Table of contents
Need help with Google Workspace?

Tell us what is broken. We reply the same working day.

Almost every IT provider that services Google Workspace asks for a super administrator account. It is convenient. But a super administrator can do everything: reset any employee’s password, read any user’s mail through Vault, delete accounts, grant rights to themselves or others, switch off security settings. For a company whose data matters, and especially for a regulated one, this is a question to ask before signing the contract, not after the incident.

What Google reserves for super administrators

Google publishes the list of actions that cannot be delegated to any custom administrator role. According to Google’s administrator documentation (read 29.09.2026) they are:

  1. Create and assign administrator roles.
  2. Manage other administrators, including changing their passwords and second factor.
  3. Enforce two-step verification.
  4. Install Google Workspace Marketplace apps domain-wide.
  5. Grant domain-wide delegation and manage API client access.
  6. Set up Google as a SAML identity provider; add or modify SAML apps.
  7. Restore deleted users.
  8. Transfer ownership of files when deleting a user.
  9. Accept terms of service for a product.
  10. Turn multi-party approval on or off.
  11. Use the data migration service.
  12. Invite unmanaged accounts to become managed accounts.
  13. Manage Calendar resource access-level controls.
  14. Change another administrator’s account settings.

Notice what is not on the list: creating and managing users, administering groups, Gmail and Drive settings, security settings, DLP rules, reports and audit logs, the alert centre, Vault. All of that can be delegated through a custom role, and many areas have separate read and manage privileges.

What this means for day-to-day service

None of the 14 super-admin actions is needed for routine monitoring. Most are one-off (during implementation) or exceptional (recovering an administrator’s access, changing the backup product). So a provider’s access can be split into three modes:

  • Standing access – a custom role with read privileges: reports and audit logs, alert centre, security dashboard, read access to users, groups and organisational units, view DLP rules. Enough to monitor, review logs and prepare evidence.
  • Your administrator on written instruction – every change that needs a manage privilege is applied by your own administrator, with the provider specifying what to change and why. The action stays in your hands and under your account.
  • Temporary elevation – when you want the provider to carry out a specific task, your super administrator grants the needed privilege before the work and removes it afterwards. Google has no built-in time-limited grant, so granting and revoking are two deliberate actions, both visible in the admin audit log.

How to supervise the provider

  • Named accounts for every provider person, no shared accounts. Every action is attributable to a human.
  • Alert rules for administrator role changes and for admin activity on the provider’s accounts, delivered to your IT owner as well.
  • A monthly admin audit log extract filtered on the provider’s accounts, countersigned by your side.
  • A hardware security key (FIDO2) on the provider’s account and, in Enterprise editions, a context-aware access level: managed device only, your country only.
  • Quarterly access recertification in which the provider’s role and every elevation granted during the quarter is a separate line.

The provider cannot edit the audit log, so you can check their activity at any time without their involvement.

When super-admin is still needed

During implementation – to create roles, enforce 2SV, grant domain-wide delegation for a backup or MDM integration. Even then there is a choice: your super administrator performs the actions with the provider on a screen-share, or the provider’s account receives the super-admin role for a defined task window and loses it afterwards. Both are acceptable if documented and visible in the log.

If a provider says service is impossible without standing super-admin, ask them to name which of the 14 actions they need every day. The answer is usually none.

We offer Google Workspace security monitoring without standing super-admin rights. The access model is described on our security audit and monitoring page.

FreeIT SIA · Google Cloud Partner in the Baltics since 2012

The first Google Cloud Partner in the Baltics. Our founder has been a Google-certified Deployment Specialist since 2012 (certificate #849). Google Workspace deployments, migrations and support for Baltic companies since 2011.

Get in touch · +371 22 30 50 90

Google Workspace knowledge base

Related articles