ADMIN-002: Admin Role Assignments Audit

Platform
Google Workspace
Category
Admin & User Management
Severity
High
Zero Trust pillar
Governance (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Administrative role assignments should follow the principle of least privilege. Custom roles should be used instead of broad built-in roles

Recommended value

All admin role assignments reviewed with least-privilege custom roles used where possible

Remediation

Admin Console > Account > Admin roles > Review each role assignment > Replace broad roles with scoped custom roles

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for ADMIN-002
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-6(1), AC-2(7)
CIS Benchmark
4.2
MITRE ATT&CK
T1078.004, T1098.003