Google Workspace: Complete Visual Guide

Every product, admin concept, and security feature made easy to learn

10 Core Apps
11 Admin & Security
100% Visual

1. Google Workspace Overview

๐Ÿข Plans Comparison

PlanStorageMeet ParticipantsVaultPrice (user/mo)
Business Starter30 GB / user100,$7
Business Standard2 TB / user150,$14
Business Plus5 TB / user500โœ“$22
EnterpriseAs needed1 000โœ“Contact Sales

All plans include custom domain email, Google Docs editors, and Admin Console. Enterprise adds advanced security controls, DLP, and S/MIME.

โญ Key Features

EmailCustom domain ([email protected]) StorageGoogle Drive, cloud file storage CollaborationDocs, Sheets, Slides, real-time editing VideoGoogle Meet, HD video conferencing ChatSpaces, team messaging & threads AdminCentralized Admin Console, users, devices, security

๐Ÿ”€ Architecture

User
โ†“
Google Workspace
โ†“
Gmail
Drive
Meet
Calendar
Docs
Admin Console
2. Gmail

๐Ÿ“ง Gmail Features

Custom DomainSend/receive as [email protected] Uptime SLA99.9% guaranteed availability Spam FilterML-powered, blocks 99.9% of spam/phishing Confidential ModeExpiring emails, revoke access, passcode-protected Smart ComposeAI-powered autocomplete & smart reply Mail DelegationGrant read/send access to assistants Send-As AliasSend from alternate addresses under one inbox

๐Ÿ“ฌ Email Routing

Inbound Email
โ†’
MX Records
โ†’
Google Servers
โ†’
Spam / Phishing Filter
โ†’
Compliance Rules
โ†’
Inbox

Admins can configure split delivery, dual delivery, and catch-all routing for migration scenarios.

๐Ÿ”’ Email Security

ControlPurpose
SPFAuthorizes which servers can send on behalf of your domain
DKIMCryptographic signature proves message wasn't altered in transit
DMARCPolicy telling receivers what to do when SPF/DKIM fail (reject, quarantine, none)
S/MIMEEnd-to-end email encryption with certificates (Enterprise)
TLS EnforcementRequire TLS for specific domains, reject plaintext delivery
Content ComplianceScan messages for keywords, PII, attachments, block or quarantine

โš™๏ธ Admin Mail Settings

SettingDescription
Default RoutingRoute all inbound/outbound through a gateway or secondary MX
Content ComplianceMatch patterns (regex/word lists) and quarantine or reject
Attachment ComplianceBlock file types (.exe, .zip), size limits, DLP scan
Email AllowlistBypass spam filters for trusted senders / IPs
Objectionable ContentBlock based on custom word lists
Append FooterAdd legal disclaimer to outbound messages
3. Google Calendar

๐Ÿ“… Calendar Features

SchedulingFind free/busy across org, suggest times Resource BookingReserve rooms, equipment, cars via calendar Working HoursSet hours & location (home / office) Out of OfficeAuto-decline new invites, show status Appointment SlotsBookable time blocks for external scheduling Calendar InteropFree/busy lookup with Exchange/O365

๐Ÿ”— Sharing Levels

LevelWhat They See
Free/BusyOnly whether you're available or busy, no details
All Event DetailsEvent title, time, location, attendees
Make ChangesEdit events, RSVP on your behalf
Changes & ManageFull control including sharing settings

๐Ÿ›ก๏ธ Admin Controls

External SharingControl whether users share calendars outside the org Video ConferencingAuto-add Google Meet to new events (default on/off) Resource ManagementBuildings, floors, rooms, features (video, whiteboard) Calendar InteropConfigure Exchange interop for hybrid environments
4. Google Drive

๐Ÿ’พ Storage Architecture

My Drive (Personal)

  • Owned by individual user
  • Deleted when user is removed
  • User controls sharing
  • Counts against user's quota
  • Admin can transfer ownership
vs

Shared Drives (Team)

  • Owned by the organization
  • Persists when members leave
  • Membership-based access
  • Counts against org pool
  • Manager role controls settings

๐Ÿ‘ฅ Sharing Permissions

RoleViewCommentEditMove / DeleteShare
Viewerโœ“,,,,
Commenterโœ“โœ“,,,
Editorโœ“โœ“โœ“,Optional
Ownerโœ“โœ“โœ“โœ“โœ“

