← Back to Blog

What a Google Workspace consultant actually does for a 10 to 50 person company

  • Admin console
  • Gmail
  • Drive
What a Google Workspace consultant actually does for a 10 to 50 person company

A thirty-person company rarely has an IT department. It has an office manager who created the email accounts three years ago, a developer who knows the DNS password, and a founder who is the only super admin and cannot remember the recovery phone number on the account. It holds together until someone resigns, a laptop is stolen, or Gmail starts bouncing the invoices.

That is usually when the call comes. Below is what the work actually is, in the order we do it, so you can tell a real proposal from a vague one and decide which parts your own team should keep.

The five situations that make a company call

Nearly every Google Workspace engagement we run starts in one of five places.

  • A migration. Mail is moving from Microsoft 365, an old Exchange server, cPanel or Zoho, and nobody wants to be the person who loses a message on cutover day.
  • A security scare. Someone clicked something, a mailbox started sending invoices to a client list, or an insurer asked for proof that two-factor authentication is enforced.
  • An offboarding mess. A person left four months ago and still owns half the shared files, or their account was deleted in a hurry and now the accountant needs a message that was in it.
  • Licensing waste. The bill grew past what headcount justifies and nobody knows which seats belong to people who left.
  • Nobody owns the admin console. This is the quiet one. Settings sit at their defaults, or at whatever a contractor chose in 2021, and there is no second super admin if the first one is unreachable.

The first four are projects with an end date. The fifth is usually the reason the other four happened, and it is the one worth solving properly.

What the first audit covers, item by item

The audit is a read, not a change. We ask for a delegated admin account, or we sit with whoever has one, and we go through the same list every time. Google publishes a security checklist written specifically for organizations of one to a hundred users, and it is the honest backbone of this part: administrator accounts, user accounts, apps, Calendar, Chat, Chrome, devices, Drive, Gmail, Groups, Sites and Vault. Many of the settings it recommends are already on by default, which is good news. The findings are almost always in the handful that are not.

These are the items that produce findings, in reading order:

  1. Super admins. How many exist, whether each one is a real identifiable person, and whether each has 2-Step Verification. Google's own guidance is blunt here: super admin accounts control access to all business and employee data in the organization, so they should use 2-Step Verification, security keys are the strongest form of it, and whoever holds one should sign in to it only for admin work and use a separate ordinary account the rest of the time. There should also be more than one. A company with a single super admin can be locked out of its own email by one lost phone, and only a super admin can generate backup verification codes for another admin, which is exactly the help you need on the day it happens.
  2. Recovery information. Recovery phone numbers and addresses that belong to people who no longer work there.
  3. Organizational units and groups. Whether access is granted to groups or to individuals one at a time. Access granted name by name is what turns an offboarding into a week of work.
  4. Drive sharing. How much is shared with anyone who has the link, and whether critical files live in shared drives the company owns or in somebody's personal My Drive.
  5. Third-party app access. This is the finding that surprises people most. Under Security, then Access and data control, then API controls, the console lists the apps that have been configured with an access setting and the apps your users have actually connected to their accounts. Each one can be set to trusted, limited to unrestricted services, restricted to specific data, or blocked outright, and an unconfigured third-party app is blocked by default, with the user's request landing in a list for an admin to allow or block. The details of a newly authorized app can take a day or two to appear, so a tool connected this morning will not show up this afternoon.
  6. Devices. Whether the phones carrying company mail are enrolled at all, and whether a remote wipe is actually possible.
  7. Licences. Which seats are assigned, which are suspended and still being paid for, and which plan the subscription sits on.
  8. Mail authentication. SPF, DKIM and DMARC for the domain, and every outside system that sends as it: the invoicing platform, the CRM, the online store, the helpdesk, the scanner in the corner that emails PDFs.

That last item is where a Workspace audit and a deliverability audit meet, and it is the one a business feels first, because it puts invoices in the spam folder. You can run that part on your own domain right now.

What we fix, and what we hand back

A consultant worth hiring is trying to become unnecessary for the routine work. The split we aim for: we take what needs judgement and a one-time hand, your people keep what has to happen every week.

What we take on: the migration and the cutover, the super admin structure and the delegation of admin roles so that not everyone who needs to reset a password needs full control, groups and organizational units rebuilt so access follows a role instead of a name, sharing defaults, the third-party app review, device enrollment, and the full SPF, DKIM and DMARC setup including the outside senders nobody listed. Anything that needs a rollback plan attached to it.

