Screenata

Integrations / Identity & access

Screenata + Google Workspace

How do you prove SOC 2, ISO 27001, and HIPAA access controls in Google Workspace?

Quick answer

Google Workspace is where logical access control is proved for most companies. It is the first thing an auditor samples under SOC 2 CC6.1, and it is where quarterly access reviews get their source of truth. A sharing or authentication policy existing on paper is not the control. The control is the enforced domain setting plus the record that it operated for every user across the audit period. Screenata runs 10 native checks against that configuration on a schedule and turns each result into signed evidence mapped to the control it satisfies.

Screenata connects to Google Workspace read-only and runs 10 native checks against your domain: 2-step verification, sharing policies, mobile management, and audit logs. Each finding becomes a signed, timestamped evidence artifact mapped to SOC 2, HIPAA, and ISO 27001 controls through a shared control catalog.

10 native checks · read-only · signed evidence

What it proves

Google Workspace evidence, mapped to controls.

Each area below is scanned on a schedule. A finding is not a green checkmark: it is a signed artifact an auditor can verify, mapped to the exact requirement it satisfies.
Evidence area
What the checks verify
Maps to
2-step verification

Whether 2-step verification is enforced across the domain and how enrollment is tracked.

Proof that workspace access requires strong authentication, the first thing an auditor samples.

SOC 2CC6.1HIPAA§164.312(d)ISO 27001A.8.5
Sharing policies

Drive and calendar sharing posture, including how broadly content can be shared outside the domain.

Findings that data sharing is restricted to what your data handling policy claims.

SOC 2CC6.7ISO 27001A.5.14
Mobile management

Mobile device management posture for devices accessing workspace data.

Proof that company data on mobile devices sits behind the device controls your policies describe.

SOC 2CC6.7HIPAA§164.310(d)
Audit logs

Admin and user activity log availability across the domain.

Proof that administrative activity is recorded, which monitoring controls depend on.

SOC 2CC7.2HIPAA§164.312(b)ISO 27001A.8.15

Control references are the requirements each evidence area supports, via the shared control catalog. Your auditor decides sufficiency; the artifacts are theirs to verify.

Compliance checks

What Screenata checks on Google Workspace, and why each matters.

Each row is a real native check, the framework control it produces evidence for, and the risk it closes. This is what continuous Google Workspace compliance actually looks like. Checks run on a schedule; a failing check opens a ticket and re-verifies after a human applies the fix.
Check & why it matters
Maps to

2-Step Verification Enrolled

Accounts without 2-step verification fall to a single stolen or sprayed password. An auditor verifies every active user has completed enrollment, not just that a policy exists.

SOC 2CC6.1

2SV Strong Methods Allowed

Allowing SMS or other phishable factors weakens 2-step verification even when it is enforced. Auditors confirm the policy restricts users to phishing-resistant methods such as passkeys.

SOC 2CC6.1

Password Strength Policy

Short or weak passwords are the first credential an attacker guesses. An auditor verifies the domain policy sets a minimum length and requires strong password strength.

SOC 2CC6.1

Session Duration Control

Web sessions that never expire let a single sign-in grant lasting access. An auditor checks that session duration is explicitly bounded across the domain.

SOC 2CC6.1

Super Admin Assignments Limited

Each additional super admin widens the blast radius of a compromised account. Auditors confirm the number of accounts holding super admin stays within a least-privilege threshold.

SOC 2CC6.1SOC 2CC6.3

Google Workspace User Inventory (for SOC 2 user population)

Access reviews and termination testing need a complete, system-generated list of who has access. This check enumerates the full Directory roster so auditors sample against an authoritative population.

SOC 2CC6.1SOC 2CC6.2ISO 27001A.5.18HIPAA§164.308(a)(3)(ii)(C)

Drive External Sharing Restricted

Unrestricted Drive sharing lets files leave the domain to anyone with a link. An auditor verifies external sharing is disallowed or limited to approved domains.

