Patronum Logo
00%
Patronum Logo
menu-icon

Too many super admins in Google Workspace: how to find them and fix it

By Patronum

August 10, 2026

Read Time: 4 mins

Google publishes no recommended number of super admins. Google Workspace Admin Help says only that you should have more than one, each with their own account, and that a super admin account shouldn’t be used for daily work. Everything else belongs in a delegated role.

A security questionnaire asks something easy-looking: how many super administrators do you have? You filter the Google Admin console by admin role and count eleven. Four moved to teams with nothing to do with IT. The list grew one exception at a time.

What to do in the next hour

Google Admin console Admin roles page listing the prebuilt system roles including Super Admin, Groups Admin, User Management Admin and Help Desk Admin
Google Admin console Admin roles page listing the prebuilt system roles including Super Admin, Groups Admin, User Management Admin and Help Desk Admin

In the Google Admin console, go to Menu, then Account, then Admin roles, click Super Admin, and read the list. For each name, ask one question: does this person do something only a super admin can do? Google’s prebuilt roles documentation puts that list at creating administrator roles, managing other admins, restoring deleted users, and setting up Google as a SAML identity provider. Most admins never touch it.

What does Google actually say about super admin accounts?

Google gives instructions, not a number. Its administrator account security best practices page says your organization “should have more than one super administrator account, each managed by a separate individual,” and to “Give each super administrator 2 accounts: Their own super admin account and a separate account for daily activities.” It adds: “Delegate administrator tasks to user accounts with limited admin roles.” The “2 to 4 super admins” figure quoted everywhere appears on neither that page nor Google Cloud’s super admin best practices page.

What are the prebuilt Google Workspace admin roles?

Prebuilt roles cover almost everything people ask a super admin to do.

Prebuilt roleWhat it can do
Super Admin“Has access to all features in the Google Admin console and Admin API”
Groups Admin“full control over Google Groups’ tasks in your Admin console”
User Management Admin“Can perform all actions on users who aren’t administrators”
Help Desk AdminReset non-admin passwords, view profiles and OUs
Services AdminService settings and devices, including Calendar, Drive

How do you fix too many super admins? A seven-step checklist

Work it in order. Steps 1 to 4 shrink the blast radius, steps 5 to 7 keep it small.

  1. Count your super admins. Account > Admin roles > Super Admin, Admins tab. Write the number down and date it.
  2. Remove stale assignments. Anyone who left IT, changed teams, or can’t name a super-admin-only task they performed this quarter.
  3. Replace them with prebuilt roles. Help Desk, Groups, User Management and Services Admin cover most of what people get promoted for.
  4. Create custom roles where nothing fits. Google allows up to 750 custom roles per organization, so “no role does exactly this” is rarely a real reason to grant Super Admin.
  5. Enforce security keys. Google Cloud’s super admin best practices page says to use “a security key or other physical authentication device” for two-step verification.
  6. Separate the daily account from the admin account. Two accounts per super admin, exactly as Google’s admin account security best practices page describes.
  7. Review quarterly and at every offboarding. “Remove admin roles” belongs in the leaver runbook.

Keep a break-glass account. This is a widely used security practice, not a Google-published rule, and Google publishes no number for it either. Set aside one emergency super admin account nobody uses day to day, with credentials and second factors stored offline, so a lost key can’t lock you out of your own tenant. Google’s version of the same idea: enroll more than one security key per admin account, and save backup codes ahead of time.

Why does this happen? Role creep, then role rot

Role creep happens at onboarding. A new IT hire needs one thing a Help Desk Admin can’t do, it’s 4pm, and Super Admin takes eight seconds to grant while a custom role takes twenty minutes. Nobody schedules the removal.

Role rot happens at offboarding. Most checklists cover password reset, mobile wipe, Drive transfer and license reclaim, but few include “remove admin roles.” Patronum’s offboarding checklist for zero data leakage does. Google keeps Admin log events for 6 months, so a role granted fourteen months ago has no record of who approved it.

The fix: make role state part of the lifecycle

Treat admin roles like group membership and Drive access: something a policy owns, not a person remembers. Patronum’s onboarding and offboarding automation runs the account-side steps in the same order every time: automatic password changes, recovery email updates, app-specific password deletion, mobile device wipe.

If leaver mailboxes need keeping, Patronum Archive retires the account without losing the email or the Google Vault data behind it.

One boundary worth stating plainly: removing a Super Admin assignment stays a Google Admin console governance step, taken by a human who holds the privilege. Automation’s job is to make sure the step is never skipped: put it in the runbook, with the quarterly count as the backstop.

Key takeaways

  • Google recommends more than one super admin and publishes no maximum.
  • A super admin can’t be scoped down, so delegate instead of promoting.

Frequently asked questions

How many super admins should a Google Workspace organization have?

Google does not publish a target number. Its Admin Help says only that you “should have more than one super administrator account, each managed by a separate individual.” Anyone quoting a figure as Google guidance is repeating something Google never wrote.

What is the difference between a super admin and a delegated admin?

A super admin has access to every feature in the Google Admin console and Admin API. A delegated admin holds a prebuilt or custom role scoped to organizational units. Only a super admin creates roles, restores deleted users or transfers file ownership.

Can I limit what a Google Workspace super admin can see?

No. Google’s privacy guidance notes that “By default, administrator accounts in your organization have access to user content and activity records.” You can withhold the Reports privilege, investigation tool and security dashboard from a delegated admin. A super admin has no scoping switch.

Audit your admin roles before someone else does

Count your super admins this week, then decide which could be a prebuilt role instead. Patronum’s Google Workspace user provisioning makes those lifecycle steps repeatable.

Sources