files automatically with DLP rules.
- Set up your Assured Controls rule (using the steps earlier on this page) to watch for that exact same classification label.
Once linked, the data protection rule finds the sensitive data, applies the label, and your Assured Controls rule restricts Google staff access.
Policy conflict resolution
If you apply rules to data that is already covered by existing user policies, those settings might conflict. When this happens, Google Workspace automatically resolves the conflict using the following order of priority:
- Assured Controls rules override user-based policies—If data triggers an Assured Controls rule that is also covered by a user-based policy set for a department or team, the rule takes precedence. Broader user-based policies only apply if no Assured Controls rules are triggered.
- Groups override departments—If a resource owner belongs to a department and a group with conflicting user-based policies, the group settings take precedence.
- Stricter Access Management policies take precedence—If 2 different rules apply to the same data without conflicting geographic boundaries, Google Workspace enforces the stricter restriction. For example, a rule requiring both CJIS and IRS 1075 credentials overrides a rule that only requires standard U.S. staff credentials.
- Geographic conflicts depend on location priority—If one rule requires U.S. staff and another requires EU staff for the same data, the system follows your domain's global location priority setting.
Set up location priority for rule conflicts
To choose which region takes precedence when multiple rules apply different geographies via Access Management policies:
-
In the Google Admin console, go to Menu
Data
Compliance
Access Management.
Requires the Assured Controls Plus add-on
You must be signed in as a super administrator for this task.
- Click Rule-based scoping.
- For Location priority for conflicts between Assured Controls rules,
select an option:
- Prioritize U.S.—Prioritizes U.S. policies over EU policies if both apply to the same resource.
- Prioritize EU—Prioritizes EU policies over U.S. policies if both apply to the same resource.
- Click Save.
Related topics
- Access Management: Limit the Google staff who can take support actions related to your data
- Access Approvals: Require Google staff to request approval before viewing support data
- Access Transparency: View logs on Google access to user content
- About Assured Controls and Assured Controls Plus
- What data is covered by Access Management and Access Approvals?