What we hand back, with a written procedure short enough that someone will actually use it: creating and offboarding a person, adding someone to a group, approving or blocking a new app request, reading the monthly DMARC summary, and a quarterly licence check. If a consultant wants to keep those five in their own hands, ask why.

Offboarding, the part most companies get wrong

Offboarding deserves its own section, because the expensive mistakes are made in the first ten minutes by someone in a hurry.

The order matters. For a departing employee, Google's guidance is to reset the person's sign-in cookies so open sessions stop working, revoke their security keys, and wipe company data from their mobile devices, and to treat the transfer of what they own, Drive files and calendar events, as its own deliberate step before anything is removed.

The costly mistake is deleting the account the same day. A deleted user can be restored, but only within twenty days, and the Drive files that user owned are held for that same window and are reachable only if you restore the account first. After that the recovery conversation is over. Suspending blocks the person's access while leaving every file and message in place, which is why it is the right first move for almost every departure. If the mailbox has to be kept for accounting or legal reasons, an archived user licence keeps that data available in Vault without holding an active seat.

The pattern we install is boring on purpose: suspend on the last day, transfer ownership within the week, keep or archive by a rule the company agreed in advance rather than in the moment, delete only when that rule says to.

What it should cost next to your licences

The honest answer to what this should cost is a ratio, not a number. Judge a proposal against what you already pay for licences: an audit with a fix list is a small multiple of one month of your subscription, and a migration with a real cutover is more, but it is a one-time cost against a bill you pay every month for years. The thing to push back on is not the rate, it is an open-ended hourly engagement with no defined finish.

Licensing is also where the work often pays for itself, and what you can recover depends on your plan. On the Flexible Plan you are billed for the accounts you have that month, so deleting a user lowers the licence count and the payment right away. On the Annual Plan you committed to a seat count for the term, and you can reduce it only at renewal, by setting the subscription to auto-renew with fewer licences before the term ends. Companies that learn this in month two of a twelve-month term pay for the lesson. Our own terms and how we scope an engagement are on how we work.

How to check that a consultant is independent and certified

Three questions separate a practitioner from a slide deck.

Ask what they are certified in and when they passed. Google Cloud runs a proctored certification for Workspace administrators, and the preparation it recommends is roughly six months of hands-on super admin experience rather than a weekend of reading. The badge also expires and has to be earned again, so a claim of being certified without a date attached is worth less than it sounds.

Ask whether they resell your licences. A reseller earns a margin on the subscription. An independent consultant does not, which makes it easier to be told to drop a tier when dropping a tier is the right answer. Neither model is disqualifying, but you should know which one is sitting across from you. Google lists partner companies in its public partner directory, and it is worth understanding that a certification belongs to a person while partner status belongs to a company. They answer different questions, and a small independent team can be strong on the first without the second.

Ask what happens when they are finished. The answer should include documentation you own, admin access that stays with you rather than with them, and a named person on your side who was taught the weekly tasks.

How Guanacos Tech helps

We are an independent consultancy with Google-certified engineers, working in English and Spanish with companies of roughly ten to fifty people across North America and Latin America, since 2018 and across more than eighty projects. A Workspace engagement with us usually starts with the audit above, delivered as a findings list ranked by what each item would cost you if it went wrong, then the fixes in that order, then a handover short enough that your own team can run the weekly work. Our Google Workspace consultants page describes how the engagement runs, and a first call is thirty minutes to look at your admin console together and work out which of the five situations you are in.

Sources

Next step

Would you rather we did this for you?

Thirty minutes on Google Meet, free. We look at your domain or project with you, tell you what is wrong and what we would do first. If you can fix it yourself, we say so.

Book a 30-minute call or read about our Google Workspace consulting

Frequently asked questions

What does a Google Workspace consultant actually do?

Three things, in order: audit the tenant against Google's own security checklist, fix what needs judgement (super admin structure, groups and access, sharing defaults, third-party app access, devices, mail authentication, migrations and cutovers), then hand back a short written procedure so your own team runs the weekly work. If a proposal has no audit and no handover, it is not a consulting engagement.

Do we need one if we only have 15 people?

Not permanently. Companies that size usually need a one-time audit and fix, plus a written procedure for onboarding, offboarding, app approvals and the monthly DMARC check. The exception is a migration or a security incident, where the cost of doing it wrong is far higher than the cost of help.

Is a certified consultant the same as a Google partner?

No. Certification is earned by a person through a proctored Google Cloud exam and it expires, so ask when it was passed. Partner status belongs to a company and is listed in Google's public partner directory. An independent consultancy with Google-certified engineers can be a strong fit without being a reseller, and a reseller has a margin on your subscription that an independent consultant does not.