← Google Workspace audit scope

Calendar, Meet, Chat & Sites

10 checks · 3 sub-categories

The collaboration apps are where information leaks sideways: a calendar published externally with full event details, a Meet link anyone can join, a Chat space with an outside member, or an old Google Site quietly serving internal documents to the public web.

Calendar

  • External calendar sharing limited to free/busy

    Full-detail external sharing exposes client names, deal titles and travel patterns. We check the domain default and per-OU exceptions.

    • CIS GW 6.1
    • SCuBA GWS.CALENDAR
  • Calendars published publicly

    Individual calendars can be made public independently of the domain policy. Each publicly visible calendar is listed.

  • External invitation warnings enabled

    Warnings before inviting or accepting external guests reduce accidental exposure and calendar-phishing success.

Meet

  • Host management and lobby controls enabled

    Without host management, any participant can mute, remove or admit others. We check host controls and knocking for external guests.

    • SCuBA GWS.MEET
  • Who can join meetings created by your organisation

    Restricting joins to signed-in users, or to your domain, stops anonymous link-sharers from wandering in.

  • Recording, transcription and streaming policy

    Recordings land in Drive and inherit its sharing settings. We check who may record and where recordings go.

    • Privacy Act APP 11

Chat, Spaces and Sites

  • External chat and space membership policy

    We check whether staff can chat with, and add, people outside the domain, and whether that is allow-listed to trusted domains.

    • SCuBA GWS.CHAT
  • Chat file sharing and history settings

    File sharing in external spaces bypasses normal Drive review, and history-off conversations undermine investigations. Both are checked.

  • Chat apps and bots allowed

    Chat bots can read space content. We check whether users may install them and which are present.

  • Publicly published Google Sites

    Old intranet Sites are a classic forgotten exposure. Every site published beyond the domain is listed with its sharing scope.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.