Getting Started with
GAT Labs

The Guide for Google Admins

This guide provides a step-by-step walkthrough for using the GAT Labs Suite to audit and secure your Google Workspace environment. It covers essential functionalities to help you set up the tools and safeguard your domain effectively from the start

Initial Setup

1. Installing GAT+:
  • Follow installation guidelines.

GAT+ is a Google Workspace Audit tool that by default can be installed only by the Super Admin of the Domain.

Install GAT+

How to install GAT+  Video

Step 1:

First login to your domain with Super Admin Account.

Navigate to >  Google Workspace Marketplace   > You can also search for GAT+ in the search bar.

When GAT+ is selected click on Admin install 

A pop-up window will be displayed click on “Continue“.

Then a new pop-up will be shown with all the permissions required.

Scroll down to the bottom.

  • Under: Install the app automatically for the following users
    • Select “Everyone at your organization”
      • Note: installing on certain groups or org. units will not give clear and accurate data stats of the domain data
    • Enable the checkmark – “I agree to the application’s terms…”
  • Click on Finish

Note: You can not install it from an incognito window unless you are signed in to your Super Admin account.

Result

GAT+ will be installed.

When installed, click on the Goole apps button and scroll down to the GAT+ icon

This will be the initial login and the initial scan will be started.

The time for the initial scan to complete will depend on the size of the domain.

  • The number of users
  • The number of Drive files etc

Estimate time of the initial scan

We estimate the initial scan to take 30 min per 1 million files. When the scan is completed an automatic email will be sent to the Admin account.

Note: Subsequent scans will be faster.

When the initial scan has been completed, the data from your domain will be displayed in the GAT+ console.

Data access

To view and access the full domain data (metadata), we recommend GAT+ be installed domain-wide and all permissions be granted.

Access GAT+ by Super Admins only

By default the tool can be accessed ONLY by Super Admins of the domain.

Non-admin accounts can see the GAT+ application under their Google Apps option, but CANNOT launch the tool itself.

When the tool is installed domain-wide, it can be launched from the Google Apps menu.

Click on the Google Apps menu button and scroll down to third-party apps and click on GAT+

This will launch GAT+ into a new window on your browser.

Source: Knowledge Base 

  • Grant necessary permissions through the Google Admin console.

Is GAT+ failing to run? Check these options in your Admin Console

How to make sure GAT+ is running correctly and showing correct information from your domain?

Navigate to Google Admin console 

Click the Google Apps menu button on the top right corner of your Chrome session and click on the Admin button

In the Google Admin console navigate to Apps > Google Workspace Marketplace apps > Apps list

Click on the GAT+ app

You will need to click and grant access to GAT+

  • Distribution – it has to be Enabled for all organizational units and groups
  • Data Access – status Granted
  • Grant access – click to grant access to GAT+

IMPORTANT NOTE: As Google has deprecated their ‘Google Sites’ product, GAT cannot be granted access to that. You may see that the status is only ‘Partially Granted’ during this step. Though once you have clicked the ‘Grant access’ button you can consider this step finished.

Access by Super Admin Only

By default the tool can be accessed ONLY by Super Admins of the domain. Non-admin accounts cannot login to the tool.

To enable Classroom auditing

Navigate to Apps > Google Workspace > Classroom > Data Access

Make sure that Classroom API – is turned on: ‘Users can authorize apps to access their Google Classroom data’

2. Configure Basic Settings:
  • Customise User profile settings.

Configuring your User Profile Settings and Preferences

Each Google Workspace Super Admin or Delegated Auditor within GAT+ can have their own user profile settings and preferences configured.

Configuring Settings

To configure your settings, navigate to GAT+, and click on your user name at the top right corner of the side menu.

GAT+ | Configuring your User Profile Settings and Preferences 1

Within the Settings area, you will see Common, Querying, Language tabs.

Common

  • Change Timezone (may affect time stamps on exported reports)
  • Change Date Format
  • Change Time appearance
  • Records Shown per page

Querying 

  • General time-out settings
  • Drive audit time-out setting
  • Gmail/Email audit time-out setting

The above settings influence the waiting time for filter searches within Drive or Email sections. If time expires while waiting for a search to complete, a time-out error will be shown.

Language

  • Change language within the GAT+ tool to English or Polish
3. Define Administrative Roles::
  • Assign Delegated Auditors.

Why create a delegated auditor in GAT+?

By default, only Google Workspace Super Admins have access to the GAT+ tool.

With the delegated auditors functionality Super Admins can assign users to audit or analyze others within their domain without ever having access to the Google Workspace Admin Console (admin.google.com). 

How is this useful? Many organizations have multiple offices, departments, campuses, or locations with the delegated auditors feature you can assign the right person to perform the auditing of a group or organizational unit.

