What WOSP does for your Google Workspace tenants

WOSP is a partner portal for MSPs who manage Google Workspace. Bulk work the Admin Console cannot do, scheduled lifecycle jobs, client baselines, security findings, and a portal your clients can log into themselves.

The reason MSPs switch

Work the Admin Console has no answer for

Google's Admin Console is built for one organization with one admin. These are the gaps you hit on day one of managing thirty of them.

Bulk actions on every list

Multi-select users and suspend, restore, archive, unarchive, sign out, delete, change domain, move org unit, add to a group, add to a shared drive, assign a license, or set IMAP. Groups, org units, OAuth apps, devices, alerts, and Chat spaces have their own bulk actions. Destructive ones always confirm first and report per-item results.

Scheduled user creation

Build the new hire now, have WOSP create the account on their start date. Org unit, title, department, recovery contacts, and a welcome email to their personal address all fire at run time, not when you filled the form. Cancel or run it early from Jobs.

Scheduled offboarding

Queue a departure for the last day and walk away. Password reset, session revoke, Drive transfer to a manager, license reclaim, org unit move, and a final state of archive or delete, run as one composed job across one user or a whole list.

Sign in with Google or Microsoft Entra ID

Your techs sign in with the identity provider you already run. Entra ID single-tenant SSO is included alongside Google Sign-In, and a built-in wizard creates the Entra app registration for you through Microsoft Graph so you are not hand-building a redirect URI and a client secret.

MSP technician accounts

The shared admin account you keep in every client tenant stops polluting your findings. Declare the username once and WOSP excludes it from inactive-user and 2SV audits across every tenant, then holds it to the Directory and Gmail baseline you set.

Export anything

Every list view exports to CSV. Users, groups, devices, licenses, findings, audit rows. No scraping the Admin Console into a spreadsheet to answer a client question.

Access

Who can see what, down to the tenant

Techs, auditors, and client contacts all use the same portal with very different views of it.

Five fixed roles

Platform admin, MSP technician, MSP read only, client user, and client read only. Read-only roles are enforced on the API too, not just hidden in the UI.

Client self-service access

Give a client contact their own scoped login to their own tenant, read-only or with writes. A feature to package and charge for, not another item on your support queue.

Per-tenant scoping

Every assignment carries a tenant scope of all, include, or exclude. Mark your own partner tenant platform-admin-only so technicians scoped to all tenants never see it.

Break-glass that fails closed

Sign-in resolves to an explicit assignment first, then a break-glass allowlist. An empty allowlist denies rather than handing admin to everyone on your domain.

Security

Posture you can set once and enforce everywhere

Policies & standards

Define the posture you expect once and WOSP checks every tenant against it, covering identity and access, Gmail safety, Chrome browser, directory hygiene, licensing, and storage. Most of this is detection rather than deployment: Google exposes far more of Workspace for reading than for writing, so WOSP reports what has drifted and tells you how to fix it. Where Google does allow the write, Chrome browser policy being the clearest case, WOSP can remediate for you.

Findings that read like advice

Every finding says what is recommended, what is currently set, why it matters in plain language, and what to do, with a deep link into the right Admin Console page. Written to stand on its own in a ticket or a client report, not to be decoded.

Compromise remediation

Gather business-email-compromise indicators for a suspect account, then remediate in one action: reset, revoke sessions and tokens, and clear the forwarding, filters, and delegation an attacker left behind.

OAuth app control

Inventory every third-party app authorized in a tenant, revoke in bulk, and work a triage queue of user requests for unconfigured apps so shadow IT gets an actual decision.

Sharing and shared drive audits

Find the shared drives with external members and the files exposed beyond the org, per tenant, without asking a client to run a report for you.

Inbound SAML review

See the SAML profiles configured in each client tenant and the recent SSO audit events against them, so a third-party IdP nobody told you about does not stay invisible.

Visibility

Reporting your clients actually read

Multi-tenant dashboard

User counts, storage, security signals, and prioritized issues for every client. Trend charts for email volume, spam versus delivered, and storage growth, not just today's snapshot.

Branded executive reports

Client-ready PDFs carrying your logo and color: posture, findings, licensing, storage, and device summaries. Hand it over in the QBR and skip the screen share.

PSA-integrated alerting

Collection failures, security findings, and Google alerts open tickets in your PSA. Each alert is ticketed once per cooldown window, so a recurring issue does not turn into forty tickets overnight.

Audit-log alert rules

Opt in to the Google Workspace audit events worth waking up for: logins, admin changes, Drive activity, token grants. Google Alert Center items land in the same pipeline.

Automated collection

Scheduled snapshots keep every dashboard fresh. Job monitoring reconciles orphans, times out stalled runs, and keeps a per-tenant history you can point at when a client asks what happened.

Platform audit log

Every mutating action and sign-in your own team takes, recorded with the tenant it touched and what changed. The answer to "who moved that user" and to your cyber insurance questionnaire.

Day-to-day admin

The rest of the console, multi-tenant

Users, groups, and org units

Provision, edit, search, and move across every tenant. Domains, admin roles, and calendar resources too.

Licensing & storage

License assignment by SKU, reclaimable seats, per-user Drive usage, and shared drive size, without a spreadsheet to keep in sync.

Devices and browsers

Chrome OS, mobile, and Chrome browser inventory with remote actions: approve, block, wipe, disable, deprovision. Chrome policy edits apply by org unit.

Gmail settings and delegation

Per-user Gmail configuration, delegation, forwarding, and compliance settings, reviewable across your client base rather than one mailbox at a time.

Adoption metrics

Meet, Calendar, Drive, Chat, Classroom, Docs, and Sites usage per tenant. Evidence for the license conversation you keep putting off.

Chat spaces and Classroom

Space inventory and membership, plus Classroom course administration for the education and nonprofit tenants that live in it.

Running it

One instance per MSP

Isolated per MSP

Your instance is yours. Tenants, settings, and history belong to your MSP alone and are never pooled with another provider's.

Guided tenant onboarding

A wizard walks the GCP project, OAuth client, and API enablement steps for a new client tenant, which is the part of Google Workspace multi-tenancy that usually eats an afternoon.

White-label branding

Your logo and color on the login screen and on every PDF report. Client-facing copy supports variables for MSP name, tenant name, and primary domain, so one template serves your whole client base.

Backup, restore, and migration

Export instance config and tenant connections as portable packages, and seed a new instance from a preferred-settings pack instead of reconfiguring it by hand.

REST API with scoped keys

A documented OpenAPI surface for automating against your client base. API keys carry a role, a tenant scope, an expiry, and their own write toggle, and are shown in full exactly once.

MCP server for Claude and Cursor

Point an AI assistant at your tenants over MCP and ask it to find compromised accounts or provision a user. Same roles, same tenant scoping, and writes stay behind a gate a platform admin controls.

Where Google draws the line. Google's admin APIs are narrower than Microsoft Graph, especially for org-wide tenant settings. WOSP documents every one of those gaps instead of pretending they are not there, and ships coverage as soon as Google makes an API usable.

Read the docs (opens in a new tab)