How to fix your Google Workspace security gaps and automate the process

Your Google Workspace is likely just waiting for a security incident to happen. We see this all the time.

To be fair, keeping a workspace secure is difficult because every single day, users share new files, invite external vendors into folders, and connect third-party apps. In fact, research shows that human error contributed to 95% of data breaches in 2024, often driven by everyday user mistakes. Decision-makers also report that data leaks caused by insiders cost an organization $13.9 million on average.

Keeping track of who has access to what becomes an impossible task, which is why most businesses approach security reactively. They only look at permissions or fix settings after an issue happens, treating security as a one-time project.

But real security requires a different, two-step approach. First, you need to run an audit to see your current risks and clean them up. Second, you need to use software to handle that cleanup automatically so that the same issues don’t happen again next week.

Finding hidden data exposure in your workspace

When a business grows, security settings change because users are just trying to move quickly and get their work done. To fix this, you need a clear look at where your files actually are and who can see them.

As Daniel Brychta, a Google Workspace security engineer at Revolgy, puts it:

When we run an audit for a client, we almost always find files that have been open to the public for months without anyone realizing it. Honestly, employees are just trying to do their jobs quickly. The issue is that IT teams don’t have the time to manually check thousands of files every day.

When looking at a company’s workspace, four main problems usually come up:

  • Sharing data with public AI tools: Employees often copy and paste company data, source code, or customer information into public generative AI tools to help them write emails or analyze data. Right now, 81% of security leaders say they are worried about data leaks happening through these AI tools.
  • Old sharing links: Links created for a contractor or client a year ago that are still active today, or public links that anybody on the internet can access. Anyone who gets ahold of that link can view internal files.
  • People who left the company: Ex-employees or past vendors who still have access to shared company folders because no one manually removed their specific file permissions when they stopped working with the organization.
  • Third-party apps: Software, add-ons, or SaaS applications that users connect to their Google accounts, which often are granted broad permissions to read, edit, or delete company data without IT knowing about it.

Running a security audit allows you to find these specific problems and clean them up. Download our checklist with tips to cover security settings from start to finish.

How a Google Workspace security audit fixes these risks

Finding every open link or misconfiguration manually is nearly impossible on your own. Most organizations use less than 50% of their available Google Workspace security features, not because they don’t care, but because settings degrade as teams grow.

Our Google Workspace security audit assesses nearly 100 critical risk points across 10+ key areas, including administrator accounts, user MFA, Google Drive sharing, Gmail protocols, third-party app permissions, and mobile endpoints.

 

GWS security audit exampleAn example of an audit finding (source: Revolgy)

 

During an audit, Revolgy provides:

  • Full assessment of core controls across 10+ key areas: We evaluate nearly 100 specific risk points, checking account security (like MFA enforcement), email protocols (SPF, DKIM, DMARC), and device access rules. Vulnerabilities are ranked by risk level so you know what needs attention first.
  • Clean, safe baseline: We locate publicly accessible files, revoke permissions left open for former employees, and clean up unapproved third-party app tokens to secure your data.
  • Actionable 14-day roadmap: Within two weeks, you receive a structured report and a prioritized list of specific fixes ranked by business impact, making it easy to align with standards like ISO 27001 or SOC 2.

 


 

Cleaning up your workspace establishes a solid, safe foundation. But because employees create new documents and share files every single day, you need software to keep those security rules enforced automatically over time.

Using DoControl to automate and maintain security day-to-day

Revolgy helps organizations identify and fix today’s security gaps. The next challenge is making sure those same issues don’t quietly return a week or month later.

Running an audit is the right first step, but it’s only a snapshot of your environment at one moment in time.

The challenge is that Google Workspace changes every day. Employees create new documents, share files with customers, invite contractors into folders, connect third-party applications, and collaborate across teams. Even after cleaning up today’s risks, new ones can appear tomorrow.

That’s why manual security reviews become difficult to sustain as an organization grows. IT teams simply can’t keep up with thousands of sharing events, permission changes, and user activities happening across the workspace every day.

Instead of relying on someone to regularly review permissions and remember every security task, organizations increasingly use automation to continuously enforce the security policies established during their initial audit.

This is where DoControl helps.

DoControl continuously monitors Google Workspace activity. It then automatically applies the security rules your organization has defined. Rather than simply notifying administrators or security teams about risky activity, it can take action immediately — helping reduce exposure before it turns into an incident.

Turning security policies into automated actions

One of the biggest advantages of automation is consistency. Every file, user, and sharing event is evaluated against the same security policies without requiring manual review.

For example, with DoControl, organizations can automatically:

  • Expire external sharing links after a predefined number of days (7, 30, 60, 90, etc.), preventing temporary access from becoming permanent exposure.
  • Remove a departing employee’s access to shared files across Google Workspace as soon as they’re offboarded through an HRIS or identity provider, eliminating the need to manually update permissions.
  • Detect unusual activity, such as mass file downloads or large-scale sharing events, and immediately respond by alerting security teams, notifying managers, revoking access, quarantining sharing, or triggering an automated workflow.

Instead of waiting for someone to discover these risks during the next audit, they’re addressed as they happen — strengthening your organization’s Google Workspace security and Google Drive security 24/7.

 

 

 

Remediating security risks at scale

As organizations grow, fixing security issues one file at a time quickly becomes unrealistic.

An audit may uncover hundreds — or even thousands — of files that are publicly shared, accessible to former employees, or exposed to unauthorized users. Correcting each permission manually can take days and still leave room for human error.

DoControl helps organizations remediate these risks in bulk while continuing to monitor for new ones. Using no-code, event-driven workflows, security teams can automatically apply consistent policies across Google Workspace based on business context, user identity, file sensitivity, and organizational rules.

For example, if a confidential file is shared outside the company, DoControl can automatically remove external access, notify the file owner, alert the security team, and create a ticket for follow-up — all without requiring manual intervention.

This allows security teams to focus on investigating the highest-priority incidents instead of spending their time on repetitive administrative work.

Take security into your hands

Finding security gaps is only the first step. The real challenge is making sure they don’t come back.

Google Workspace security isn’t something you complete once and check off a list. It’s an ongoing process that evolves alongside your business.

Revolgy helps organizations assess their Google Workspace environment, uncover hidden risks, and remediate existing security gaps through a comprehensive security audit. Once your environment has been cleaned up, DoControl helps keep it that way by continuously monitoring activity, enforcing your security policies, and automatically remediating new risks as they emerge.

Together, this approach gives you both immediate visibility into your current security posture and the automation needed to maintain it over time — without relying on manual reviews or repetitive administrative work.

Whether you’re concerned about overshared files, former employees retaining access, third-party application risk, or sensitive data exposure, combining an expert-led security assessment with continuous automation provides a practical, scalable way to strengthen Google Workspace security.