Quarterly Google Groups access review, without the spreadsheet
Assign a reviewer to every Google Group, certify each member, revoke access on the spot, and hand auditors the evidence trail in one click.
I want an app for running our quarterly user access reviews on Google Groups, so our IT team can stop emailing a spreadsheet around every quarter. The failure we keep hitting is that the review and the actual removal are two separate exercises: everyone responds on time, and former employees still sit in groups for weeks because remediation is a manual follow-up. In this app, certifying and revoking are the same click.
The home screen is a campaign board. An admin creates a campaign with a name, a quarter and a due date, then picks which Google Groups are in scope, either by browsing everything with List Groups or by narrowing with Search Groups. Each in-scope group gets a reviewer assigned by email address. The board shows one card per group with its reviewer, how many members have been decided out of the total, and a completion bar, plus overall campaign progress and days remaining at the top.
Opening a group shows every member as a row. Load direct members with List Memberships and inherited members with Search Transitive Memberships, then merge them into one list where each row shows the person's email, their role (member, manager or owner), and whether their access is direct or comes through a nested group. For inherited rows, use Get Membership Graph to show the path, for example "via engineering-all". Each row has a Keep button and a Remove button. Keep records the certification. Remove calls Delete Membership and actually revokes the access.
Two nuances matter on removal. First, Delete Membership returns a long running operation rather than finishing immediately, so a removed row should display as Revoking until the operation reports done and only then flip to Removed. If it fails, show the error on the row with a retry rather than claiming the person is gone. Second, someone who is only in the group transitively has no membership in that group, so removing them means acting on the nested group that actually holds them. Show the reviewer which group holds the real membership and either revoke it there or record the row as escalated to that group, so nothing is silently marked done.
When someone holds owner or manager on a group and should not, the reviewer picks Downgrade to member, which calls Modify Membership Roles instead of removing the person entirely. That decision is logged like any other.
Each group has a Prepare this review button that starts a background agent for that group before the reviewer touches it. The agent walks the membership using List Memberships, Search Transitive Memberships and Get Membership Graph, and writes findings back onto the rows: members whose email domain is outside our own, members who only hold access through a nested group and probably do not know they have it, and a group level warning when the group has no active owner. It should also write a short summary at the top of the group, something like "34 members, 4 external, 9 inherited only, no owner assigned", so the reviewer sees the shape of the problem before scrolling. Findings are notes only. The agent never keeps, removes or downgrades anyone; it just means the reviewer is working through findings rather than a raw list.
Closing a campaign is one click and writes the full evidence trail into Google Sheets with Append Values: one row per decision carrying the campaign, group, member email, role, whether access was direct or inherited, the reviewer, the decision (kept, removed, downgraded), any agent flags on that row, and the timestamp. Append to a tab so history accumulates instead of overwriting. That sheet is the artifact auditors ask for. The same screen has a Nudge reviewers action that uses the Slack Send a Message action to message each reviewer who still has undecided rows, naming which groups and how many rows are outstanding along with the due date. Nobody who is finished gets messaged.
Reviewers only see the groups assigned to them; admins see the whole campaign. Decisions are immutable once submitted, so a submitted row locks and a correction is recorded as a new dated entry rather than an edit over the original. Past campaigns stay browsable in an archive, and there is a search box where anyone can type a person's email address and see every group they were reviewed in, who certified them, what was decided and when, which answers "who approved this person's access last quarter" without digging through email.
Campaigns, group scope, reviewer assignments, agent findings and decisions all persist in the app so a review survives a refresh and can be picked up over several days. Google Groups stays the source of truth for who is currently in a group, so re-opening a group re-reads live membership and the reviewer never certifies a stale list.
What does this prompt do?
- Build a review campaign each quarter: pick which Google Groups are in scope, assign a reviewer to each one, and watch a completion bar fill as reviewers work through their lists.
- Every member shows up as a row, including people who inherit access through a nested group, with Keep and Remove buttons. Remove actually takes the access away in Google Groups instead of adding to a follow-up list, and an owner who should not be one gets downgraded to a plain member.
- A Prepare this review button per group starts a background assistant that reads the membership first and flags outside email addresses, inherited-only access, and groups with nobody genuinely in charge, so reviewers start from findings instead of a raw list.
- Closing a campaign writes the full record (group, person, reviewer, decision, time) into a Google Sheets tab for auditors and sends a Slack nudge to anyone with rows still open.
- Reviewers only see their own groups, submitted decisions lock, and past campaigns stay searchable so anyone can answer who approved a person's access last quarter.
What do I need to use this?
- A Google Workspace account with admin rights over your Google Groups
- A Google Sheets file where the evidence log should be written
- A Slack workspace for reminding reviewers who still have rows outstanding
- A list of who should review which group, which you assign inside the app
How can I customize it?
- Change what counts as a red flag: which email domains count as outside your company, whether inherited access is always worth flagging, and how long a group can sit without a real owner.
- Set the cadence and scope: every group once a quarter, or a monthly pass over the handful that touch production data.
- Point the evidence log at a different spreadsheet or a fresh tab per quarter, and choose whether reminders go to a shared channel or straight to each reviewer.
FAQs
Does the Remove button actually take the access away?
What about people who get access through a nested group?
Can reviewers see groups they were not assigned?
Can a decision be changed after it is submitted?
Will this give me the evidence an auditor asks for?
Do I need to do this every quarter?
Related templates
Stop buying stale lists. Reps run a saved search, work the results like an inbox, and only the accounts they approve ever reach your CRM.
Drag creators through Sourced to Wrapped on a board grouped by campaign, with audience stats on every card and a one-click brief for each creator.
Search creators for free, shortlist the best with your team, and spend an audit credit only when you decide someone is worth a closer look.
Pick a repricing rule, send an assistant out to check competitor pages, then approve the new prices that clear your margin floor.
See the projected bounce rate for any outbound send before it goes out, and keep the launch button locked until the list is clean enough to be safe.
One screen showing invited, completed, and shortlisted counts for every open role, plus the stalled invites that have quietly gone nowhere.
Retire the quarterly access review spreadsheet.
Certify and revoke in the same click, and hand auditors a clean evidence trail without digging through anyone's email.