SOC 2CC6.1

Third-Party App Access Restricted

If unconfigured third-party apps can request access, a malicious OAuth app can reach user data. Auditors confirm third-party app access is blocked or limited to sign-in only.

SOC 2CC6.1

Admin Audit Log Access

Monitoring and incident response depend on admin activity being recorded and retrievable. An auditor verifies admin audit activity is accessible through the Reports API.

SOC 2CC7.2

Critical Alert Rules Not Disabled

Disabling critical alert rules blinds the org to admin changes, phishing, and account takeover. An auditor checks that identity, privilege, phishing, and malware alert rules remain active.

SOC 2CC7.1

Drawn from Screenata’s Google Workspace check library. Control refs are the requirements each check produces evidence for; your auditor decides sufficiency.

How it connects

Read-only, revocable, yours.

You authorize a read-only connection with domain administrator consent and Screenata uses it for scheduled scans. Vera never receives write access to your domain, and credentials never touch the Screenata database. Findings are hashed and stored as evidence the moment they land.

Read-only by construction

OAuth scopes and IAM roles are scoped to read. Vera never gets write access to your systems.

Signed findings

SHA-256 per artifact, RSA/ECDSA signatures, RFC 3161 timestamps. Verifiable without a Screenata account.

Mapped to controls

Each finding lands on the shared control catalog, so one scan satisfies SOC 2, HIPAA, and ISO 27001 at once.

BAA & attestation status

Google offers a BAA covering designated Google Workspace core services on paid business and enterprise editions. Free consumer Gmail is not covered, because Google does not sign a BAA for it. Accepting the BAA in the Admin console is the start, not the finish. Sharing settings, 2-step verification, retention, and access controls are yours to configure and yours to evidence.

Google Workspace FAQ

What teams ask before connecting.

Full provider list on the integrations page.
What access does Screenata need to Google Workspace?

A read-only connection approved by a domain administrator. Screenata uses it for scheduled scans and never receives write access. You can review the requested scopes before consenting and revoke access at any time from the admin console.

Does the Google Workspace integration feed access reviews?

Yes. User and admin state from the domain feeds the quarterly access reviews Vera schedules and orchestrates, with every decision left to a human reviewer, and the completed review recorded as signed evidence.

Is Google Workspace evidence enough for HIPAA?

It covers the identity, sharing, and logging slice of the Security Rule, and the same findings map to SOC 2 through the shared catalog. A HIPAA program also needs a signed BAA with Google, policies, training records, and a documented risk assessment, which come from the rest of the program.

What are the steps to implement SOC 2 with Google Workspace?

Connect the domain read-only with administrator consent. Let the first scan establish a baseline so you can see which settings already pass and which do not. Fix what fails: enroll every active user in 2-step verification and restrict it to strong methods, bound session duration, restrict Drive external sharing and third-party app access, keep super admin assignments limited, and leave the critical alert rules enabled. Collect the passing results as signed evidence on a schedule, so you hold coverage across the whole audit period rather than one snapshot. Then hand the evidence package to an independent auditor. The audit is a separate engagement with a CPA firm; Screenata prepares the evidence and does not issue the report.

How do you automate user access reviews?

Google Workspace supplies the authoritative list of accounts and entitlements from the Directory. The HR roster supplies who should still have them. Screenata reconciles the two, schedules the review, routes each account to the right reviewer, and records the reviewer's decision as signed evidence. The access decision stays with the human reviewer. What the automation covers is gathering, routing, chasing, and recording.

Do auditors accept evidence Screenata collects from Google Workspace?

Yes. Every finding is exported as a signed, timestamped artifact, a SHA-256 hash with an RSA or ECDSA signature and an RFC 3161 timestamp, that an auditor verifies outside Screenata with a free CLI. A person reviews and approves the evidence before it reaches the auditor. Screenata collects and signs it; it does not decide the audit result.

Connect and see

Fifteen minutes after connecting Google Workspace, you know your real posture.

Pricing

Related: Okta · Google Cloud · Microsoft 365 · Rippling