Here are a few examples of when delegated auditors could be used: 

  • A sales manager would like to create reports for his/her sales team covering data across all of the different Google apps like Gmail and Google Drive. 
  • A school IT Director would like to give another IT member access to GAT+ but not to his/her Google Workspace Admin Console. 
  • A Super Admin would like to delegate responsibility to his internal auditing team to give them scope over a specific Org unit. 

Creating a Delegated Auditor

In GAT+ navigate to Configuration > Delegaed auditors > + button (Add new auditor)

View the auditor and fill in the details for the Auditor you want to create.

  • Product – select the product needed
    • GAT+ – create Auditor for GAT+
    • Shield  – create Auditor for Shield
  • Auditor – select the user who will be the Auditor
    • User – select individual user to be the Auditor
    • Group – select group of users to be the Auditors
    • Org. Unit – select org. unit of users to be the Auditors
  • Scope – select the users to who the Auditor will audit and have access in GAT or Shield. Users will be under the scope of users the Auditor will manage.
    • User – select individual user to be the Auditor
    • Group – select group of users to be the Auditors
    • Org. Unit – select org. unit of users to be the Auditors
      • Include sub. org. units 

  • Access areas – select what areas in GAT+ and Shield the Auditor will have access to. Access areas visible to the Auditors

  • Enable any of the Audit areas
    • Enabled – the area will be visible to the Auditor
    • Disabled – the area will not be visible to the Auditor

Super Admin 

Super Admin (warning! Can change permissions and more like Google Workspace Administrator)

This is a “custom” Google Super Admin within GAT+ only.

The User with Super Admin Delegated auditor will have the same access Super Admin from Google would have – but Only within GAT+ and not within the Google Admin console.

  • Enable changes – Enabled by default – Unchecking will give ‘Read-only’ access to GAT for the Auditor
  • Valid to – select the time until the Auditor will be enabled.
    • Indefinite expiration period
  • Active – enable or disable the Auditor

  • Click on Save to create the Delegated auditor.

Giving GAT+ Auditor Additional Privileges

When a GAT+ delegated auditor policy is active, you can give the auditor additional privileges. Those privileges allow the Auditor to make changes via Export/Import functionality.

With these additional privileges, the auditor can

  • Export any metadata to a Google spreadsheet
  • Edit any field in the spreadsheet
  • Import the spreadsheet back in to confirm the changes.

Note: A Super Admin has these types of privileges by default.

In Delegated Auditors > click on “lock icon” under Actions to add Additional permissions

Manage additional permissions – in the following areas:

  • Classrooms import
  • Groups import
  • Users import
  • Automatic email forwarding
  • Email delegation
  • Students import
  • ChromeOS device import

For example: 

  • If Email delegation is enabled, the Delegated auditor will be able to use Unlock and request enablement of Email delegation.
  • If Email delegation is not enabled as additional permission, the Delegated auditor will not be able to use Unlock and request the action.

Add the Additional permissions and click on the Save button

Access GAT+ as Delegated auditor

Your delegated auditor can now launch and access the tool from their Google Apps button.  

In the Google Chrome session click on the Google Apps menu button scroll down in the menu and click on GAT+

Accessing the tool as a delegated auditor

When the Auditor logs into GAT+, they will have access only to the selected by Admin audit areas

In the Auditing Areas, they can utilize all of the features of GAT Unlock of course with Security Officer approval.

  • They can modify and remove permission to download or view file content.
  • They can download emails, view emails, and remove emails from users’ Gmail accounts.
  • They can set up email delegation to give one user direct delegation into another user’s Gmail account.
  • They can remove and add permissions from Drive and much more

Security Officer

If the Auditor is also a Security officer – they will be able to see the Security Officer section in GAT+

  • Configuration > Security officer
  • How to assign a Security Officer.

What is GAT Unlock?

Set Up Security Measures

Products: GAT+ & Unlock

2-Step Verification (2FA):
  • Monitor and alert on disabled 2FA .

Two-factor authentication (2FA) is a form of authentication that requires only two authentication factors. The first factor is your username and password and the second factor is another method that you choose.

GAT+ Alert Rules functionality can be configured by a Google Workspace Super Admin when these alerts are triggered by end-users the recipients of the rule get notified.

There are multiple types of Alert options:

  • Applications
  • Emails
  • Drive
  • YouTube
  • Mobile Devices
  • Users
  • User Logins

For users, you can set up different alerts and be notified of different actions.

  • Notify on Two-Factor Authentication (2FA) backup codes used
  • Notify on 2FA disabled
  • Notify when an account has not been used for a period of time
  • Notify when an account is used again after x days of inactivity
  • Notify when storage exceeded

Configure an Alert Rule

Navigate to GAT+ → Configuration → Alert Rules 

2FA

Click on the “+ sign” and a new window will be displayed, fill in the details.

