Table of contents
Need help with Google Workspace?

Tell us what is broken. We reply the same working day.

We compiled this list after a regulated client sent us 30 questions before signing: how exactly we would access their Google Workspace environment, how they would supervise us, and what happens when something goes wrong. The questions were good. Most of them apply to any company that entrusts its email, files and user accounts to an external IT provider – whether on Google Workspace, Microsoft 365 or anything else. We have generalised them and grouped them into ten areas.

Access

  1. Exactly which administrator rights will you hold in our environment? Do you need the super administrator (global administrator) role on a standing basis, and if so, for which daily tasks?
  2. Will each of your staff work under their own named account in our environment, or under a shared one?
  3. How are temporary rights granted and removed when a task needs more than you hold permanently? Where is that recorded?
  4. From which countries and which devices will you access our environment? Is that technically enforced or only written in a procedure?

Authentication

  1. What second factor do your administrator accounts use – hardware key, app or SMS?
  2. How many keys does each administrator have, and what happens when one is lost?
  3. How do you store our environment’s passwords and recovery codes? Who can reach them?

Configuration

  1. Which standard will you configure our environment against (for example a CIS Benchmark), and which version?
  2. Where will it be documented which settings are applied and why there are deviations from the standard?
  3. How will you learn if a setting is changed without agreement, and how often will you check?
  4. What happens when our own administrator changes something – do we have to tell you, and how?

Backup and restoration

  1. Are our email and files backed up outside the platform provider’s (Google’s or Microsoft’s) own retention mechanisms? Where, and for how long?
  2. Who tests restoration, and how often? Will we receive the test record?
  3. How long does it take to restore one user, one file, the whole environment?

Monitoring and logs

  1. Which alerts are configured (administrator changes, suspicious logins, third-party app access), and who receives them – only you, or us as well?
  2. How long are audit logs retained, and are they exported outside the platform?
  3. How can we check your own activity in our environment without your involvement?

Incidents

  1. How fast will you respond to an alert during working hours and outside them?
  2. Who classifies an incident and who decides on notifying regulators or data subjects – you or us?
  3. How will you tell us if the incident happened on your side (your account, your computer, your tools)?

Documentation and acceptance

  1. Which documents will we receive at the end of implementation – environment description, control register, exception list, acceptance record?
  2. How and how often are these documents updated?
  3. Are the documents our property, and can we hand them to another provider?

People and subcontractors

  1. Which specific people will work on our environment, and who covers for them when they are away?
  2. Do you use subcontractors? Which ones, for what work, and will they have access to our data?
  3. Which tools (ticketing, password vault, remote access) are used to service us, and where do they store data?

Data location

  1. Where is our data physically stored, and can that be set and evidenced (for example a data region in Europe)?
  2. Do any of your tools or subcontractors process our data outside the EEA?

Contract and exit

  1. What happens to your access, our data and the documentation when the contract ends – within how many days, and with what confirmation?
  2. Does the contract give us audit rights, and will you cooperate with our auditor or regulator if they ask about your work?

How to read the answers

A good provider answers most of these immediately, because it is already documented. If the answer on access is “we need full rights, otherwise we cannot work”, on backup “Google already keeps everything”, and on subcontractors “that is not relevant”, those are three red flags. A provider who answers “we still need to check” on a few questions is doing better than one who answers everything confidently without evidence.

For regulated companies (payment institutions, e-money institutions, insurance intermediaries, NIS2 entities) these questions are also part of the outsourcing assessment the regulator expects. The answers can go into the outsourcing register as they are.

Our own answers to these questions for Google Workspace are described on the security audit and monitoring page. If you would like the list as a document to send to your provider, write to info@freeit.lv.

FreeIT SIA · Google Cloud Partner in the Baltics since 2012

The first Google Cloud Partner in the Baltics. Our founder has been a Google-certified Deployment Specialist since 2012 (certificate #849). Google Workspace deployments, migrations and support for Baltic companies since 2011.

Get in touch · +371 22 30 50 90

Google Workspace knowledge base

Related articles