๐Ÿ“Š Storage & Sync

Starter30 GB pooled per user Standard2 TB pooled per user Plus5 TB pooled per user EnterpriseAs much as needed (with reasonable use)
Sync OptionHow It Works
Drive for DesktopStream files on demand, appears as a local drive letter
Mirror ModeFull offline copy of selected folders, syncs both ways
Web / MobileBrowser & app access, mark files as offline for mobile

๐Ÿ›ก๏ธ Drive Security

DLP on DriveScan files for PII/sensitive data, block external sharing Classification LabelsPublic, Internal, Confidential, Restricted, drive labels Link SharingOff, Org-only, Anyone with link, admin sets default External SharingAllowlist specific domains or block all external sharing IRMDisable download, print, copy for viewers Target AudiencesPre-defined groups for safe link sharing
5. Docs, Sheets & Slides

โœ๏ธ Real-Time Collaboration

Simultaneous EditingMultiple users edit at the same time, cursors visible Suggesting ModeTrack-changes style, author accepts or rejects Version HistoryFull revision timeline, restore any version Comments & RepliesThreaded discussions on any selection @MentionsTag people, files, or calendar events inline Action ItemsAssign tasks from comments, tracked in checklist

๐Ÿ“„ Docs vs Sheets vs Slides

ProductUse CaseReplaces
DocsDocuments, proposals, meeting notesWord
SheetsSpreadsheets, budgets, data analysisExcel
SlidesPresentations, pitch decks, trainingPowerPoint
FormsSurveys, quizzes, data collection,
DrawingsSimple diagrams, flowchartsVisio (basic)

๐Ÿ”Œ Extensibility

Connected SheetsQuery BigQuery datasets directly in Sheets, billions of rows Apps ScriptServer-side JavaScript, automate, extend, integrate Add-onsMarketplace extensions, mail merge, diagrams, signatures TemplatesOrg-wide branded templates for docs, sheets, slides Offline ModeEdit without internet, syncs when reconnected

๐Ÿ—๏ธ Enterprise Features

Comparison ModeCompare two documents side-by-side, highlights diffs Linked ObjectsEmbed live Sheets charts in Docs/Slides, auto-update Building BlocksVoting chips, trackers, dropdown chips in Docs Document ApprovalsRequest approval workflow, approve/reject directly in Docs eSignatureNative electronic signature requests in Docs
6. Google Meet

๐ŸŽฅ Features by Plan

FeatureStarterStandardPlusEnterprise
Max Participants1001505001 000
Meeting Length24 hrs24 hrs24 hrs24 hrs
Recording,โœ“โœ“โœ“
Breakout Rooms,โœ“โœ“โœ“
Q&A & Polls,โœ“โœ“โœ“
Attendance Tracking,,โœ“โœ“
Noise Cancellationโœ“โœ“โœ“โœ“
Live Streaming,,,โœ“ (100K viewers)
Translated Captions,,โœ“โœ“

๐ŸŒ Meet Architecture

User (Browser / App)
โ†’
Meet Client
โ†’
Google Edge Network
โ†’
Media Server
โ†’
Other Participants
Companion ModeJoin from a second device for in-room + remote hybrid Live StreamingBroadcast to up to 100K viewers in domain (Enterprise) Translated CaptionsReal-time caption translation across languages

๐Ÿ” Meet Security

ControlDescription
EncryptionAll media encrypted in transit (DTLS-SRTP) between client and Google
Meeting Codes10-character codes + phone PINs, expire after event ends
Host ControlsMute all, remove participants, lock meeting, disable chat
Lobby / KnockingExternal participants must request entry, host approves
Abuse ReportingReport abusive users, triggers admin review
Admin ControlsDisable recording, restrict who can create meetings, auto-admit policy
7. Google Chat & Spaces

๐Ÿ’ฌ Chat Features

1:1 ChatDirect messages between two people Group ChatUnthreaded group conversation, quick discussions Spaces (Threaded)Persistent rooms with topics and threads File SharingShare Drive files inline, preview without leaving Chat Task IntegrationCreate tasks from messages, tracked in Google Tasks Bots / WebhooksAutomated messages, slash commands, interactive cards