2FA

  • Name – enter the name of the Alert.
  • Enabled – checkmark to enable or disable the Alert.
  • Type – Users.
  • Scope – select what users for which alert will be triggered.
  • Recipients – Add a user email or group email for Email notifications, or leave as blank ( this will show alerts only in the alerts section).
  • Select – Notify on 2FA disabled.
  • Click on the Save button to save the rule.

Result

The rule can be viewed, edited, or removed in Alert rules

Two-Factor Authentication (2FA)

When the Alert is triggered they will be generated and displayed in Audit & Management → Alerts 

Video How-to: Two-Factor Authentication (2FA) Alert

Data Loss Prevention (DLP)
  • Set alert for sensitive information sharing.
External Sharing and Permissions
  • Remove public and ‘public with link’ access.
  • Automate removal of outdated shares .

Audit your Google Workspace Environment

Products: GAT+ & Unlock

Users and Devices:

1. Audit login behaviour.

2. Identify inactive or idle accounts.

3. Monitor and manage devices.

4. Set up location-based alerts to monitor logins from unusual regions.

5. Audit users 3rd party apps.

Google Drive:

1. Audit externally shared files.

2. Find and resolve duplicate or orphaned files.

3. Export detailed Drive scheduled reports.

Emails:

1. Monitoring email activity and Storage.

GAT+ is a powerful audit and security tool for Google Workspace. It provides admins with an extensive and detailed overview of their entire domain.

Email audit is one of the many features GAT+ offers, whereby Google Workspace admins can view all incoming and outgoing emails across their domain.

Email audit

Run different reports for all emails coming into your domain.

Email stats by the size of emails received/sent

Navigate to GAT+ > Email > User statistics

There you’ll see Email stats for your domain users. You can see the size of received and sent internal and external emails

In “User statistics” click on Column visibility and enable the fields.

  • Bytes received external
  • Bytes received internal
  • Bytes sent externally
  • Bytes sent internally

Daily Email statistics

Select a user and pick a date.

  • User statistics – navigate to User statistics
  • Daily statistics – click on Daily statistics
    • Select user and Date > Filter data

The result will show the user and the bytes of sent/received internal and external emails for the chosen day.

The result can be exported into Google Sheets or CSV.

Scheduled Email audit report

This can also be set up as a Scheduled report.

Monthly Email audit report

The Admin can also apply a more extensive filter for a longer period of time. Per month for example.

  • Apply a filter in User statistics
  • Type – change type to Stats by date range and users 
  • Date from – enter date from
  • Date to – enter date to
  • Local user – enter local user, group, or org. unit
  • Scheduled – click to set up a Scheduled report (optional)
  • Apply – run the filter

Result of monthly data

You can see the chosen user and all the data (bytes) sent/received by internal/external users.

The “Email” will show the user from which the email was sent or received.

  • Dave from Sales@gatlabs.com
  • Dave from Dave@gatlabs.com

2. Detect and delete phishing or suspicious emails.

With the GAT+ tool, Google Workspace Admins can identify and delete emails of any user in your domain. There are several reasons why an admin would want to do that, but the biggest concern is the security risks posed by them. GAT+ has been designed to offer the ability to navigate the emails of your concern and delete them.

Some of the scenarios that may apply are as follows:

  • an email containing sensitive data
  • an email wrongly addressed
  • phishing or spamming

Identify emails that are a security risks

In order to find the emails of your concerns, navigate to GAT+ and apply a filter that helps to identify them.

There are several filtering options that can be applied depending on your use case. Apply a definition that best suits your search purpose. Once ready, apply the filter.

We show a proposal of the filter below that searches for emails containing specific wording in the title of the email: ‘for example ‘sensitive data’. 

Request access permission to emails for security auditing

As a result of the above, GAT+ returns the metadata based on the filter applied.

You can have a quick overview of the metadata that is returned and decide on what email you wish to have closer look at by selecting them for further investigation (select All or specific results).

Next, you can request access to view the content of those emails.

To create a request to access the emails’ content, click on the ‘Email operations‘ button. From the drop-down menu select the option ‘Create new access request’.

When requesting access, specify the timeframe, add a message for internal communication, and select the option Allow removing emails. When ready, send a request for review.

The request can be verified by Security Officer.

Get Security Officer’s approval

The Security Officer can view the request under Access Permissions tab once signed in to GAT+ dashboard, and approve it from there.

Review emails’ content and delete the ones that pose security risks

Once the request to access the emails’ content is approved, the requestor of the access can now navigate to Email audit in GAT+ and apply the same filter as before.

GAT returns the same results with the additional options enabled under the ‘open padlock’ icon on the right-hand side.

The email content will be displayed in GAT’s new window from there the email details can be reviewed. Upon that review, you can decide to move forward and remove the emails.

To trigger such an action, select the email you reviewed, navigate again to Email operations button, and select the option Remove e-mails (permanently).

