Collect access
Pull Group memberships, Shared Drive access, Drive permissions, delegated mailboxes, licences and OAuth grants into a review process.
Run recurring access reviews, route each decision to the right owner, automatically change or revoke access, and generate a complete review record — without deploying a full IGA platform just to govern Google Workspace.






Every quarter, the same work comes back: export permissions, build a spreadsheet, email managers, chase responses, collate decisions, make the changes by hand, then reconstruct evidence that it happened.
Pull Group memberships, Shared Drive access, Drive permissions, delegated mailboxes, licences and OAuth grants into a review process.
Send reports to the people who can judge the access, wait for replies, follow up with non-responders and resolve exceptions.
After the review, IT still needs to make the changes and assemble a record of what was reviewed, decided and executed.
The real problem is not only the hours. It is that evidence is often assembled after the fact instead of being produced by the review process itself.
Zenphi does not impose one fixed certification process. You assemble the review from native Google Workspace actions, approval tasks, conditions, remediation steps, reporting and dashboards.
Retrieve the users and permissions that need to be reviewed. Build the population dynamically from Google Directory, Groups, OUs, selected resources or external-user status.
Send a task to the resource owner, the user's manager, IT, Security, a fixed approver or multiple required approvers. Routing can use Google Directory data and fallback logic.
Standard access can follow one path while sensitive resources, external users or privileged access follow stricter review and escalation rules.
Keep access, revoke it, change the permission level, transfer ownership, escalate an exception or trigger another workflow. Zenphi can re-check current access before remediation.
Set task expiration rules and choose what happens next: reminder, escalation, hierarchy-based fallback, second approval or automatic revocation.
Capture reviewer identity, access state, decisions, comments, timestamps, remediation and outcomes. Generate a final PDF review report as a workflow step.
Different access types can use different reviewers, deadlines, escalation paths and remediation rules.
Route to the Group owner. Keep or remove membership. Log the decision and reviewer identity.
Flag external accounts, route them to the resource owner, escalate overdue reviews and revoke access after the policy deadline if required.
Require the resource owner and Security to approve. If the reviewer is the affected user, route to a different approver.
Trigger from offboarding, review remaining access, remove permissions and transfer file ownership in the same wider process.
Zenphi is strongest where it has first-class Google Workspace actions. External systems can be incorporated through APIs, but they are not the core positioning for this page.
| Review area | What the workflow can do |
|---|---|
| Google Groups | List membership, route for review, remove membership |
| Shared Drives | List users and roles, review access, change or remove permissions |
| Google Drive permissions | Retrieve current permissions and remediate rejected access |
| Delegated mailboxes | Identify delegated access, route it for review and remove it |
| Licences | Review licence assignments and act on the result |
| OAuth grants | Include OAuth access in Google Workspace review workflows |
| External users | Flag accounts outside the internal domain and route their access separately |
| Offboarding | Review and remove remaining access and transfer file ownership |
Do not wait until the audit to reconstruct what happened.
Zenphi can retain the access state presented to the reviewer, who responded, what they decided, comments, timestamps, remediation actions and the result. Reviewer email and user ID can be associated with Google Directory data, and the workflow can generate a final PDF review report.
User, resource, access type, permission or role, and the point-in-time state presented for review.
Reviewer email, user ID, Directory-enriched identity, decision, optional comment and timestamp.
Remediation path, permission change or revocation, result and the final review report.
Custom dashboards can represent the review data you choose to store in Zenphi Tables, BigQuery or another supported data source.
Completed, outstanding and overdue review tasks by reviewer, department or process.
Approvals, revocations, permission changes and other results captured by the workflow.
If prior review state is explicitly stored, dashboards and workflow logic can compare current and historical data.
Zenphi helps you automate recurring reviews, route decisions to the right people, remediate access, and keep the evidence — without adding another heavyweight governance project.
For those requirements, dedicated platforms such as SailPoint or Saviynt are the more appropriate category.
Show us the spreadsheet, email chain or recurring review process you use today. We will map how the routing, decisions, escalation, remediation and evidence can run as a Zenphi workflow.