๐Ÿ†š Spaces vs Group Chat

Spaces

  • Threaded conversations
  • Named, discoverable in org
  • Persistent, long-lived topics
  • Shared files & tasks tabs
  • Can add/remove members
  • Supports bots & apps
vs

Group Chat

  • Flat / unthreaded messages
  • No name, based on members
  • Quick ad-hoc discussions
  • No shared files tab
  • Fixed member list
  • Simpler, lightweight

๐Ÿค– Chat Bots & Webhooks

IntegrationDescription
Incoming WebhooksPush notifications from external services into a Space
Chat APIREST API, create messages, manage spaces, read conversations
Apps Script BotsServer-side JS, respond to commands, interactive cards
DialogflowNLU-powered conversational bots with intent matching

โš™๏ธ Admin Settings

Chat HistoryOn (always save), Off (24h expiry), or User's Choice External ChatAllow/block chat with users outside the organization Space ManagementAdmins can view, manage, and export Space content App AllowlistControl which Chat bots/apps users can install
8. Google Forms

๐Ÿ“ Google Forms

Form BuilderDrag-and-drop, multiple choice, dropdown, grid, short/long answer QuizzesAuto-grading with point values, answer keys, feedback per question Branching LogicGo to section based on answer, conditional flows File UploadsRespondents can upload files (stored in Drive) Response ValidationRegex, number ranges, required fields, custom error messages Sheets IntegrationResponses auto-populate a linked Google Sheet in real-time NotificationsEmail alerts on each response or summary digests Add-onsTimer, advanced branching, conditional email, form limiter
Create Form
โ†’
Share Link / Embed
โ†’
Collect Responses
โ†’
Analyze in Sheets
9. Google Sites

๐ŸŒ Google Sites

BuilderDrag-and-drop WYSIWYG editor, no code required Custom DomainsPublish to your own domain via DNS CNAME EmbedsGoogle Maps, Sheets, Docs, Slides, YouTube, Calendar, Forms Published / DraftPreview changes before publishing, version history included Access ControlPublic, org-only, or specific people / groups can view Intranet UsePerfect for team portals, project hubs, knowledge bases ResponsiveMobile-friendly layouts auto-generated
Create Site
โ†’
Add Pages & Content
โ†’
Embed Workspace Content
โ†’
Publish & Share
10. AppSheet

๐Ÿ“ฑ AppSheet, No-Code App Builder

No-Code PlatformBuild apps without writing code, visual editor Data SourcesGoogle Sheets, SQL databases, REST APIs, Excel, Salesforce Mobile AppsNative mobile experience, iOS & Android AutomationBots, triggered workflows (email, update data, call API) Offline SupportWorks offline, syncs when connectivity returns Enterprise DeployAdmin-managed deployment, SSO, data governance policies
Data Source (Sheets / SQL / REST)
โ†’
AppSheet Engine
โ†’
Mobile / Web App
โ†’
End Users

11. Admin Console

๐Ÿ–ฅ๏ธ Admin Console Architecture

Super Admin
โ†“
Users
Groups
Devices
Apps
Security
Billing
Reports

๐Ÿ‘ค Admin Roles

RoleScope
Super AdminFull access to all settings, users, billing, security
Groups AdminCreate/manage groups, add/remove members
User Mgmt AdminAdd/suspend/delete users, reset passwords
Help Desk AdminReset passwords, view user profiles (no delete)
Services AdminConfigure service settings (Gmail, Drive, Meet, etc.)
Custom RolesFine-grained privileges, pick specific permissions

๐Ÿ—๏ธ Key Admin Settings

Organizational UnitsHierarchical OUs, apply policies per department/team Manual ProvisioningAdd users one by one in Admin Console CSV UploadBulk-add users via spreadsheet Admin SDK APIProgrammatic user CRUD, automate onboarding GCDSGoogle Cloud Directory Sync, sync from LDAP/AD Password PoliciesMin length, strength, expiration, disallow reuse 2-Step EnforcementRequire 2FA for all users or specific OUs

๐Ÿ”„ Directory Sync (GCDS)

LDAP / Active Directory
โ†’
GCDS Agent
โ†’
Google Cloud Directory
โ†’
Admin Console (Users, Groups, OUs)

GCDS runs on-prem, reads LDAP, and pushes changes to Google. One-way sync (LDAP โ†’ Google). Does not sync passwords, use GSPS or SSO for that.

