Free · IT Operations Guide
Beyond Provisioning
Automating IT Access Requests Across Complex Google Workspace Organisations
A practical 21-page guide for lean IT teams supporting multiple locations, departments, roles, entities, and approval structures — focused on the access work that begins after the user account already exists.
- Why access requests stay manual even when user provisioning is already automated
- How to resolve location, entity, manager, resource-owner, and policy context automatically
- The eight-step anatomy of an end-to-end automated access request
- What a platform needs to handle approvals, Google Workspace actions, expiry, and audit history
- A diagnostic worksheet and 30-day plan for choosing the right first workflow
21-page practical guide + access request diagnostic worksheet
Get your free copy
21-page PDF. Includes the access request diagnostic worksheet and a 30-day starting plan.
What's inside
From the access request problem to a 30-day starting plan
- 01Who this guide is for
- 02The work that starts after the account's created
- 03How one request becomes ten decisions
- 04The three layers of access management
- 05And what about Apps Script?
- 06The anatomy of an automated request
- 07The execution layer
- 08Seven questions to ask any platform
- 09Three organisational patterns
- 10Two architectures for IT service delivery
- 11In production: Gordon Food Service
- 12Gordon Food Service's IT delivery architecture
- 13Where to start
- 14The diagnostic
- 15Access request diagnostic worksheet
- 16Reading the result
- 17A 30-day starting plan
Why it matters
The access layer is where manual IT work accumulates
reduction in IT ticket requests reported by Gordon Food Service after automating Google Workspace service-delivery workflows.
cut in admin time spent on Google Admin tasks in the same production deployment.
recurring access-request types often account for the bulk of request volume — enough to identify a practical first automation.
Source: Gordon Food Service case study and access-request diagnostic guidance featured in the guide.
Who it's for
Written for IT teams managing complexity after provisioning
Lean IT teams
Supporting growing organisations where routine access requests consume time that should be going to higher-value IT work.
Google Workspace admins
Managing Groups, Shared Drives, Gmail delegation, licences, OAuth access, Chrome extensions, and other permissions that sit beyond initial provisioning.
Complex organisations
Operating across multiple sites, business entities, departments, managers, resource owners, and approval policies where one static workflow is not enough.
FAQ
Questions about automating IT access requests
What is the difference between user provisioning and access request automation?
User provisioning handles the predictable access that can be assigned when an account is created: the account itself, standard groups, licences, and organisational-unit placement. Access request automation handles what happens afterwards — requests for project groups, Shared Drives, delegation, temporary permissions, third-party applications, elevated roles, and other access that depends on context that could not be known at provisioning time. Workflow platforms like Zenphi can help connect these post-provisioning requests to approvals, Google Workspace actions, expiry, and audit records.
Why are Google Workspace access requests difficult to automate?
The requested action is usually simple; the context is not. A single request may depend on employment status, contract type, legal entity, site, current manager, resource owner, access level, duration, and additional security policy. Platforms like Zenphi can help resolve that context from existing systems and route the request according to the policy that applies to that specific combination.
Can Apps Script automate Google Workspace access requests?
Yes. Google Workspace and Admin APIs are accessible from Apps Script, so the capability is there. The challenge appears as the process grows: conditional routing becomes harder to maintain, approvals need persistent state, expiry needs reliable scheduling, audit history must be built deliberately, and ownership becomes risky when only one or two people understand the code. Workflow platforms such as Zenphi can be an alternative when the process needs shared ownership, visual logic, approvals, auditability, and easier maintenance.
Does automating access requests mean replacing our ITSM or service desk?
No. An existing helpdesk or ITSM can remain the front door. A ticket can trigger the workflow, which resolves context, applies policy, routes approvals, performs the Google Workspace action, records the result, and updates the ticket. Platforms like Zenphi can sit behind the existing service desk as the execution layer, or support form- and chat-based self-service where that model fits better.
What should an automated IT access request include?
A robust automated access request should include structured intake, context lookup, policy checks, approval routing, provisioning, confirmation, audit logging, and review or expiry. The exact lookups and policies change by request type, but the underlying sequence remains consistent across Shared Drive permissions, Group membership, licence assignments, site transfers, and similar requests. Platforms such as Zenphi can be used to coordinate these steps in one workflow.
How should temporary access be handled?
Temporary access should carry an end date from the moment it is approved, with revocation scheduled automatically. If removal depends on somebody noticing a reminder later, permissions tend to accumulate. Workflow platforms like Zenphi can help tie the approval and expiry together so temporary access is removed as part of the same governed process rather than treated as a separate manual task.
Which access request should an IT team automate first?
Start with a recurring request that has a consistent shape, an approver that can be determined from data you already hold, and an action that can be performed through Google Workspace administration. Then compare monthly volume with the number of approval layers: the qualifying request with the highest coordination load is usually the strongest first build. Platforms like Zenphi can then be used to model that request end to end before expanding to more complex cases.
What results can access request automation produce in practice?
Gordon Food Service used Zenphi behind its existing Employee Center and ServiceNow environment to automate Google Workspace service-delivery workflows including Groups, mailboxes, delegation, licences, access visibility, Chrome and OAuth requests, forwarding alerts, and Shadow IT monitoring. The team reported an 83% reduction in ticket requests and an 85% cut in admin time spent on Google Admin tasks.
Get Beyond Provisioning
Download the 21-page guide, including the access request diagnostic worksheet and a practical 30-day plan for getting the first workflow into production.
Get my free copy