Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the It Policy topic
No spam. Unsubscribe anytime.
Legislative Council staff outline Google Workspace plan; staff recommend district accounts and prohibit credential sharing
Summary
Legislative Council staff presented a plan for the Google Workspace enterprise instance, recommending district aide accounts, prohibiting sharing of member-account credentials, and describing admin access logs and audit safeguards.
Get email alerts on the It Policy topic
No spam. Unsubscribe anytime.
Legislative Council staff presented a set of decision items and recommended settings for the legislature’s Google Workspace enterprise instance, including organizational-unit structure, policies for member and district accounts for aides, and administrative access safeguards.
Director Natalie Castle and Deputy Director Manish Jani described how the instance is organized into organizational units (nonpartisan agencies, partisan staff, Senate and House units) so that settings can be applied to the entire department, to agencies, or to individual users. Manish Jani explained that “some settings can be applied at an individual level, some at an organization unit… and some are for the entire organization,” and that the recommended structure is intended to allow targeted settings for members, partisan staff, and nonpartisan agencies.
Castle and system administrator David Holder recommended that members stop sharing personal credentials with their aides and instead use district aide accounts that are delegated to the member account. Castle said that if configured correctly, “an aide has full access to the member's email if the member wants that and has full access to the member's calendar,” while preserving separate credentials for security and administrative auditability. Deputy director Jani explained delegation: an aide would log into a district address using the aide’s credentials and be delegated access to the member account; actions taken by the aide are logged and show the aide’s account on outgoing messages.
Staff recommended policy language to prohibit credential sharing and to create “district accounts” owned by members but accessible to aides via delegated accounts. The presentation included a draft example (staff used a sample address in materials) and noted administrative issues such as onboarding (“account provisioning” at new-member orientation), handling staff turnover, and what happens to member accounts when a legislator leaves office.
On privacy and access, system administrators said access by staff administrators is restricted and logged. Deputy Director Jani said there are four administrators who can access accounts for troubleshooting, and “every time they do access somebody else's account, they have to provide a reason and it gets logged. And those logs are immutable we can't delete.” Jani also said staff have an internal policy not to access accounts without permission; when access is granted by an owner, administrators record the reason.
Members raised enforcement and ownership questions: how to enforce a prohibition on shared credentials in practice; what happens to a member’s account if a member leaves or cannot grant permission (staff said they had not finalized rules and sought direction); and requests for a sandbox or demo to test workflows. Castle and Jani offered to set up test accounts and demos for members’ offices and emphasized that the recommendations currently apply only to members already migrated to the Google Workspace enterprise instance.