12. Identity & Access

๐Ÿ”‘ SSO Flow

User
โ†’
Service Provider
โ†’
Redirect to Google IdP
โ†’
SAML / OIDC Auth
โ†’
Token Issued
โ†’
Access Granted

Google can act as both Identity Provider (IdP) for third-party apps, or Service Provider (SP) when using an external IdP (Okta, Azure AD).

๐Ÿ›‚ Authentication Methods

MethodDescription
PasswordStandard username + password
2-Step: SMSVerification code sent via text message
2-Step: TOTPTime-based code from Google Authenticator / similar
2-Step: Security KeyFIDO2 hardware key, phishing resistant
2-Step: Phone PromptTap "Yes" on trusted mobile device
SSO (SAML 2.0)Federated login via external IdP
SSO (OIDC)OpenID Connect token-based auth
Secure LDAPLDAP apps authenticate against Google directory
Context-AwareConditional access based on signal (IP, device, geo)

๐Ÿ” Advanced Authentication

FIDO2 / WebAuthnPhishing-proof, cryptographic challenge/response Titan Security KeyGoogle's hardware security key, USB-A, USB-C, NFC PasskeysPasswordless auth, biometric or device PIN

Context-Aware Access Signals

SignalExample
IP AddressAllow only from corporate IP ranges
Device StateRequire encrypted, managed, up-to-date OS
GeolocationBlock logins from countries you don't operate in
Device OSRequire ChromeOS or managed Windows

๐Ÿ†” Cloud Identity

Cloud Identity Free

  • Identity & device management
  • No Workspace apps
  • SSO & directory sync
  • Basic endpoint management
  • Free, unlimited users
vs

Cloud Identity Premium

  • Everything in Free +
  • Advanced endpoint (MDM)
  • Context-Aware Access
  • Security Center (BeyondCorp)
  • $7.20 / user / month
13. Security Center

๐Ÿ›ก๏ธ Security Dashboard

Phishing Attempts
Malware Detections
Suspicious Logins
โ†“
Recommendations
Investigation Tool
Audit Logs

Security Center is available on Enterprise plans. Provides unified view of threats, actionable recommendations, and a powerful investigation tool to query events across all Workspace services.

๐Ÿ’š Security Health

2-Step Adoption% of users with 2FA enabled, target: 100% External SharingFiles shared outside org, monitor exposure Mobile SecurityUnmanaged devices accessing data, enforce MDM OAuth AppsThird-party apps with access to user data, review & restrict Email AuthSPF, DKIM, DMARC adoption across domains

๐Ÿšจ Alert Center

Alert TypeTrigger
PhishingUser-reported phishing or Google-detected phishing spike
Suspicious LoginLogin from new device, unusual location, or leaked password
DLP ViolationSensitive data shared or downloaded outside policy
Government AttackState-sponsored attack warning from Google Threat Analysis
Admin ActionCritical admin changes (delete user, change Super Admin, etc.)
14. Google Vault

๐Ÿ›๏ธ eDiscovery Flow

1. Define Scope (users, dates, terms)
โ†’
2. Search
โ†’
3. Preview Results
โ†’
4. Export (mbox, PST, etc.)
โ†’
5. Legal Hold

Legal holds preserve data indefinitely, even if the user deletes it or retention rules would have purged it.

๐Ÿ“ฆ Vault Features

Retention RulesDefault (org-wide) + custom rules per OU, group, or date Legal HoldsPreserve specific users' data for litigation, override retention Search ScopeGmail, Drive, Chat, Meet recordings, Groups, Voice Export Formatsmbox (email), PST, PDF, native format (Drive files) Audit LogsTrack who searched, previewed, or exported what

โฑ๏ธ Retention Policies

Default Retention

  • Applies to entire org
  • One rule per service
  • e.g. Keep Gmail 7 years
  • Purge after expiry
vs

Custom Retention

  • Per OU, group, or date range
  • Overrides default if longer
  • e.g. Legal dept: keep 10 yrs
  • Multiple rules can coexist
15. Data Loss Prevention (DLP)

๐Ÿšซ DLP Flow

Content Created / Shared
โ†’
DLP Rules Engine
โ†’
Detectors (PII, CC#, SSN, Regex)
โ†’
Action: Block / Warn / Audit

DLP rules run on Gmail (outbound), Drive (sharing), and Chat messages. Powered by the same Cloud DLP detectors used in GCP.

