SOC 2 policies for Google Workspace teams

Google Workspace is the system of record for who works at your company, so it appears in the policies about access provisioning, authentication and multi-factor enforcement, and the joiner, mover and leaver steps in HR security.

Identity providers · Referenced by 3 of 22 policies · Generator preset available

The 3 policies that reference Google Workspace

With Google Workspace in your intake, these policies name it in their scope, roles and procedures. The other 19 policies in the set apply to your company regardless of tooling; the template index lists all 22.

  • P03 Access Control Policy: Defines how access to systems and data is requested, approved, provisioned, reviewed and removed.
  • P04 Authentication and Password Policy: Sets the requirements for passwords, multi-factor authentication, sessions and secrets used by people and systems.
  • P18 Human Resources Security Policy: Sets the security requirements that apply to people before, during and after their engagement so that screening, access, training and accountability follow every personnel change.

What the Audit Kit writes for Google Workspace

The free generator fills in names. The Audit Kit goes further: Claude rewrites section 4 (Policy Statements) and section 5 (Procedures) of each policy using your full intake, so the text describes Google Workspace the way you actually run it. The statements below are examples of that output for Google Workspace; your own answers produce different text, and every statement should be checked against your configuration before management adopts it.

P03 Access Control Policy

Google Workspace is the identity provider: business applications are federated through SAML apps configured in the Admin console, application access is assigned to Google Groups or organisational units rather than to individual users, and administrator privileges are delegated through pre-built or custom admin roles. The Super Admin role is limited to two named accounts protected by security keys plus one emergency account held in the password manager.
Third-party app access control in the Admin console limits OAuth access to Google Workspace data to allowlisted applications, unconfigured apps are blocked from restricted scopes such as Gmail and Drive, and the connected-apps list is reviewed at each quarterly access review.
Context-Aware Access levels require a company-managed, encrypted device running a current operating system for access to Gmail, Drive and the Admin console, and Endpoint Verification is deployed to every company laptop so device state can be evaluated at sign-in.

P04 Authentication and Password Policy

2-Step Verification is enforced for every organisational unit with no enrolment grace period for new users, security keys and Google prompt are the only permitted methods, SMS and voice codes are disabled, and Super Admins must use security keys. Session control limits the web session length for administrators to no more than 24 hours.
The Admin console password policy requires a minimum of 14 characters, enforces strong passwords, rejects password reuse, and requires a change at next sign-in for any account flagged by Google security alerts as having a leaked password.

P18 Human Resources Security Policy

On the last working day People Operations suspends the leaver's Google Workspace account, which signs out every session and revokes application tokens; Drive files and calendar events are transferred to the manager through the data transfer tool, and the account is deleted after 90 days unless a legal hold applies. New hires are placed in the organisational unit for their team so 2-Step Verification, Context-Aware Access and app assignments apply from their first sign-in.

How to use this page

  1. Open the generator with the Google Workspace preset and answer the remaining questions: company, product, headcount, other tools, data types, owners, scope and review cadence.
  2. Download the 22 policies as Markdown. Read the sections that mention Google Workspace with the admin console open and fix anything that is not true of your setup.
  3. Optionally buy the Audit Kit to have sections 4 and 5 tailored to Google Workspace and the rest of your stack, and to get Word documents, the TSC crosswalk, an evidence checklist, acknowledgment forms and a review calendar in one ZIP built on your machine.
  4. Have management approve the policies, collect acknowledgments, and start producing the evidence the procedures describe. The CPA firm performs the examination.

Other tools

Cloud platforms: AWS, Google Cloud, Microsoft Azure, Vercel, Cloudflare

Source control and CI: GitHub, GitLab

Identity providers: Okta, Microsoft 365

Vendors and subprocessors: Supabase, Clerk

Frequently asked questions

Does Google Workspace's SOC 2 report cover our own SOC 2?
No. Google Workspace's own SOC 2 report covers the controls Google Workspace operates for its platform. Your examination covers how your company configures and uses Google Workspace: who has access, how it is authenticated, what is logged and how data in it is protected. Auditors read the vendor's report to decide what they can rely on, and the Vendor and Third-Party Risk Management Policy tells you to collect it at onboarding and annually.
What does the generator pre-fill when I arrive from this page?
The link on this page opens the generator with a preset that sets the identity provider to Google Workspace. The other answers (company, product, headcount, owners, data types, scope and review cadence) are yours to fill in. The policies render in your browser as Markdown; nothing is sent to a server and there is no signup.
Which policies change when I add Google Workspace to my answers?
3 policies name Google Workspace once it is in the intake: Access Control Policy, Authentication and Password Policy, Human Resources Security Policy. The free generator names it in scope, roles and procedures; the Audit Kit ($39 one-time) rewrites sections 4 and 5 of each policy with statements specific to how Google Workspace is configured, like the examples on this page. Refunds are available within 14 days on request.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.