What are the four types of Google Groups?
By Patronum
August 10, 2026
Read Time: 5 mins

By Patronum
August 10, 2026
Read Time: 5 mins

Google Workspace gives every group one of four access types: Public, Team, Announcement only, and Restricted. Each type is a preset bundle of permissions covering who can join, post, view conversations, view members, and contact the owners. Change any one of those settings and Google relabels the group Custom.
Most admins learn that last part the hard way.
An access type is an access control decision, not an email setting. Google’s Admin Help says a type “includes predefined permissions for group owners, managers, and members, as well as whether the group is open to the entire organization or people outside.” The Admin console shows that grid when you pick a type, and clicking any cell makes the group Custom.
| Access type | Built for | What you’re really deciding |
|---|---|---|
| Public | Open discussion, including outside the organization | Widest reach, lowest control. |
| Team | An internal working group or department | Members collaborate freely, outsiders stay out. |
| Announcement only | One-way broadcast, like all-staff or a newsletter | Only the group’s owners can post. |
| Restricted | Sensitive or confidential distribution | Tightest defaults on joining and viewing. |
| (Custom) | Anything you hand-tune | Google’s label once a group stops matching a preset. |
External posting and external joining depend on organization-level Groups settings, not just the access preset. Two admin checkboxes gate them: “Group owners can allow external members” and “Group owners can allow incoming email from outside the organization.” Google states that “Leaving the options unchecked means that group owners cannot allow external group members or emails.” Viewing is gated separately, by whether Groups for Business sharing is “Public on the Internet” or “Private.” A group labeled Public can still be unreachable from outside, because the organization-level policy says no.
Google’s Help pages describe each preset in a sentence but publish the actual grid only inside the Admin console’s group creation screen. Here it is, read straight off that screen. O = group owners, M = managers, Mb = members, Org = everyone in your organization, Ext = external.
| Access setting | Public | Team | Announcement only | Restricted |
|---|---|---|---|---|
| Who can contact group owners | O, M, Mb, Org, Ext | O, M, Mb, Org, Ext | O, M, Mb, Org, Ext | O, M, Mb, Org, Ext |
| Who can view conversations | O, M, Mb, Org | O, M, Mb, Org | O, M, Mb, Org | O, M, Mb |
| Who can post | O, M, Mb, Org | O, M, Mb, Org | O, M | O, M, Mb |
| Who can view members | O, M, Mb, Org | O, M, Mb, Org | O, M | O, M, Mb |
| Who can manage members | O, M | O, M | O, M | O, M |
Two things jump out. Public and Team have identical permission grids. The only difference is joining: Google’s own wording is that Public means “Anyone in your organization can post to and join the group,” while Team means “Anyone in your organization can post to the group, but they must ask to join.” Pick between them on approval, not on permissions.
And no preset lets external people post or read conversations. The external column is checked for one row only, contacting group owners. Announcement only narrows posting and member visibility to owners and managers. Restricted is the one that drops the whole organization out of viewing and posting, leaving members.

Four terms, four different things.
A 400-person company creates all-staff@ as Team, the default everyone reaches for. Six months later a junior hire replies-all to 400 people with a payroll question. The fix: one field, Announcement only.
The quieter version costs more. That company has 300 groups, nobody remembers which drifted to Custom, and two leavers still sit in finance-approvals@. Deleting an account doesn’t audit every group it touched. Patronum works the lifecycle side: group membership is set by policy at onboarding, reassessed on role change, and stripped at offboarding.
“Groups are just email lists.” No. Google states that “A user’s group settings always override their organizational unit’s settings,” so a configuration group can rewrite Admin console policy.
“Restricted means private forever.” It’s a starting preset. Anyone with manage rights can loosen one cell, and the label quietly flips to Custom. Practical fix: audit your Custom groups quarterly. Filter the group list to Custom and check who can join, post and view. Custom means a human changed something, so it’s the cheapest place to look.
“Deleting the user cleans up the groups.” Memberships are separate records, which is why Patronum ties directory upkeep to lifecycle policy.
Yes. Edit the group in the Google Admin console and pick a different access type. Adjusting individual permission cells flips the type to Custom, so if the group must keep reporting as Team or Restricted, use the preset.
Google documents a maximum of 500,000 members in one group, and a limit of 1,500 groups any single user can own. Google notes these limits “can change without notice.”
No. Groups still work as email lists, calendar invitees, sharing targets, and access control. Groups for Business adds groups.google.com, moderation, and Collaborative Inbox.
No. Google lists dynamic groups on Frontline Standard and Plus, Enterprise Standard and Plus, Education Standard and Plus, Enterprise Essentials Plus, and Cloud Identity Premium, capped at 500 per organization.
Picking the right access type takes ten seconds. Keeping 300 groups accurate for three years is the actual work, and that’s a lifecycle problem, which is what Patronum’s onboarding and offboarding automation handles. On exit, the same policy can hand a leaver’s mail and Google Vault data to Patronum Archive rather than leave a licensed account in your groups.