๐Ÿ” Built-in Detectors

DetectorWhat It Finds
Credit CardVisa, MC, Amex, Discover patterns + Luhn check
SSNUS Social Security Numbers (XXX-XX-XXXX)
PassportPassport numbers for 40+ countries
Tax IDEmployer Identification Numbers, VAT IDs
Custom RegexYour own patterns, employee IDs, project codes
Word ListsMatch specific terms, "confidential", "internal only"

โšก DLP Actions & Scope

ActionBehavior
BlockPrevent sharing / sending, user cannot override
WarnUser sees warning, can acknowledge and proceed
Audit OnlyLog the event, no user-visible action (shadow mode)
QuarantineHold message/file for admin review before delivery
GmailScan outbound messages and attachments DriveScan on upload, share, or download ChatScan messages in real-time
16. Mobile Device Management

๐Ÿ“ฑ Endpoint Management

Basic Management

  • Require screen lock
  • Remote account wipe
  • Device inventory
  • No agent required
  • All plans
vs

Advanced Management

  • Managed app deployment
  • Work profiles (Android)
  • Full device wipe
  • Compliance policies
  • Plus / Enterprise plans

๐Ÿ”„ MDM Enrollment Flow

Device
โ†’
Enroll (MDM profile)
โ†’
Policies Applied
โ†’
Compliant โœ“ โ†’ Access
Device
โ†’
Enroll
โ†’
Policies Applied
โ†’
Non-compliant โœ— โ†’ Block

๐Ÿ’ป Supported Platforms

PlatformManagement Model
AndroidWork profile (BYOD) or fully managed (company-owned)
iOS / iPadOSManaged device via MDM profile, supervised optional
WindowsEndpoint verification, device trust signals
macOSEndpoint verification, certificate-based trust
ChromeOSFully managed via Chrome Enterprise, most integrated

๐Ÿข BYOD vs Company-Owned

BYODWork profile separates personal & work data, user keeps device Company-OwnedFull device management, wipe on departure, kiosk mode App ManagementPush managed apps, block unmanaged, auto-update policies Remote WipeAccount wipe (remove work data) or full device wipe
17. Google Groups

๐Ÿ‘ฅ Google Groups

Group Types

TypeUse Case
Email ListDistribution list, send to one address, reach many
Collaborative InboxShared inbox, assign, track, resolve conversations
Web ForumDiscussion board, threaded topics
Q&AQuestions with "best answer" marking

Roles & Access

OwnerFull control, settings, members, delete group ManagerManage members, approve messages MemberSend/receive messages, participate

Access Settings

PublicAnyone on the internet can find & join Org-onlyVisible to organization members only RestrictedInvite-only, hidden from directory

Groups Are Used For

Email Distribution
โ†’
Drive / Calendar Permissions
โ†’
Google Cloud IAM
โ†’
Shared Drive Access
18. Shared Drives

๐Ÿ“ My Drive vs Shared Drives

AttributeMy DriveShared Drive
OwnershipIndividual userOrganization
On User DeletionData deleted (unless transferred)Data persists, org retains
MembershipN/A, personalExplicit members with roles
SharingOwner controls per file/folderInherited from Shared Drive settings
Storage QuotaCounts against userCounts against org pool
Nested FoldersUnlimited depthSupported (improved in recent updates)

๐Ÿ”‘ Shared Drive Access Levels

RoleViewCommentEditMove/DeleteManage Members
Viewerโœ“,,,,
Commenterโœ“โœ“,,,
Contributorโœ“โœ“โœ“,,
Content Managerโœ“โœ“โœ“โœ“,
Managerโœ“โœ“โœ“โœ“โœ“

โœ… Best Practices

Team ContentUse Shared Drives for team-owned docs, not My Drive OffboardingData stays when employees leave, no transfer needed Admin TransferSuper Admins can migrate My Drive files โ†’ Shared Drive External MembersOptional, allow external collaborators per Shared Drive Folder StructurePlan structure early, consistent naming, clear hierarchy
19. APIs & Automation

