← Google Workspace audit scope

Groups & Mailing Lists

8 checks · 2 sub-categories

Google Groups are simultaneously mailing lists and access-control objects. One group set to 'anyone on the internet can view' can publish years of internal email conversations, and one over-broad membership can silently grant access to half your Drive.

Group visibility and access

  • Groups accessible to anyone on the internet

    Publicly viewable groups can expose archived conversations and member lists. Each affected group is named.

    • CIS GW 5.1
    • SCuBA GWS.GROUPS
    • Privacy Act APP 11
  • Domain-wide default group access setting

    We check the default sharing setting for new groups so future groups don't repeat the same mistake.

  • Groups allowing external members

    External members receive everything the group receives, indefinitely. All groups permitting outside membership are listed with their current external members.

  • Groups accepting mail from outside the organisation

    Open posting turns an internal list into an unauthenticated inbound channel — a common phishing and spam vector. Each open group is flagged.

Governance

  • Groups used to grant Drive or app access

    We identify which groups act as access-control groups so their membership can be governed accordingly rather than treated as a mailing list.

  • Groups with no owner or a stale owner

    Owner-less groups accumulate members and nobody prunes them. Each is reported with member count and last activity.

  • Suspended and ex-staff members across groups

    Departed staff commonly remain in distribution and access groups. We list every group containing suspended accounts.

  • Members who can view conversation archives

    Archive visibility settings decide whether new members can read years of past discussion. We report groups where the archive is broader than the membership.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.