2 Alert recipient hygiene + suspicious-login alerts
Google raises security alerts of its own — suspicious logins, leaked passwords, compromised devices, admin-privilege changes — through system-defined rules that are already active. This control points those rules at a monitored mailbox with a named owner instead of the default 'all super admins', and fixes the organisation's admin contact addresses so Google's own notifications do not land in a departed admin's inbox. The detection already exists; the usual failure is that nobody receives it.
Documentation: About the alert center
Caveats
- Alerts default to every super admin — a recipient list that broad means nobody owns it, and nobody reads it.
- Turning a rule off only hides it from the alert center — the underlying event is still written to the audit logs, so you lose the alert, not the evidence.
Setup steps
-
-
- open ↗
https://admin.google.com/ac/groups · captured 2026-07-15
Create group security-alerts@<domain>; Members = the responders (owner + at least one deputy); Who can post = Anyone on the web (Google's alert mail originates outside your domain); Who can view conversations = Group members
-
Rules › <rule> › Actions- Email notifications
On- Recipients
security-alerts@<domain> (monitored group whose access settings allow senders from outside the organisation)
- open ↗
https://admin.google.com/ac/accountsettings/profile · captured 2026-07-15
Account › Account settings › Profile- Secondary email
a monitored address outside your Workspace domain (the console rejects in-domain addresses here)
Ongoing maintenance
- requires a human Quarterly: re-check rule recipients after admin departures — alerts routed to a leaver’s mailbox fail silently.
- automatable: AI agent Weekly: review the alert center for unhandled alerts.
How to verify
-
Trigger a harmless rule (e.g. sign in from a fresh browser profile to raise a suspicious-login event) and confirm the alert reaches the monitored mailbox.
-
Read the recipient list on each system-defined rule in Rules — every alert should route to the monitored security address.
v0.2.0 Detect policy #33 · #11 ↗