Too many super admins in Google Workspace: how to find them and fix it
By Patronum
August 10, 2026
Read Time: 4 mins

By Patronum
August 10, 2026
Read Time: 4 mins

Google publishes no recommended number of super admins. Google Workspace Admin Help says only that you should have more than one, each with their own account, and that a super admin account shouldn’t be used for daily work. Everything else belongs in a delegated role.
A security questionnaire asks something easy-looking: how many super administrators do you have? You filter the Google Admin console by admin role and count eleven. Four moved to teams with nothing to do with IT. The list grew one exception at a time.

In the Google Admin console, go to Menu, then Account, then Admin roles, click Super Admin, and read the list. For each name, ask one question: does this person do something only a super admin can do? Google’s prebuilt roles documentation puts that list at creating administrator roles, managing other admins, restoring deleted users, and setting up Google as a SAML identity provider. Most admins never touch it.
Google gives instructions, not a number. Its administrator account security best practices page says your organization “should have more than one super administrator account, each managed by a separate individual,” and to “Give each super administrator 2 accounts: Their own super admin account and a separate account for daily activities.” It adds: “Delegate administrator tasks to user accounts with limited admin roles.” The “2 to 4 super admins” figure quoted everywhere appears on neither that page nor Google Cloud’s super admin best practices page.
Prebuilt roles cover almost everything people ask a super admin to do.
| Prebuilt role | What it can do |
|---|---|
| Super Admin | “Has access to all features in the Google Admin console and Admin API” |
| Groups Admin | “full control over Google Groups’ tasks in your Admin console” |
| User Management Admin | “Can perform all actions on users who aren’t administrators” |
| Help Desk Admin | Reset non-admin passwords, view profiles and OUs |
| Services Admin | Service settings and devices, including Calendar, Drive |
Work it in order. Steps 1 to 4 shrink the blast radius, steps 5 to 7 keep it small.
Keep a break-glass account. This is a widely used security practice, not a Google-published rule, and Google publishes no number for it either. Set aside one emergency super admin account nobody uses day to day, with credentials and second factors stored offline, so a lost key can’t lock you out of your own tenant. Google’s version of the same idea: enroll more than one security key per admin account, and save backup codes ahead of time.
Role creep happens at onboarding. A new IT hire needs one thing a Help Desk Admin can’t do, it’s 4pm, and Super Admin takes eight seconds to grant while a custom role takes twenty minutes. Nobody schedules the removal.
Role rot happens at offboarding. Most checklists cover password reset, mobile wipe, Drive transfer and license reclaim, but few include “remove admin roles.” Patronum’s offboarding checklist for zero data leakage does. Google keeps Admin log events for 6 months, so a role granted fourteen months ago has no record of who approved it.
Treat admin roles like group membership and Drive access: something a policy owns, not a person remembers. Patronum’s onboarding and offboarding automation runs the account-side steps in the same order every time: automatic password changes, recovery email updates, app-specific password deletion, mobile device wipe.
If leaver mailboxes need keeping, Patronum Archive retires the account without losing the email or the Google Vault data behind it.
One boundary worth stating plainly: removing a Super Admin assignment stays a Google Admin console governance step, taken by a human who holds the privilege. Automation’s job is to make sure the step is never skipped: put it in the runbook, with the quarterly count as the backstop.
Google does not publish a target number. Its Admin Help says only that you “should have more than one super administrator account, each managed by a separate individual.” Anyone quoting a figure as Google guidance is repeating something Google never wrote.
A super admin has access to every feature in the Google Admin console and Admin API. A delegated admin holds a prebuilt or custom role scoped to organizational units. Only a super admin creates roles, restores deleted users or transfers file ownership.
No. Google’s privacy guidance notes that “By default, administrator accounts in your organization have access to user content and activity records.” You can withhold the Reports privilege, investigation tool and security dashboard from a delegated admin. A super admin has no scoping switch.
Count your super admins this week, then decide which could be a prebuilt role instead. Patronum’s Google Workspace user provisioning makes those lifecycle steps repeatable.