โšก Google Workspace APIs

APIWhat It DoesUse Case
Gmail APIRead, send, label, search email programmaticallyEmail automation, CRM sync
Drive APICRUD files/folders, manage permissions, upload/downloadDocument management, backups
Calendar APICreate/update events, check availability, manage resourcesScheduling bots, room booking
Admin SDKUser/group/device management, reporting, audit logsAutomated onboarding/offboarding
Sheets APIRead/write cells, format, create sheets programmaticallyDashboards, data pipelines
Chat APISend messages, manage spaces, interactive bot cardsAlert bots, workflow notifications

Apps Script & Marketplace

Apps ScriptServer-side JavaScript, triggers, custom menus, web apps, add-ons TriggersTime-driven (cron), on form submit, on edit, on open Add-onsExtend Docs/Sheets/Slides/Gmail/Calendar with custom UI panels MarketplaceThird-party apps, admin approves โ†’ domain-wide install OAuth ConsentAdmin can restrict OAuth scopes, block risky app access
20. Workspace + GCP Integration

๐Ÿ”— Integration Architecture

Google Workspace
Gmail, Drive, Meet, Docs
โ†”
Cloud Identity
Unified Directory
โ†”
Google Cloud (GCP)
IAM, Projects, Billing

๐Ÿค Shared Features

Cloud IdentityUnified user directory, same account for Workspace & GCP SSOSingle sign-on between Workspace apps and GCP Console Groups for IAMGoogle Groups grant GCP IAM roles, manage access at scale Audit โ†’ Cloud LoggingExport Workspace audit logs to Cloud Logging & BigQuery DLPWorkspace DLP powered by Cloud DLP API, shared detectors Connected SheetsQuery BigQuery from Google Sheets, billions of rows, no SQL needed

๐Ÿ”’ Enterprise Data Controls

Data ResidencyChoose where primary data is stored (US, Europe, global) Assured WorkloadsCompliance framework, FedRAMP, ITAR, CJIS, IL4 CMEKCustomer-Managed Encryption Keys, you control the key in Cloud KMS CSEClient-Side Encryption, encrypt before Google sees it (Drive, Docs, Meet, Calendar) Access TransparencyLogs when Google staff access your data (and why) Access ApprovalRequire your explicit approval before Google support accesses data
21. Quick Reference

๐Ÿ“‹ Google Workspace, Full Reference

ProductCategoryKey FeatureAdmin Setting
GmailCommunicationCustom domain email, 99.9% SLARouting, compliance, SPF/DKIM/DMARC
CalendarSchedulingResource booking, appointment slotsExternal sharing, video defaults
DriveStorageMy Drive + Shared Drives, real-time syncSharing policies, DLP, storage quotas
Docs / Sheets / SlidesCollaborationReal-time co-editing, version historyOffline access, external sharing
MeetVideoHD video, recording, breakout roomsRecording policy, auto-admit, streaming
Chat & SpacesMessagingThreaded Spaces, bots, webhooksHistory, external chat, app allowlist
FormsData CollectionQuizzes, branching, Sheets integrationExternal response settings
SitesWeb PublishingDrag-and-drop intranet builderSharing & publishing permissions
AppSheetNo-Code AppsBuild mobile apps from Sheets / SQLEnterprise deployment, data governance
Admin ConsoleAdminCentralized user, device, app managementOUs, roles, provisioning, password policy
Cloud IdentityIdentitySSO, directory, device managementSAML/OIDC, 2FA enforcement, LDAP
Security CenterSecurityThreat dashboard, investigation toolRecommendations, alert center
VaultComplianceeDiscovery, legal holds, retentionRetention rules, export policies
DLPSecurityPII detection, block/warn/audit actionsRules, detectors, scope (Gmail/Drive/Chat)
Endpoint MgmtDevicesMDM, work profiles, remote wipeBasic vs advanced, BYOD vs company-owned
GroupsCollaborationEmail lists, collaborative inbox, IAMAccess settings, external membership
Shared DrivesStorageOrg-owned team storage, persistentSharing, external members, migration
APIs & Apps ScriptAutomationREST APIs, triggers, add-ons, botsOAuth scopes, marketplace allowlist