Skip to content

Temporary Admin Roles in Google Workspace: What Changes

Google Workspace can now assign an admin role with an expiration date. How it works, which editions get it, its limits, and how to roll it out.

Updated on 2 October 2026

An outside contractor asks for admin access for a two-day audit. You grant it, the audit ends, and three months later you find that account still holding active admin rights in your console. Nobody remembered to remove them. This scenario is ordinary, and it is exactly what Google set out to eliminate with time-bound administrator roles, available in the Google Admin console since 23 September 2026.

What the feature does

A super administrator can now assign an admin role to a user, a group, or a service account for a defined period. When the expiration time arrives, the access granted by the role is revoked automatically. No human action is required at that moment.

When assigning the role, the super admin picks a predefined duration, such as 30 days, or sets a custom date and time. Google’s official Help Center page specifies a one-year maximum. You cannot set an expiration in the past, and the revocation does not renew on its own: once it triggers, you have to reassign the role to extend access.

Google frames the feature as an answer to a concrete security problem: the buildup of standing privileges and ambient access. The announcement appears on the Google Workspace Updates blog of 23 September 2026. It cites three use cases: short-term projects, coverage during an employee’s absence, and external audits.

The real benefit: least privilege becomes the default path

Every administrator knows the least-privilege principle. An account should hold only the rights it needs, for as long as it needs them. In practice, the second half of that sentence rarely holds. Removing access requires a deliberate action, and that action gets lost in daily operations.

Automatic expiration flips the burden. Instead of having to remember to remove a right, the admin decides when it will disappear at the moment of assignment. This is the setting we would turn on first for any admin access meant for one-off use. A contractor, a temp, a colleague covering a leave: in all these cases, the question “who will remember to remove this right?” no longer arises.

The effect goes beyond convenience. Every admin account that keeps unneeded rights widens the attack surface. A compromised password on an account that should have lost its privileges two months ago is worth far more to an attacker than an account already back to its baseline rights. Cutting standing privileges mechanically cuts exposure, as we explained in our article on essential Admin console settings.

What to know before you rely on it

The feature is available to all Google Workspace customers, with no edition restriction. That is good news: an SMB on Business Starter gets it just like an organisation on Enterprise Plus. The rollout covers Rapid Release and Scheduled Release domains. Google does note, though, that some enterprise accounts may not yet see the expiration options until the rollout is fully complete. If you cannot find them in your console, wait.

Only a super administrator can set a duration. A delegated admin, even one in charge of user management, does not set an expiration themselves. That centralisation fits the sensitive nature of granting admin rights, but it means the feature rests on the discipline of super admins.

One limit deserves attention: Google states you cannot assign multiple roles to the same user, group, or service account when those roles carry an expiration, even with different end times. An account that needs two distinct temporary roles will hit this constraint. Finally, the organisation’s primary admin cannot receive a temporary super admin role, and a time-bound super admin role prevents designating its holder as the primary admin. The pivot account must keep its rights permanently.

What the feature does not solve

Automatic expiration is not a full privileged-access management system. It grants a role for a duration and revokes it. It does not offer on-the-fly elevation requests approved case by case, nor a logged justification flow for each activation.

Two building blocks already exist for those needs. Google Workspace multi-party approval requires a second super admin to validate a sensitive role assignment before it takes effect. Combined with an expiration, it controls both who grants the right and how long it lasts. On the Google Cloud side, Privileged Access Manager handles temporary, approved elevations for cloud resources. These tools target organisations with a deeper audit requirement.

For most small and mid-size companies, nonprofits, schools, and small public bodies, native expiration covers the essentials. The watch point stays human: the feature does not tell you when an existing permanent access should be temporary. It acts on new assignments, not on the backlog. Auditing the roles already in place remains necessary, in line with what we describe for auditing your API key and Gemini exposure.

What an admin should do now

The first move is to check that the expiration options appear in your console, under Account then Admin roles. Then adopt a simple rule: any admin access granted for a one-off need gets an end date at assignment time. A contractor for a two-day audit gets a role set to seven days. A three-week coverage gets a role aligned with the holder’s return date.

The second, longer task is to review existing permanent assignments. How many accounts hold admin rights whose real use is occasional? Every permanent right that could be temporary is a security debt. The feature does not fix that retroactively, but it gives you the right tool to stop creating more. A coherent least-privilege posture combines this expiration with the rest of the console’s best practices, which we detailed in our guide on securing your business data with Google Workspace.



Do your Google Workspace admin accounts pile up rights that nobody ever removes? We audit your roles and set a least-privilege policy fit for your organisation. Let’s spend 30 minutes on your context.

Frequently asked questions

Are temporary admin roles available for every Google Workspace edition?
Yes. Google states the feature is available to all Google Workspace customers, without reserving expiration for a premium edition. It has rolled out since 23 September 2026 on both Rapid Release and Scheduled Release domains. Google notes, however, that some enterprise accounts may not yet see the expiration options until the rollout is fully complete. An admin who does not see them should wait for the rollout to reach their domain.
Who can assign an admin role with an expiration date?
Only a super administrator can set a duration on a role assignment. You do it in the Admin console, under Account then Admin roles. The super admin picks a predefined duration, such as 30 days, or a custom date and time up to one year maximum. A delegated administrator who does not hold the super admin role cannot set an expiration themselves. The feature centralises this sensitive action with super admins.
What happens when a temporary role's duration expires?
The access granted by the role is revoked automatically at the expiration time. The administrator loses the privileges tied to that role with no human action required. That is the core benefit: no more manually tracking temporary access or remembering to remove it after a short project, coverage during an absence, or an audit. The revocation does not renew itself, so you must reassign the role to extend access.
Can you give a temporary role to the primary super administrator?
No. Your organisation's primary admin must keep permanent super admin privileges because it receives the account's critical notifications. Google therefore prevents assigning it a super admin role with an expiration. A user who holds a temporary super admin role also cannot be designated as the primary admin. The constraint makes sense: the organisation's pivot account must never lose its rights through expiration.
Do temporary admin roles replace a privileged access management tool?
Not for every organisation. The feature covers the basic need: grant a role for a defined period and revoke it automatically. It does not provide on-demand approval for each elevation or a detailed justification flow. For those needs, Workspace multi-party approval adds validation by a second super admin, and Google Cloud environments have Privileged Access Manager. For most small and mid-size organisations, native expiration is enough.

Related Articles