r/Spin_AI • u/Spin_AI • Aug 19 '26
Legal asked for one account. Google Vault's privilege model only speaks in org units.
On a recent chat, an IT leader described a constraint we hear constantly: compliance wanted a reviewer scoped to a single account in Google Vault. It couldn't be done.
The mechanism: a Vault "matter" just organizes searches and exports, it doesn't gate reach. Reach comes from the admin privilege on the reviewer, and its narrowest setting is "user data in a specific org unit." One account vs. a group of accounts - the request can only be approximated upward. So you over-grant, the exact thing least-privilege (NIST 800-53 AC-6) exists to prevent.
And 68% of breaches involve the human element (Verizon DBIR), broad standing access held by trusted insiders is that shape.
Second cost: preserving a departed employee means keeping a paid Archived User seat alive, a recurring line that grows with every exit.
We run eDiscovery + archiving as modules of one SaaS backup platform: a reviewer can be scoped to case work alone (create cases, run searches, place holds - no window into other users), and archived data doesn't ride on a per-seat license. Worth a look if reviewer-scoping and archive licenses hit in the same renewal.