Calendar, Meet, Chat & Sites
10 checks · 3 sub-categories
The collaboration apps are where information leaks sideways: a calendar published externally with full event details, a Meet link anyone can join, a Chat space with an outside member, or an old Google Site quietly serving internal documents to the public web.
Calendar
External calendar sharing limited to free/busy
Full-detail external sharing exposes client names, deal titles and travel patterns. We check the domain default and per-OU exceptions.
- CIS GW 6.1
- SCuBA GWS.CALENDAR
Calendars published publicly
Individual calendars can be made public independently of the domain policy. Each publicly visible calendar is listed.
External invitation warnings enabled
Warnings before inviting or accepting external guests reduce accidental exposure and calendar-phishing success.
Meet
Host management and lobby controls enabled
Without host management, any participant can mute, remove or admit others. We check host controls and knocking for external guests.
- SCuBA GWS.MEET
Who can join meetings created by your organisation
Restricting joins to signed-in users, or to your domain, stops anonymous link-sharers from wandering in.
Recording, transcription and streaming policy
Recordings land in Drive and inherit its sharing settings. We check who may record and where recordings go.
- Privacy Act APP 11
Chat, Spaces and Sites
External chat and space membership policy
We check whether staff can chat with, and add, people outside the domain, and whether that is allow-listed to trusted domains.
- SCuBA GWS.CHAT
Chat file sharing and history settings
File sharing in external spaces bypasses normal Drive review, and history-off conversations undermine investigations. Both are checked.
Chat apps and bots allowed
Chat bots can read space content. We check whether users may install them and which are present.
Publicly published Google Sites
Old intranet Sites are a classic forgotten exposure. Every site published beyond the domain is listed with its sharing scope.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.