Cloud workspace

Somebody has to own the accounts, the drives and the access.

Google Workspace and Microsoft 365, set up properly and administered daily — so files are findable, leavers actually lose access, and nobody is sharing a login.

Google Workspace and Microsoft 365 · Licences bought in your name · No long-term contract

A new hire's first hour

  1. 09:00automatic

    Account created

    Named properly, in the right groups, with the right licences.

  2. 09:05automatic

    Mailbox and signature live

    Sending from your domain, authenticated so it lands in the inbox.

  3. 09:10automatic

    Shared drives appear

    The folders for their role, and none of the ones for other roles.

  4. 09:15automatic

    MFA enrolled

    Before they get access, not during an audit eighteen months later.

What is cloud workspace management?

It is owning the setup, security, permissions and daily administration of a business's Google Workspace or Microsoft 365 environment: creating and closing accounts, structuring shared drives, enforcing security settings and keeping licences right — so it is nobody's part-time job and nothing drifts.

Almost every business at this size has the same story. Workspace was set up years ago by whoever was most technical, folders grew organically, one person has admin because they always have, and there are four accounts still active belonging to people who left. None of it is broken enough to fix, right up until it is.

The security half of that is genuinely urgent and takes days. The organisational half — drives that make sense, permissions on roles, onboarding that is one action — takes a few weeks and is what people actually notice week to week.

What a workspace actually holds

  • Mail and deliverabilitySPF, DKIM and DMARC set so quotes reach the inboxManaged
  • Accounts and groupsJoiners set up, leavers removed the same dayManaged
  • Shared drivesA structure people can find things in, not a personal driveManaged
  • Access and MFAWho can see the customer list, and proof of itManaged
  • Retention and backupDeleted files recoverable past the platform defaultManaged
Licences and the tenant stay in your name. If we part company, nothing has to be rebuilt.

What's included

What management covers

  • Setup and configuration

    Domain and DNS, MX records, mail authentication, security baselines, and a shared drive structure designed before anyone starts putting files in it.

  • Shared drive architecture

    Folders organised around how the business works — by job, by client, by year — with permissions attached to roles rather than to individuals who then leave.

  • Onboarding that takes minutes

    A new hire gets their account, groups, drive access, calendar and licence from one action, rather than from someone remembering six separate steps.

  • Offboarding that actually closes access

    Account suspended, sessions revoked, mail forwarded, files transferred to a named owner. The step most businesses do partially, months late, if at all.

  • Security baselines enforced

    Multi-factor authentication on every account including the admin ones, device and session controls, suspicious login alerting, and external sharing rules that match the business.

  • Email deliverability

    SPF, DKIM and DMARC published and verified so your mail reaches inboxes. Routinely misconfigured, invisible until it matters, and the reason "our emails go to spam".

  • Licence and cost review

    Which tier each person actually needs, and which licences belong to people who left. This is usually where the engagement pays for itself in the first quarter.

  • Ongoing administration

    Someone who owns the environment: access requests, permission fixes, new accounts, alerts reviewed. Not a ticket queue where requests go quiet.

The finding nobody expects

The licences for people who left usually pay for the project

Every workspace audit includes a licence review, and the result is reliably the same: accounts still being billed for staff who left, several people on a higher tier than their job needs, and at least one subscription nobody can identify the owner of.

It is not a headline service and it is not clever work. It is just what happens when nobody has looked at the billing page in three years, and it means the cleanup often arrives cost-neutral in the first quarter. Those dormant accounts are also a security problem — an active account with an old password and no MFA is the most common way a business this size gets compromised.

How it works

Secure first, then restructure

  1. Audit the environment

    Week 1

    Every account including the dormant ones, sharing settings, external access, admin roles, licence assignment and mail authentication. Read-only, no changes.

  2. Secure it

    Week 2

    MFA everywhere, admin roles reduced to who genuinely needs them, dormant accounts suspended, external sharing brought under a rule. Fast, and it is the part that matters most.

  3. Restructure the drives

    Weeks 2–4

    A folder architecture that matches how work is organised, with permissions on roles. Migration done in stages so nobody loses access to a live job mid-week.

  4. Automate and hand over

    Weeks 4–5

    Onboarding and offboarding workflows, documented processes, and a short walkthrough for whoever handles requests internally.

