

THE DIGITAL GOVERNANCE CASE FILES
True stories… or almost.
Situations inspired by real-life cases that shed light on the often-overlooked risks associated with digital assets, access, licenses, and responsibilities within organizations.

CASE FILE 006
Who has Google access?
An urgent publication, necessary access… and no one knows who owns the administrator account. The problem is no longer technical: it's a governance issue.
A publication needs to be made quickly. The manager requests access to the company's Google tools.
Problem: no one knows exactly which account holds administrative rights , who has the login credentials, or which people currently have access to the different services.
Access was created gradually over the years by employees, managers, agencies, or external suppliers. Some resources are associated with work accounts, others with personal addresses.
When the time comes to intervene quickly, the company discovers that it uses its Google environment daily without having a clear view of who actually controls it .
ASSET CONCERNED
Google ecosystem, administrator accounts and digital access
GOVERNANCE ISSUE
Control, allocation and continuity of administrative access
GOVERNANCE FINDINGS
The organization does not have a centralized and up-to-date register of its accounts, administrators, owners, and authorization levels .
Operational access to a service does not necessarily mean that the company has administrative control over it.
When a digital asset depends on an individual account or a single person, that person unintentionally becomes a single point of failure .
Business continuity then relies more on the availability of an individual than on a governance structure belonging to the organization.
IDENTIFIED RISKS
Loss or blockage of administrative access
Dependence on an employee, manager, or supplier
Business accounts linked to personal addresses
Inability to intervene quickly during an emergency
Maintaining access after an employee leaves
Excessive allocation of administrative privileges
Difficulty in determining who made a change
Complex recovery of a compromised account
Interruption of essential services
Security risks associated with sharing credentials
RECOMMENDED MEASURES
List all Google accounts and services used by the organization
Identify the owners and administrators of each asset
Use company-controlled business accounts
Avoid having a single person with sole administrator access
Appoint at least one primary administrator and one backup administrator
Enable multi-factor authentication on sensitive accounts
Assign privileges according to actual responsibilities
Document the procedures for adding, modifying, and removing access
Review authorized users periodically
Establish a procedure for recovering and maintaining access
WHAT TO CHECK IN YOUR ORGANIZATION
☐ The Google accounts used by the company are listed
☐ The owner of each asset is identified
☐ The administrators are known and documented
☐ Critical accounts belong to the organization
☐ No single personal account constitutes the sole administrative access
☐ A backup administrator is planned
☐ Multi-factor authentication is enabled
☐ The old users have been removed
☐ Authorization levels are tailored to responsibilities
☐ A procedure for recovering access exists