63 Audit-the-auditors alerting
draft
Vault searches and exports, investigation-tool queries and mailbox-delegation grants are the lawful privileged reads: they are how someone with legitimate access reads everyone else's mail without breaking anything. Activity rules on Vault log events and Admin log events raise a high-severity alert whenever they happen, routed to a recipient who is not an auditor or Vault admin — self-notification is not oversight.
Caveats
- A rule that notifies the auditors about the auditors is theatre — the recipient must sit outside the group being watched.
- A Vault admin with rule-edit privilege can disable the rule that watches them — pair this with the config-drift sentinel (№61).
- Basic activity rules are available in all editions, but Vault log events need a Vault add-on license and the investigation tool needs Enterprise Standard+, Frontline Standard+, Education Standard+ or Cloud Identity Premium — without those this control is partially blind.
Setup steps
- open ↗
https://admin.google.com/ac/sc/investigation · captured 2026-07-15
Reporting › Audit and investigation- Data source
Vault log events
- open ↗
https://admin.google.com/ac/ax · captured 2026-07-15
Rules › Create rule › ActivityCondition: Vault event in {search, export, hold created/deleted}; Severity = High
-
Rules › Create rule › ActivityRule: Admin log events, investigation-tool query; Rule: Gmail log events, Has delegate = true; Severity = High
-
- Recipients
oversight alias outside the Vault admin group
-
Ongoing maintenance
- requires a human Weekly: review auditor-activity alerts — the point is that someone other than the auditor reads them.
How to verify
-
Perform a benign privileged audit action (e.g. an investigation-tool search) and confirm the corresponding alert fires to the second-person channel.
draft v0.1.3 Detect edition Rules: all editions; Vault log events need a Vault license policy #30 · #18, #31 ↗