Google Workspace Posture Report
Delivers a weekly Google Workspace report on admin second factors, domain-wide delegation, and mail and recovery settings, with what changed since last week.
What this agent does
This read-only agent checks the health of a Google Workspace domain every week. It measures which active users are not enrolled in 2-Step Verification or are enrolled without a security key, and which admins lack one. It lists super admins and delegated admins, including roles assigned through groups. It lists dormant accounts that are still active and users with app passwords. It lists the service accounts with domain-wide delegation and the scopes they hold. It compares the admin settings it tracks with last week and names who changed what from the admin audit log. It summarizes suspicious login events.
The challenge
A service account with domain-wide delegation can act as any user in the domain, and the grant never expires. A migration tool gets delegation to read every mailbox and keeps it after the migration. Automatic forwarding is on, so any user can send all mail to a personal address. A super admin keeps a phone prompt as the second factor. An organizational unit is exempted from 2-Step Verification enforcement during a rollout and never put back. Nobody reviews the delegations, admin roles, and enforcement settings together.
The solution
The agent reads users, enrollment, admin roles, and policy settings each week. It compares them with the previous week and leads with what changed. It reads domain-wide delegation from the API controls export and the admin audit log. It reports a count it cannot read as not available, never as zero. Provides a weekly briefing with the fix for each item.
Workflow
- 01
Check users and enrollment
List active users with their 2-Step Verification enrollment, enforcement, security keys, app passwords, and last login, by organizational unit.
- 02
Check admins
List super admin and delegated admin role assignments, including roles assigned through groups, and check each holder's second factor and last login.
- 03
Check delegation and settings
Read domain-wide delegation from the API controls export and the admin audit log, and compare enforcement, session, recovery, forwarding, and sharing settings with last week.
- 04
Check the audit logs
Summarize suspicious logins, login failures, and admin actions since last week.
- 05
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Google Workspace Posture Report
## Measurable outcomes
Every week, the Workspace admin knows which admins lack a security key, which service accounts can act as any user, and which mail and recovery settings changed. Track the users without a strong second factor, the super admin count, the unapproved delegations, and the open action items on every run.
## Procedure
Once a week, list the active users in the domain by organizational unit. Include their 2-Step Verification enrollment and enforcement status, their security keys, their app passwords, and their last login. Count users not enrolled in 2-Step Verification. Count users enrolled without a security key or passkey. Flag organizational units where enforcement is off. Flag active users with no login in the last 90 days, unless I set another window. Flag users with app passwords. List every super admin and every delegated admin role assignment, including roles assigned through groups. Flag each admin without a security key or passkey. Flag each admin with no login in 30 days. Flag more super admins than the number I set. Read domain-wide delegation from the API controls export I hand it, and from AUTHORIZE_API_CLIENT_ACCESS events in the admin audit log. Report grants older than the log's retention as not checked. Record each delegation's client ID and scopes. Translate each scope into plain words, such as read all mail or manage all Drive files. Flag any delegation I have not marked as approved. Compare the 2-Step Verification enforcement settings, session length, account recovery settings, third-party app access settings, and external sharing settings with last week's report. Name each change and who made it from the admin audit log. Flag the gmail.auto_forwarding setting when it is on. Flag super admin account recovery when it is on. Summarize the suspicious login events, login failures, and admin actions since the last report. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Admin SDK access to users, roles and role assignments, and organizational units. It needs read-only Cloud Identity Policy API access. It needs read-only Reports API access to the login and admin audit logs, and nothing more. It runs under a custom admin role with read privileges only. It never changes users, roles, delegations, or settings. Reports show counts, organizational units, and setting names. User names appear as stable pseudonyms. Related templates
-
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools -
Bitbucket Public Repository Posture Audit
Reports the public repositories in a Bitbucket workspace that fail its security policy, with each failing check.
Reporting and Compliance 1 tools