Tech

Setting Up Google Workspace: The Decisions to Get Right

Published

on

Google Workspace is a subscription that gives an organisation the Google productivity applications on its own domain, with administrative control over the accounts that use them. Gmail, Calendar, Drive, Docs, Sheets, Slides, Meet and Chat are the components most people recognise. The admin console, which most descriptions leave out, is the reason a business buys it rather than issuing everyone a free consumer account.

The distinction is not cosmetic. A free account is owned by the person who created it, is subject to consumer terms, and cannot be transferred, suspended or audited by an employer. A Workspace account is owned by the organisation, sits under a business agreement, and can be administered. For a business of any size, that is the product.

What the editions differ on

Google sells Workspace in tiers, and the tiers are separated by three things rather than by the applications themselves, which are essentially the same across the range.

  • Storage. The entry tier provides a pooled allowance shared across users; the higher tiers increase it substantially. Storage is the first constraint most growing teams meet, and the first reason a business moves up a tier.
  • Meeting and recording capability. Participant limits, recording, live streaming and attendance tracking sit in the higher tiers, which matters to any organisation that runs large external meetings.
  • Administrative and security controls. The top tiers add controls over data regions, retention, device management and advanced security reporting. A regulated business tends to need these; a ten-person consultancy rarely does.

Two qualifications belong with that comparison. The first is that Google changes the contents of each tier periodically, so a comparison written a year ago may not describe what is being sold today, and the current published plans are the only reliable source. The second is that the subscription price is not the cost of the project. Migration, configuration and the internal time spent learning a new system sit outside the per-user figure, and they are frequently larger than the first year of licences.

The setup decisions that are hard to reverse

Workspace is easy to buy and easy to get wrong, because the defaults are designed for consumer convenience rather than organisational control. Four settings deserve attention before users are added.

  • Identity and domain. The domain must be verified and the mail records pointed at Google, which means the records that control email authentication move at the same time. Get the sending records right, including the authentication records that mailbox providers check, or legitimate mail starts landing in spam and the cause is not obvious afterwards.
  • Two-step verification. Enforced from the start, not offered. Retrofitting it across an organisation that has grown used to passwords alone is significantly harder than requiring it on day one.
  • Shared drives, not personal folders. A file created in one person’s My Drive belongs to that person’s account. When they leave, the access goes with them unless the data has been transferred. Shared drives give the organisation ownership from the beginning, and moving later means re-sharing everything.
  • Admin roles and recovery. More than one super administrator, with recovery options configured. An organisation with a single administrator and no recovery path has a business continuity risk in one account.

Sharing defaults are the fifth item and the least technical. The default that allows anyone with a link to open a file is convenient and it is how confidential documents end up outside an organisation. Setting the default to a narrower option and requiring an explicit decision to widen it costs nothing and prevents the majority of avoidable incidents.

What migration involves

For a business moving from another provider, the migration has three separate parts, and they behave differently.

  • Mail. Email history can generally be migrated in bulk. The volume is what determines the duration, not the complexity, and a large archive can take days rather than hours.
  • Calendar. Event data moves well, but shared calendars and recurring meetings frequently need to be rebuilt by hand because the sharing relationships do not transfer cleanly.
  • Files. Documents move; their sharing permissions and links often do not. Every internal link in a document, every bookmark and every saved shortcut is a thing that either survives the move or has to be reissued, and nobody notices until someone clicks one.

A migration plan that accounts for those three separately is a different document from one that promises “everything moved”. The second is a promise the tooling cannot keep.

Doing it yourself compared with paying for help

The honest answer depends on the size of the organisation and the amount of history it is carrying, not on the complexity of the software.

A small team with a clean start, no legacy archive and a technically capable person on staff can complete the setup described above without external help. Creating users, enforcing two-step verification, configuring shared drives and adjusting sharing defaults are documented tasks, and a business can genuinely do them itself.

Three situations change the calculation. A large mail archive, where a failed or partial migration is expensive to unpick. A regulated or contractually constrained business, where retention, data location and access controls need to be defensible rather than merely sensible. And an organisation with no one holding responsibility for IT at all, where the practical issue is not capability but the absence of a person who will be asked the questions later.

Where help is engaged, the engagement should be scoped in the same terms the business would use itself: which of the four setup decisions are included, what happens to the existing archive, and what the handover looks like. An engagement that produces a working tenant but no documentation leaves the organisation in a worse position than one that never bought the software.

The obligations that come with the tools

Moving business records into a cloud platform does not change a business’s obligations to protect personal information. Australia’s privacy legislation applies to many organisations, and the so-called small business exemption is narrower than it sounds: it does not extend to health service providers, to businesses that trade in personal information, or to many of the other exceptions the Act sets out.

What that means in practice is not that Workspace should be avoided, which would be an odd conclusion given how widely it is used. It means the security configuration described above is the compliance work, and the notifiable data breach scheme that sits behind it assumes the organisation has thought about who can access what, and how it would know if that changed.

For teams already invested in the wider Australian software ecosystem, the comparison that usually follows is with the project and documentation tools that other vendors build. How that industry developed, and what it reveals about the tools Australian teams adopted, is worth a read if you are choosing a stack rather than a mailbox.

What to plan before you move

Choose the tier by the constraint you are most likely to meet, which is usually storage or meeting size rather than security. Configure two-step verification, shared drives and admin recovery before the first user signs in, because all three are cheaper at the start. Treat mail, calendar and files as three projects. And decide, in writing, who owns the tenant after the migration ends, because that is the question nobody asks on the day and everybody asks two years later.

Sources: Google publishes the current edition comparison, admin documentation and migration guidance for Workspace at workspace.google.com; the Office of the Australian Information Commissioner (oaic.gov.au) publishes the scope of the Privacy Act, the small business exemptions and the notifiable data breaches scheme.

Trending

Exit mobile version