GOOGLE WORKSPACE · MANAGED RIGHT
Google Workspace Management for Small Businesses
Your Workspace admin console run properly — security tightened, Gmail landing in inboxes instead of spam, shared drives organized, and departures closed out cleanly.
Google Workspace management means someone actually runs your admin console instead of leaving it on the defaults from setup day. We harden security settings, fix the DNS records that decide whether your Gmail reaches inboxes or spam folders, organize shared drives so files stop living in personal accounts, and handle every user change.
It’s for businesses with 1–50 employees whose Workspace was set up in an afternoon years ago and never touched since. Flat rate per user, no contract — and when someone leaves, their access dies the same day, with their files safely handed off.
What we manage
Tenant Security Hardening
2-step verification enforced, risky app access reviewed, sharing defaults tightened, and admin roles trimmed to the people who actually need them.
Gmail Deliverability
SPF, DKIM, and DMARC configured and monitored so your quotes and invoices land in customer inboxes — and nobody can send mail pretending to be you.
Shared Drive Structure
Company files moved into shared drives with sensible permissions — so documents belong to the business, not to whoever happened to create them.
Clean Offboarding
When someone leaves, access is cut the same day, mail is routed to their manager, and their files transfer — nothing lost, nothing lingering.
Choosing the right Google Workspace tier for a small team
Most 5–40 person companies land on Business Standard, but plenty overpay for Plus features they never touch, or squeeze into Starter and hit the 30 GB storage ceiling within a year. The tiers differ in four places that actually matter: pooled storage per user, Google Meet capacity and recording, whether Google Vault is included, and security controls like endpoint management. Here is the practical comparison we walk clients through before they commit.
| Feature | Business Starter | Business Standard | Business Plus |
|---|---|---|---|
| Pooled storage per user | 30 GB | 2 TB | 5 TB |
| Meet participants | 100 | 150, with recording | 500, recording + attendance tracking |
| Shared drives | No | Yes | Yes |
| Google Vault (retention/eDiscovery) | No | No | Yes |
| Advanced endpoint management | No | No | Yes |
| Typical price band (per user/month, annual) | ~$7 | ~$14 | ~$22 |
The rule of thumb: if your industry has any retention obligation — legal, financial services, healthcare-adjacent, or you simply expect litigation risk — the Vault feature alone justifies Plus. Everyone else starts at Standard, because Starter’s lack of shared drives creates the ownership problem described below.
Why company files belong in shared drives, not My Drive
Files in My Drive are owned by the individual account. When that person leaves and you delete the account, every file they owned — the client contracts, the pricing spreadsheet, the folder your whole sales team links to — goes with them, and every shared link breaks. We see this constantly during onboarding: a company’s “shared folder” turns out to be one employee’s My Drive folder shared out to twelve people.
Shared drives fix this structurally. The drive itself owns the files, membership is role-based (Manager, Content Manager, Contributor, Viewer), and staff turnover has zero effect on the data. Part of any Workspace cleanup we do is migrating team content out of personal drives, which Google supports natively — a Content Manager can move folders into a shared drive without re-uploading anything.
Getting mail delivered: SPF, DKIM, and DMARC
If your quotes and invoices keep landing in customers’ spam folders, the cause is almost always missing email authentication records, not “bad luck.” Since February 2024, Gmail and Yahoo require authenticated mail from bulk senders and treat unauthenticated mail with suspicion from everyone. Three DNS records do the work:
- SPF — a TXT record listing which servers may send as your domain, e.g.
v=spf1 include:_spf.google.com ~all. If your CRM or invoicing tool also sends as you, its include must be added too, and the record must stay under 10 DNS lookups. - DKIM — a cryptographic signature on each outgoing message. In Workspace you generate a 2048-bit key in the Admin console and publish it at
google._domainkey. Many small firms never turn this on because it is not enabled by default. - DMARC — the policy that tells receiving servers what to do when SPF/DKIM fail, and it is what stops criminals spoofing your domain in invoice-fraud emails. We start at
p=nonewith reporting, review the aggregate reports for a few weeks, then move top=quarantineand finallyp=reject.
Admin console settings small firms almost always miss
Workspace ships permissive. Four settings close the most common gaps, and none of them cost anything:
- Enforce 2-Step Verification for the whole organization, not just recommend it. Enforcement with a grace period for enrollment takes ten minutes to configure; without it, one phished password equals a mailbox takeover.
- Review third-party app access. Under Security > API controls you can see every app employees have granted OAuth access to Gmail or Drive — often dozens of forgotten tools with full mailbox scopes. Restrict unverified apps and allowlist the ones you actually use.
- External sharing defaults for Drive. Decide whether “anyone with the link” sharing should be allowed at all, and set link-sharing defaults to restricted so a sensitive spreadsheet is not one careless click from public.
- Admin role hygiene. One or two Super Admins with hardware-key-protected accounts, everyone else on delegated roles (Help Desk Admin, Groups Admin). Day-to-day work should never happen in a Super Admin account.
A clean offboarding sequence
Deleting a departed employee’s account on day one destroys data you may need. The sequence that preserves everything and still reclaims the license:
- Suspend the account immediately — sign-in blocked, mail still received, nothing lost.
- Transfer Drive and Calendar ownership to a manager using the built-in transfer tool during deletion, or move files into shared drives beforehand.
- Delegate or forward the mailbox for 30–90 days so client replies are not silently dropped, and set an auto-reply naming the new contact.
- Revoke app passwords, OAuth grants, and recovery methods; sign the account out of all sessions.
- After the retention window, delete the account and reclaim the license — or convert it to an Archived User license on Plus if Vault retention applies.
Frequently asked questions
We run the business on free @gmail.com addresses. Is that really a problem?
Yes, for three reasons beyond appearance. Free accounts have no admin console, so you cannot enforce 2-Step Verification, recover a hijacked account centrally, or reclaim data when someone leaves — the account, and every file and email in it, legally belongs to whoever created it. You also cannot set SPF/DKIM/DMARC for a domain you are not sending from, which increasingly means spam-folder placement.
Can we mix license tiers, say Plus for two executives and Standard for everyone else?
Not within a single Workspace subscription — Google requires one Business edition per tenant. The common workaround for retention needs is Business Standard for everyone plus a third-party email archiving service, but if more than a handful of users need Vault, upgrading the whole tenant to Plus is usually cheaper and simpler.
Does Google back up our Workspace data?
Google protects against its own infrastructure failing, not against your mistakes. A file deleted from Drive is purged from trash after 30 days; an admin has a further 25-day window, and then it is gone. Ransomware that syncs through Drive for desktop, a malicious employee, or an accidental bulk deletion are your problem. For anything business-critical we add third-party Workspace backup with independent retention.
How long does a migration from another provider take?
For a 10–30 person firm coming from Microsoft 365 or an old IMAP host, plan on one to two weeks: DNS and authentication records first, then a staged mail migration using Google’s data migration service, with the MX cutover scheduled for a Friday evening so weekend mail flows to the new tenant before Monday.
Talk to a real technician today
Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.