Once the option to remove the email is selected, the last verification message comes up. Once confirmed, the email will be removed.

Details can be found in Admin log.

Restore deleted emails

If emails are deleted permanently and done by mistake they can be resoted via the Admin console for 25 days from the day of deletion.

The process is explained in this Google article 

Related Posts

Google Calendar:

1. Audit shared calendar permissions.

GAT+ supports full domain-wide automatic Google calendar discovery and exposure classification.

GAT discovers all calendars automatically. It also classifies them by exposure type.

Filtering for Particular Calendar

You can click on the Apply Custom filter button to search for a particular calendar.

There is a multitude of different Search Operators you can use and also combine together to find the Calendar of interest.

  • ACL Type equal External
  • In account equal …

ACL Type search operator will show you calendars based on how they were exposed.

In account search operator will show you a user who appears in many different Calendars.

Calendar tab in User audit

You can now view the aggregated information about Calendars in the User Audit, Calendar tab.

In the Calendar tab, you can view calendar information per user, and the number of events the user has which has Passed (Past) or will happen in the Future.

GAT+: Google Calendar Audit 4

The values under Calendars, Past events, Future events, and Total columns are all clickable.

Clicking on any value will take you to the Calendar audit section so you can view those events in detail.

Calendar Events tab in Calendar Audit

In addition to the automatic calendar discovery, GAT+ can report on domain-wide automatic event discovery.

Super Admins or Delegated Auditors can examine the past or future appointment lists of users on the domain.

This can be particularly useful for departing employees who may have future appointments management need to be aware of. You might want to check out GAT Flow for Calendar management and Offboarding actions for Calendars.

GAT+: Google Calendar Audit 5

Actions you can take on Events

  • Ability to delete an instance of an event
  • Ability to delete all recurring events
  • Remove users from events and/or recurring events

Calendar Resource tab in Calendar Audit

Each calendar event that is created can use or book a resource (office board room, office facilities, projectors, etc).

When a resource has been taken by a calendar event it becomes unavailable to be selected by other users when they are creating a calendar event.

You can view all available resources within the Calendar Resources tab.

Selecting any of the resources’ names will redirect you to all Calendar events associated with the Calendar Resource.

Clicking the eye icon next to each calendar event you can view the associated resource.

A pop-up window will be displayed showing General, Conference data, and Calendar resources tabs.

Click on the ‘bin’ icon to remove the resource from the selected Calendar event. When the resource has been removed, the resource is freed up to be used by other calendar events.

2. Delegate and manage calendar access.

The Google Calendar audit in GAT+ provides an extensive overview of every calendar created in your domain.

Using Calendar an Admin can delegate calendar access to other users from the domain or external users.

This can be done by following a few easy steps.

Select calendars

Navigate to the Calendar audit section from the menu on left

Apply filter and search for the Calendar you want to Delegate access to 

You can apply any filter to find the result you need.

Apply calendar delegation

When the result is found apply the delegation.

Click the “pen” icon from the right side under Actions

A pop-up window will be displayed Calendar Permissions Management 

Select the permission you want to grant the Delegated user.

  • Owners – Add user as the second Owner of the calendar –
  • Writers – Add user as a writer to the calendar
  • Reader – Add user as a reader to the calendar
  • Free/Busy readers – Add user as a Free/Busy reader

In the field Email/Domain name – Enter the Email/Domain name of the User you want to add

Click on the Add button

Click on the Save button

Result

As a result of the action, the calendar will be edited and an additional user will be added as Delegated user access 

In the Calendar audit, you can see the selected calendar has a new Writer added

Remove user from the calendar

Note: Primary calendar owner – Cannot be removed 

The same action can be taken to Remove users from the calendar.

Find the calendar click on the “pen” (edit) icon, click on the “bin” icons beside the name you want to remove.

Automate User Management

Products: GAT Flow

Role Management:
  • Set Admin roles and privileges.
Onboarding:
  • Automate onboarding workflows.
  • Transfer multiple folders to multiple users in bulk.
Offboarding:
  • Remove access and secure the leaver account.
Advanced Features:
  • Conditional Workflows for dynamic user management.

Continuous Monitoring and Reporting

Products: GAT Shield

Site Access Monitoring:
  • Use Site Access Control to define policies and enforce safe browsing for your domain.
Alert Configurations:
  • Configure alerts for specific user activities, such as file downloads or unauthorised Chrome extensions .
User Behaviour Insights:
  • Configure alerts for specific user activities, such as file downloads or unauthorised Chrome extensions.

With this guide you can quickly familiarise yourself with our products, making the most out of their powerful features to audit, secure and automate your Google Workspace domain. 

If you’d like a detailed overview or require assistance, feel free to contact us at support@generalaudittool.com.

To explore more resources:

This website uses cookies to ensure you get the best experience on our website