As a Google Workspace administrator, you can control who in your organization can access the Vault service by turning Vault on or off for those people in your Google Admin console. For example, turn on Vault for accounts who have privileges to perform Vault functions and turn the service off for everyone else.
- Turning Vault on or off has no effect on which accounts are archived by Vault. All user accounts with Vault licenses can be archived.
- This setting has no effect on which accounts can change retention, search for data, or perform other Vault functions. Users must have appropriate Vault privileges to work with Vault.
- If you turn Vault on for everyone in your organization, the Vault icon appears in everyone’s list of apps. Users who don't have any Vault privileges may be confused by the presence of an app that seems to be nonfunctional. If your domain has organizational units, we recommend you restrict access to organizational units that have Vault privileges.
How to change who can sign in to Vault
Before you begin: To turn a service on or off for certain users, put their accounts in an organizational unit (to control access by department) or add them to an access group (to allow access for users across or within departments).
In the Admin console, go to Menu AppsGoogle WorkspaceGoogle Vault.
Click Service status.
To turn a service on or off for everyone in your organization, click On for everyone or Off for everyone, and then click Save.
(Optional) To turn a service on or off for an organizational unit:
- At the left, select the organizational unit.
- To change the Service status, select On or Off.
- Choose one:
- If the Service status is set to Inherited and you want to keep the updated setting, even if the parent setting changes, click Override.
- If the Service status is set to Overridden, either click Inherit to revert to the same setting as its parent, or click Save to keep the new setting, even if the parent setting changes.
Note: Learn more about organizational structure.
To turn on a service for a set of users across or within organizational units, select an access group. For details, go to Use groups to customize service access.