Who we do this for

Six kinds of business, six different problems

Construction & trades
Field teams that need job files on a phone, and office staff who need the same folder to make sense from a desk.
Professional services
Client-organised file structures with real permission boundaries, because not everyone should see every client.
Healthcare clinics
Tight access control and clear audit trails around anything patient-related, with sharing locked down by default.
Real estate teams
Agents working from phones, shared listing documents, and accounts that close properly when someone moves brokerage.
Local business services
Small teams that need email that works, files that are findable, and accounts nobody shares.
Manufacturing
Production schedules, drawings and supplier documents in one place, with version history that actually gets used.

Fit

Who this suits, and who it doesn't

This is a good fit if

  • You have between roughly 5 and 100 people and nobody whose job the workspace is.
  • Nobody can say with confidence which accounts are still active.
  • Files live in personal drives and email threads rather than a shared structure.
  • Staff turnover means onboarding and offboarding happen often and inconsistently.
  • Your email deliverability is poor and nobody has checked the authentication records.

This isn't the right fit if

  • You have an internal IT team already administering it well. Then this is duplicated cost.
  • You have fewer than about five people and a simple setup that works. A one-off configuration is the better spend.
  • You need formal compliance certification. Different discipline entirely — we would point you at a specialist.
  • You want the cheapest per-seat administration available. We are not competing there.

Cloud workspace management — frequently asked questions

What is cloud workspace management?

It is the setup, security, permissions and day-to-day administration of your Google Workspace or Microsoft 365 environment — onboarding and offboarding people, structuring shared drives, enforcing security settings and keeping licences correct, so nobody in the business has to own it part-time.

Do you support both Google Workspace and Microsoft 365?

Yes, across all business tiers of both. We handle setup, migration between them, and ongoing administration. Most service businesses are better served by Google Workspace; businesses with heavy Excel or existing Microsoft licensing usually stay on 365.

Can you clean up a messy existing environment?

That is the most common engagement. Unorganised drives, inconsistent permissions, accounts belonging to people who left years ago, sharing links open to anyone with the URL. We audit it, restructure it, and put processes in place so it stays clean.

Do you handle onboarding and offboarding?

Yes, as standardised workflows. A new hire gets their account, groups, drive access, calendar and licence in one action. A leaver has access removed, sessions revoked, mail forwarded and files transferred to a named owner — completely, and on the day.

How does this improve security?

Multi-factor authentication on every account including admins, dormant accounts suspended, admin roles reduced to who needs them, external sharing brought under a rule, and login alerting switched on. Most breaches at this size are an old account and a reused password, not a sophisticated attack.

Is it worth it for a small team?

Often yes, precisely because small teams have nobody whose job this is. Below about five people the honest answer is usually a good initial setup and then very little. Between five and a hundred, the absence of an owner is what causes the mess.

Can you integrate the workspace with our other tools?

Yes. CRM, scheduling, VoIP, automation platforms and industry-specific software. Connecting the workspace to the CRM is usually the highest-value one, because it puts documents where the job record is rather than in an email thread.

What happens when someone needs help?

They contact us directly and get a person who knows the environment. Access problems, permission fixes, new accounts and general requests are handled the same day. No ticket queue, and no requests quietly expiring in one.

How long does it take?

The security work is days. A full audit and restructure is typically two to four weeks depending on how much data is moving and how many people are working in it. Migrations between platforms take longer and are staged so nobody loses access mid-job.

How is it priced?

A one-off cleanup or migration is quoted as a project. Ongoing administration is a predictable monthly fee based on user count. Licences are bought in your name directly from Google or Microsoft, so the environment is yours regardless of who administers it.

Are we locked into a contract?

No. Work is monthly, the environment and licences are in your name, and the documentation is written so another administrator could take over. If the service is worth having you will keep it; a contract is a poor substitute for that.

Start with the audit. It's free and it takes days, not weeks.

We look at every account, the sharing settings, the admin roles, the backups and the licence bill, and send you a written list of what is exposed and what is wasted. No obligation, and useful even if you never hire us.

Mathew Brown, founder of Marketing & Technology

You talk to Mathew.Not an account manager, and not a sales team.