"Relying solely on email with external partners leads to scattered communications." "We want to avoid paying for extra tools just because a partner uses Slack." For Google Workspace administrators facing these hurdles, this guide covers the guest account feature that entered general availability on March 30, 2026.
This feature lets you invite external users who do not hold Google Workspace accounts into environments like Google Chat, Drive, Docs, and Meet to collaborate. Its greatest strength is that a dedicated Organizational Unit (OU) for guests is automatically generated in the Admin Console, allowing external collaboration while upholding your existing security policies.
What is a guest account?
A guest account is a mechanism that allows you to invite external users who do not have a Google Workspace account to your company's Workspace domain as temporary accounts.
Invited external users only need a Google account (such as Gmail) to participate, with no need to purchase a new Workspace license. The inviting organization can welcome guests at no additional cost.
Differences from traditional "external sharing"
Previously, sharing files with external users who did not have Workspace required using "Visitor Sharing." Visitor Sharing was limited to specific files in Google Drive, making it impossible to unify overall communication, such as participating in Google Chat or scheduling Google Meet calls.
With guest accounts, you can collaborate with external partners across Chat DMs, spaces, Drive, Docs, Sheets, Slides, and Meet. Because chat, file sharing, and video conferencing are consolidated into a single environment, the fragmentation of information caused by juggling multiple tools is eliminated.
Three key points administrators should check
1. Automatic creation of the "Workspace Guests" OU
When a guest account is created, the "Workspace Guests" organizational unit (OU) is automatically added to Organizational Units in the Admin console (admin.google.com). Because all guests are consolidated under this OU, administrators can centrally manage the following operations:
- Reviewing the guest list and managing their lifecycle
- Applying 2-Step Verification and Context-Aware Access policies
- Restricting the scope of services permitted for guests
Default security policies are intentionally isolated from the root OU, applying baseline settings designed for guests right from the start. Administrators simply need to add configurations aligned with their company's policies.
2. Eligibility requirements and restrictions
Guest accounts have important security restrictions in place.
| Item | Guest user permissions |
|---|---|
| Sending and receiving Chat messages | Allowed |
| Receiving @mentions | Allowed |
| Editing Drive files (only those invited to) | Allowed |
| Creating and owning new files | Not allowed |
| Unlimited access to organizational files | Not allowed |
| Accessing the Admin console | Not allowed |
Because guests cannot create or own new files, data ownership is always retained by the inviting organization. Even if a guest's invitation is revoked, there is no risk of work data being taken outside the organization.
3. Controlling guest invitations through administrator settings
From the Admin console, you can control the scope of users who are allowed to send guest invitations. Leaving it set so that "anyone can invite guests" carries the risk of inadvertently generating large numbers of guest accounts. Please review the following settings before starting operations.
Configuration path: Admin console → Apps → Google Workspace → Google Chat → Chat settings
- Turning on/off "Allow users to invite external guests"
- Filtering the OUs or target groups of users permitted to invite guests
- Setting up trusted domains (allowing guest invitations only to specific domains)
A practical approach to operations is granting invitation privileges only to departments with frequent external collaboration (such as sales and project management) while disabling them for other OUs.
Guest account invitation flow
Actions taken by end users (internal members)
- Open the screen to create a DM or space in Google Chat
- Enter the external partner's Gmail address (or the email address of their Google account)
- Select "Invite as guest" and send
The external user receives an invitation notification by email. Once they accept the invitation, a guest account is automatically created, granting them immediate access to Chat and shared Drive content.
How it appears to guest users (external partners)
- In Chat, guest users display a teal "External" label (regular external Workspace users display a yellow label)
- Guests can also confirm for themselves that their account is treated as a "Guest"
- They can only access the spaces and files to which they have been invited, and cannot view other spaces or internal content
Best practices for security design
Regularly review guest lifecycles
If guest accounts are left unattended after a project ends, there is a risk that unnecessary access permissions will remain. Establish operational rules to periodically review the guest list in the "Workspace Guests" OU within the Admin console and promptly disable accounts once projects conclude.
Enforce 2-Step Verification
By requiring 2-Step Verification (2SV) for the "Workspace Guests" OU, you can significantly reduce the risk of unauthorized access to guest accounts. Even when guest users rely on personal Google accounts, guide them during onboarding to enable 2SV settings.
Leverage dedicated spaces rather than shared drives
When collaborating with external partners, rather than directly inviting them to internal shared drives, we recommend using project-specific Chat spaces and folders linked to them. The scope of guest access is clearly delineated by space, making post-project cleanup straightforward.
For details on using Google Chat spaces as project headquarters, please also refer to Hybrid Work Management Using Google Chat's Huddle Section.
Eligible plans and rollout schedule for the guest account feature
| Item | Details |
|---|---|
| Supported plans | Business Starter / Standard / Plus、Enterprise Starter / Standard / Plus |
| Availability of administrator settings | From March 26, 2026 (gradual rollout) |
| Availability for end users | April 13–16, 2026 |
| API availability (guest creation) | From May 2026 onwards (open beta) |
Workspace Essentials, Frontline, and Education editions are currently not eligible. We recommend checking your company's plan in the Admin console and creating an internal rollout plan in line with the rollout schedule.
Relationship with initial Google Workspace setup
The guest account feature operates on the premise that your organization's security policies and external sharing settings are properly configured. If basic GWS settings are not yet finalized, establish a domain-wide external sharing policy first before enabling this feature.
To systematically review everything from initial Workspace setup to operational design, please consult the Google Workspace Initial Setup Guide for Administrators.
Conclusion
The guest account feature in Google Workspace is a high-impact practical update that meets the demand to complete collaboration with external partners entirely within Workspace.
Here is a summary of the key takeaways:
- You can invite external users without Workspace accounts to Chat, Drive, and Meet
- Because guests cannot create or own new files, data ownership remains with your organization
- All guests can be centrally managed under the "Workspace Guests" OU, allowing security policies to be applied individually
- Administrators can control the scope of guest invitation permissions by OU
- Gradual rollout to end users takes place between April 13 and 16, 2026
Deciding internal rules for guest lifecycle management and the scope of invitation privileges before enabling the feature is key to secure operations.
If you need assistance with Google Workspace guest account configuration or security policy design for external collaboration, feel free to contact GleamHub.
Consult with us about Google Workspace configuration and operations








