Free ebook 22 pages — Build an AI Agent, Code-Free. Decisions, architecture, access controls
Get your free copy →

Free · IT Operations Guide

Beyond Provisioning

Automating IT Access Requests Across Complex Google Workspace Organisations

A practical 21-page guide for lean IT teams supporting multiple locations, departments, roles, entities, and approval structures — focused on the access work that begins after the user account already exists.

  • Why access requests stay manual even when user provisioning is already automated
  • How to resolve location, entity, manager, resource-owner, and policy context automatically
  • The eight-step anatomy of an end-to-end automated access request
  • What a platform needs to handle approvals, Google Workspace actions, expiry, and audit history
  • A diagnostic worksheet and 30-day plan for choosing the right first workflow

21-page practical guide + access request diagnostic worksheet

Get your free copy

21-page PDF. Includes the access request diagnostic worksheet and a 30-day starting plan.

What's inside

From the access request problem to a 30-day starting plan

  1. 01Who this guide is for
  2. 02The work that starts after the account's created
  3. 03How one request becomes ten decisions
  4. 04The three layers of access management
  5. 05And what about Apps Script?
  6. 06The anatomy of an automated request
  7. 07The execution layer
  8. 08Seven questions to ask any platform
  9. 09Three organisational patterns
  10. 10Two architectures for IT service delivery
  11. 11In production: Gordon Food Service
  12. 12Gordon Food Service's IT delivery architecture
  13. 13Where to start
  14. 14The diagnostic
  15. 15Access request diagnostic worksheet
  16. 16Reading the result
  17. 17A 30-day starting plan

Why it matters

The access layer is where manual IT work accumulates

83%

reduction in IT ticket requests reported by Gordon Food Service after automating Google Workspace service-delivery workflows.

85%

cut in admin time spent on Google Admin tasks in the same production deployment.

5–10

recurring access-request types often account for the bulk of request volume — enough to identify a practical first automation.

Source: Gordon Food Service case study and access-request diagnostic guidance featured in the guide.

Who it's for

Written for IT teams managing complexity after provisioning

Lean IT teams

Supporting growing organisations where routine access requests consume time that should be going to higher-value IT work.

Google Workspace admins

Managing Groups, Shared Drives, Gmail delegation, licences, OAuth access, Chrome extensions, and other permissions that sit beyond initial provisioning.

Complex organisations

Operating across multiple sites, business entities, departments, managers, resource owners, and approval policies where one static workflow is not enough.

FAQ

Questions about automating IT access requests

What is the difference between user provisioning and access request automation?

User provisioning handles the predictable access that can be assigned when an account is created: the account itself, standard groups, licences, and organisational-unit placement. Access request automation handles what happens afterwards — requests for project groups, Shared Drives, delegation, temporary permissions, third-party applications, elevated roles, and other access that depends on context that could not be known at provisioning time. Workflow platforms like Zenphi can help connect these post-provisioning requests to approvals, Google Workspace actions, expiry, and audit records.

Why are Google Workspace access requests difficult to automate?

The requested action is usually simple; the context is not. A single request may depend on employment status, contract type, legal entity, site, current manager, resource owner, access level, duration, and additional security policy. Platforms like Zenphi can help resolve that context from existing systems and route the request according to the policy that applies to that specific combination.

Can Apps Script automate Google Workspace access requests?

Yes. Google Workspace and Admin APIs are accessible from Apps Script, so the capability is there. The challenge appears as the process grows: conditional routing becomes harder to maintain, approvals need persistent state, expiry needs reliable scheduling, audit history must be built deliberately, and ownership becomes risky when only one or two people understand the code. Workflow platforms such as Zenphi can be an alternative when the process needs shared ownership, visual logic, approvals, auditability, and easier maintenance.

Does automating access requests mean replacing our ITSM or service desk?

No. An existing helpdesk or ITSM can remain the front door. A ticket can trigger the workflow, which resolves context, applies policy, routes approvals, performs the Google Workspace action, records the result, and updates the ticket. Platforms like Zenphi can sit behind the existing service desk as the execution layer, or support form- and chat-based self-service where that model fits better.

What should an automated IT access request include?

A robust automated access request should include structured intake, context lookup, policy checks, approval routing, provisioning, confirmation, audit logging, and review or expiry. The exact lookups and policies change by request type, but the underlying sequence remains consistent across Shared Drive permissions, Group membership, licence assignments, site transfers, and similar requests. Platforms such as Zenphi can be used to coordinate these steps in one workflow.

How should temporary access be handled?

Temporary access should carry an end date from the moment it is approved, with revocation scheduled automatically. If removal depends on somebody noticing a reminder later, permissions tend to accumulate. Workflow platforms like Zenphi can help tie the approval and expiry together so temporary access is removed as part of the same governed process rather than treated as a separate manual task.

Which access request should an IT team automate first?

Start with a recurring request that has a consistent shape, an approver that can be determined from data you already hold, and an action that can be performed through Google Workspace administration. Then compare monthly volume with the number of approval layers: the qualifying request with the highest coordination load is usually the strongest first build. Platforms like Zenphi can then be used to model that request end to end before expanding to more complex cases.

What results can access request automation produce in practice?

Gordon Food Service used Zenphi behind its existing Employee Center and ServiceNow environment to automate Google Workspace service-delivery workflows including Groups, mailboxes, delegation, licences, access visibility, Chrome and OAuth requests, forwarding alerts, and Shadow IT monitoring. The team reported an 83% reduction in ticket requests and an 85% cut in admin time spent on Google Admin tasks.

Get Beyond Provisioning

Download the 21-page guide, including the access request diagnostic worksheet and a practical 30-day plan for getting the first workflow into production.

Get my free copy