← Google Workspace audit scope

Logging, Alerting & Data Retention

9 checks · 2 sub-categories

When something goes wrong, the question is always the same: what did they access, and can you prove it? Under the Notifiable Data Breaches scheme you have 30 days to assess a suspected breach. Without logs and retention configured in advance, that assessment is guesswork — and guesswork usually means notifying everyone.

Visibility

  • Admin, login, Drive and Gmail audit logs available

    We confirm which log sources are being generated, how far back they go on your licence, and where the gaps are.

    • NDB scheme
    • Essential Eight — Monitor and analyse event logs
  • Alert Center rules configured and routed to a human

    Default alerts fire into a console nobody opens. We check which rules are on and whether notifications reach a monitored mailbox.

  • Custom alerts for high-risk events

    Super admin grants, mass downloads, forwarding rule creation and suspicious sign-ins each deserve a named alert. We check for them individually.

  • Log export to BigQuery or a SIEM

    Where retention beyond the console default matters, we check whether logs are exported and retained for a defined period.

Retention and investigation

  • Google Vault retention rules defined

    Without a retention rule, deleted mail and files eventually purge — including evidence. We check default and custom retention rules across Gmail, Drive, Chat and Meet.

    • Privacy Act APP 11
    • TPB record-keeping (accounting)
    • RACGP (health)
  • Legal hold capability tested

    We confirm holds can be applied to individuals and OUs, and that the people who'd need to apply one know how.

  • Data regions and residency settings

    Where a client or regulator requires data to stay in a defined region, we check the data region policy applied to your OUs.

  • Backup and recovery arrangements beyond Vault

    Vault is retention, not backup. We check whether a genuine third-party backup exists for Gmail and Drive and how quickly a restore could actually happen.

  • Incident response contact details current in the console

    Google sends security notifications to the contacts on file. We check they point to someone who still works there.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.