"An employee who left last month seems to have downloaded a massive batch of files from shared drives right before resigning. We are worried they took them to a competitor. But we have no way on our end to verify whether that really happened, or what and how much was taken."—This was a concern recently shared with us by an executive at a company of about thirty employees.
When data exfiltration or unauthorized access is suspected, many SMBs cannot trace who did what and when after the fact. Lacking the routine of reviewing logs and not even knowing where records are kept, companies are often left with nothing but lingering suspicion—a scenario that is far from uncommon. Google Workspace comes standard with audit logs that record user actions and alerts that notify administrators of suspicious signs. In this article, to avoid panic after an incident occurs, we outline how to establish detection readiness ahead of time, drawn from our perspective supporting clients through custom development.
Prevention alone is not enough: Detection and tracking are missing
When it comes to security configurations, many companies focus heavily on preventative measures designed to keep intruders out. Two-step verification, password policies, and restrictions on external sharing are all critical, as covered in our passkeys and two-step verification article and our access control (Context-Aware Access) article.
However, prevention is not foolproof. When an employee holding legitimate credentials downloads large volumes of files within their granted permissions, it is not an unauthorized intrusion, meaning preventative barriers will not stop it. That is why you need detection and tracking to notice when something happens and trace it afterward. As highlighted in the opening consultation, data exfiltration by departing employees or suspicious actions by compromised accounts remain invisible without logs and alerts.
Audit logs: Records of who did what and when
The Google Workspace Admin Console records audit logs categorized by type of action. Here are the primary ones:
Drive audit logs show who viewed, downloaded, shared, or deleted which file and when. If a specific employee's downloads surge around their departure date, traces remain here. Login audit logs reveal when, from where (IP address and region), and on what device a login occurred, allowing you to trace anomalies such as unfamiliar logins from overseas. Admin audit logs record the history of administrative actions, such as configuration changes and permission grants.
Higher editions offer longer retention periods and more granular tracking. With Business Standard or above, which SMBs commonly use, you can investigate key Drive and login logs back across a certain window. The key takeaway is that asking whether logs exist after an incident has occurred is too late. You must verify during normal operations which logs are kept and for how long under your current configuration.
| What you want to see | Log to use | What you can learn |
|---|---|---|
| Data exfiltration | Drive audit logs | Who downloaded, shared, or deleted what, and when |
| Suspicious logins | Login audit logs | When, from where, and on what device access occurred |
| Configuration tampering | Admin audit logs | Who changed permissions or sharing settings |
Catching events via alerts: Moving from passive to proactive detection
Logs are meant for investigating incidents after the fact, but relying on them alone delays your awareness of problems. That is where the Alert Center comes in. This mechanism sends notifications to administrators whenever indicators such as suspicious logins, phishing attempts, or mass file operations are detected.
For instance, it proactively alerts you to events like "a login occurred from an unusual region in a short span" or "an email suspected of containing malware was received." Higher editions also allow you to configure custom rules for specific conditions (e.g., mass downloads within a short period) to automate notifications and remediation upon detection. For SMBs that lack dedicated personnel to inspect logs daily, automating passive detection through alerts delivers immense value.
Case study: A company that turned suspicion into verified fact regarding a departing employee's data exfiltration
Here is a concrete example. A company (name withheld) that had previously experienced a scare similar to the opening scenario consulted us, wanting to ensure they could properly verify what happened if a similar situation arose again. The company had never inspected its logs and had no idea what was recorded where.
We began by auditing the retention status of Drive, login, and admin logs, integrating a mandatory step into their offboarding workflow—as detailed in our account offboarding article—to review Drive download history whenever an employee resigns. Alongside this, we configured key Alert Center notifications to reach the administrator's email, creating a posture where suspicious logins or mass operations could be caught during normal operations. A few months later, when an unfamiliar login from overseas occurred on another employee's account, an alert immediately notified the admin, who disabled the password and prevented damage before it occurred. What worked was having the foundation to investigate when suspicious and notice when anomalies happen ready before an incident took place.
Do not aim for advanced detection right away; start by checking retention and enabling alerts
A word of caution on sequencing: advanced detection mechanisms such as SIEM integrations or automated rule actions are not something SMBs should aim for right off the bat. The two things you must do first are checking how long your key logs are configured to be retained and ensuring Alert Center notifications reach administrators. These two steps require no additional cost, take effect immediately, and guarantee your ability to investigate and detect when needed. From there, integrate log reviews into offboarding procedures, and add custom rules or long-term archiving (such as Google Vault) as necessary. Following this order lets you build visibility without overburdening your organization.
If you are worried about data exfiltration, feel uneasy every time an employee leaves, or want to detect account takeovers promptly, please feel free to reach out through GleamHub's free IT and Google Workspace consultation. From auditing log retention and configuring alerts to establishing offboarding review procedures and designing long-term archiving where needed, we will partner with you within a manageable scope.
Sources
- About audit logs and the investigation tool - Google Workspace Admin Help
- Drive audit log - Google Workspace Admin Help
- About the alert center - Google Workspace Admin Help
- Understand audit and investigation | Google Workspace Admin Help
- Google Workspace Security Settings Review Guide 2026 | CloudNative BLOGs








