You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
close
You are viewing the article in preview mode. It is not live at the moment.
Home > Password, Login, & User Accounts > Best Practices for Role-Based Google Accounts
Best Practices for Role-Based Google Accounts
print icon

Role-based Google accounts (like [email protected], [email protected], or [email protected]) are shared resources meant to represent a department, office, student organization, or function, not an individual person. To keep them secure, easy to manage, and in line with Google’s expectations, we need to follow a consistent approach for how these accounts are used.

This guide outlines what “doing it right” looks like and points you to other articles for deeper step-by-step instructions where needed.


1. Assign One Account Manager

Each role-based account should have exactly one person who knows the password and manages Multi-Factor Authentication. That person acts as the account manager.

  • They are the only one who signs in directly to the account.

  • They are responsible for adding and removing access and reviewing who has it.

  • If they leave or change roles, the account manager responsibility must be reassigned before they go.

Why this matters: even with MFA, sharing credentials introduces security, compliance, and accountability issues. Having one person responsible keeps things clear and secure.


2. Use Delegated Access for Email

Most people should never log in directly to a role-based account to check or send emails. Instead, use Gmail’s delegated access feature. This lets someone read, send, and manage email for a role-based account while signed into their own account.

  • Actions are tied to the individual’s identity, so there is a record of who did what.

  • Each person uses their own MFA, so you avoid passing around codes or sharing devices.

  • Access can be added or removed at any time without changing the account password.

See: How to Add or Remove Delegates for a Gmail Account

Best practice: Review delegated access at least once per semester to make sure only current staff have access.


3. Use Shared Drives Instead of Storing Files in the Role-Based Account

Important files should not live in the “My Drive” of a role-based account. They should be stored in a Shared Drive owned by the department.

  • Files in a Shared Drive remain accessible even if people leave or accounts are deleted.

  • Access is managed per person without shared passwords.

  • You can give access to the entire drive or specific folders depending on the situation.

  • Each department already has a starred Shared Drive that contains every employee in that department (faculty, staff, and adjuncts). If your department needs another Shared Drive for a specific team, CIT can help with that.

See: Managing Shared Drives and Folder-Level Access


4. Handle Calendar Access Intentionally

Calendar access works differently than email and should be handled carefully. Before creating or sharing a calendar, decide whether the calendar needs to live under the role-based account at all.

  • Only create a calendar under a role-based account if it is directly tied to that account’s purpose. For example, [email protected] might own the official academic deadlines calendar.

  • If the calendar is primarily for internal coordination, individual staff, or general scheduling, it is better to create it under a personal account and share it with the people who need access.

  • If the role account is ever retired or deleted, the calendar is deleted with it.

  • Calendar delegation is managed separately from email and can be more limited in flexibility.

See: How to Create a Google Calendar How to Share a Google Calendar

Best practice: Review who has access to shared calendars each semester and confirm whether they still need it.


5. Only Use the Direct Login as a Last Resort

There should be very few reasons anyone besides the account manager needs to sign in directly to a role-based account. Google has created built-in tools like delegation and shared drives so it isn't necessary to keep things secure. If someone believes they do need to sign in to a role-based account:

  • Double-check whether delegated access, a shared drive, or another built-in feature could solve the issue first.

  • Never share MFA codes or set up MFA on a shared device.


Next Steps for Departments

  • Identify an account manager for each role-based account.

  • Stop sharing credentials among multiple people.

  • Contact CIT if you need a new Shared Drive or help reviewing existing accounts.

  • Review who currently has delegated access for Gmail and Google Calendar and update it as needed.


Final Thoughts

This approach is not about adding red tape. It is about reducing risk, improving accountability, and making life easier for everyone. Google discourages credential sharing even with MFA because it breaks many of the security and visibility features built into Workspace. Shifting to using delegated access for email, handling calendars intentionally, using Shared Drives, and limiting direct logins keeps our data safer and our systems easier to manage.

Feedback
0 out of 0 found this helpful

scroll to top icon