Common questions about running recurring Google Workspace access reviews with Zenphi.
Short version: Zenphi can automate the review process end to end — from pulling current Google Workspace access and routing decisions to the right people, through remediation, escalation, reporting and audit evidence.
Yes. A standard scheduled workflow trigger can start the review automatically on a monthly, quarterly, annual or custom cadence.
Yes. A review can be triggered by another workflow, such as offboarding, as well as by Google Group events, Google Audit events, form submissions or a manual start.
Yes. The workflow can pull the current population from Google Directory every time it runs. For example, a quarterly Finance review can automatically include whoever is currently assigned to the Finance department.
Yes. Reviews can be scoped to specific users, departments, OUs, Google Groups, Shared Drives, external users or other defined populations.
Yes. Different workflows can run on different schedules, allowing higher-risk access to be reviewed more frequently than standard access.
Yes. Zenphi can retrieve Group membership, route it for review and automatically remove membership when required.
Yes. Zenphi can list who has access to Shared Drives, identify their access roles, route those permissions for review and change or remove access automatically.
Yes. Current Drive permissions can be retrieved, presented for review and remediated automatically based on the reviewer's decision.
Yes. Zenphi can identify delegated mailbox access, route it to the appropriate reviewer and remove the delegation automatically when required.
Yes. Licence assignments can be incorporated into the review workflow and changed based on the outcome.
Yes. OAuth grants can be included in Google Workspace access-review workflows.
Yes. Zenphi can identify accounts that are not associated with the organisation's internal domain and route that access through a dedicated review path.
Yes. A review can start with a user or user population and examine their access, or start with a resource such as a Shared Drive or Google Group and review everyone who currently has access.
Yes. Reviews can be routed to the resource owner, the user's manager, IT, Security or any other reviewer required by company policy.
Yes. Reviewer assignment can use Google Directory data such as department and reporting hierarchy, as well as resource ownership information.
Yes. Different approval tasks can route different access types to different reviewers — for example, Shared Drive access to the resource owner and licence assignments to IT.
Yes. Approval tasks can be assigned to multiple people and configured so the review is completed only when the required approvers have responded.
Yes. Google Directory data can be used to route an overdue or escalated review to the reviewer's manager or another appropriate person.
No. People receiving access-review approval tasks do not need a Zenphi account to respond.
No. Zenphi does not charge per user or per workflow run, so the pricing does not increase simply because more employees or reviewers are involved.
Yes. A rejected decision can trigger the appropriate access-removal action automatically.
Yes. A review decision can trigger a permission change, such as reducing a user's access level, rather than removing access entirely.
Yes. Approval tasks can contain custom decision options, with each option connected to a different workflow path such as keep, revoke, change permissions, transfer ownership or escalate.
Yes. If company policy requires it, an expired review task can trigger automatic revocation.
Yes. Review tasks can have deadlines, and the workflow can automatically send reminders or route an outstanding decision through an escalation path.
Yes. Different approval tasks or workflow branches can have their own deadlines, reminders and escalation paths.
Yes. The workflow can retrieve the current access state again before executing remediation.
Yes. The workflow can retain what was reviewed, the access level, reviewer identity, decision, comments, timestamps, remediation actions and outcomes.
Yes. A final PDF review report can be generated automatically as a workflow step.
Yes. The permission details presented during the review can be retained so the final record shows what the reviewer was deciding on.
Yes. The respondent's email and user ID are captured and can be matched to Google Directory data for inclusion in the final report.
Yes. Custom dashboards can display review data such as completed tasks, outstanding reviews, approvals, revocations, overdue items and remediation outcomes.
Yes. Historical access and review data stored in Zenphi Tables, BigQuery or another connected data source can be used in dashboards and future workflow logic.
Yes. An offboarding workflow can retrieve and remove the departing user's Google Workspace access and transfer file ownership as part of the same process.
Yes. A workflow can record the reviewer's confirmation and retain the evidence without triggering an access change.
Bring one access review you currently run manually and map the routing, decisions, escalation, remediation and evidence into one process.