Apply access best practices
Reduce risk through least privilege, periodic reviews, and individual accounts.
Updated August 3, 2026 Β· 7 minAssign least privilege
Start with Reader or a narrow custom role and add permissions only for a documented need. Avoid granting Administrator as a shortcut.
Keep individual accounts
Never share identities. Disable access when someone leaves and preserve audit traceability.
Review the team
Periodically remove expired invitations, inactive members, unused permissions, and obsolete corporate access.
Separate responsibilities
Reserve commercial and security operations for appropriate owners. Investigate unexpected access by checking member status, role permissions, workspace, and recent audit events.