Learn

Guide

From Probation to Permanent: How to Adjust App Access as New Hires Clear Their First 90 Days in Google Workspace

From Probation to Permanent: How to Adjust App Access as New Hires Clear Their First 90 Days in Google Workspace

From Probation to Permanent: How to Adjust App Access as New Hires Clear Their First 90 Days in Google Workspace

How to stage Google Workspace app access across a 90-day probation period: what to grant on day one, what to review at day 90, how to automate it.

How to stage Google Workspace app access across a 90-day probation period: what to grant on day one, what to review at day 90, how to automate it.

Julien Monguillot

Julien Monguillot

Julien Monguillot

Co-Founder

Co-Founder

Co-Founder

Created:

Created:

Created:

Learn

Managing app access during an employee’s probationary period is one of the most overlooked security and operational tasks in a growing business. The principle is straightforward: a new hire on a 90-day probation has different trust, role confirmation, and tool requirements than a permanent employee. Yet most Google Workspace environments handle both identically from day one, either over-provisioning access that creates real security exposure, or under-provisioning and slowing people down. The right approach is a deliberate, staged access model tied directly to employment milestones, not a one-time setup that nobody revisits.

TL;DR

  • The industry standard for new hire probation is 90 days, during which access should be role-appropriate but deliberately scoped

  • Google Workspace offers native access controls, but dynamic group management that auto-adjusts on employment milestones requires Enterprise-tier licensing

  • Excess privileges are a meaningful security risk: misuse of privileged credentials is a leading cause of data breaches

  • Transitioning from probationary to permanent access should trigger a structured review, not a manual email chain

  • Platforms purpose-built for Google Workspace can automate this entire lifecycle without requiring a dedicated IT team

About the Author: ShiftControl was founded by operators who scaled IT at ExpressVPN from 100 to over 700 employees across 7 global offices. The platform is purpose-built for Google Workspace, and the team has direct, firsthand experience designing access control systems for fast-growing companies without large IT departments.

Why does app access during probation actually matter for security?

Probationary access management sits at the intersection of HR process and IT security, and the gap between them is where risk lives. Misuse of privileged credentials is a leading cause of data breaches. Access tends to accumulate across cloud systems, creating excess privilege risks that compound as new hires take on more responsibilities.

For a new hire, the risk compounds. The employee’s role may not be fully confirmed yet. Their need for sensitive tools, financial data, or production systems is unproven. Giving permanent-employee-level access on day one means you are extending full trust to someone still in a trial phase. That is a reasonable decision for some roles and an unnecessary exposure for others.

The 90-day probation period is the industry norm, not a regulatory mandate in most jurisdictions. The Affordable Care Act does prohibit withholding health benefits for longer than 90 days, which has helped cement the period as a standard HR milestone. Tying app access reviews to that same 90-day mark creates a natural, defensible checkpoint.

What does Google Workspace natively offer for staged access control?

Building on the security case above, the practical question is what Google Workspace can actually do on its own. The answer is: quite a lot, with some important constraints.

Google Workspace provides role-based access control through Organizational Units (OUs), Google Groups, and custom admin roles. These allow granular control over which data and apps an employee can reach. For probationary employees, an admin can place new hires in a dedicated OU or group with a more restricted app policy, then manually move them to a permanent-employee group at the 90-day mark.

The limitation is that dynamic group management, which adjusts membership automatically based on user attributes or employment status, is only available in Google Workspace Enterprise Standard, Enterprise Plus, Enterprise for Education, and Cloud Identity Premium accounts. It is also capped at 500 groups and cannot include other groups as members or query admin roles directly. For companies on Business Starter or Business Standard plans, staged access tied to probation milestones requires manual admin intervention every time.

That manual step is exactly where things slip. A HR team signs off on an employee passing probation. Nobody tells IT. Access stays identical to day one. The review never happens.

What should a staged access model actually look like across 90 days?

A related but distinct question is how to structure the access tiers themselves. There is no universal template, but a practical framework looks like this:

Day 1 to Day 90 (Probationary)

  • Grant access to the core tools required to do the job: email, calendar, project management, communication tools

  • Restrict access to sensitive systems: financial platforms, HR data, production infrastructure, admin-level dashboards

  • Enable SSO for all provisioned apps so access is centrally trackable and revocable

  • Set a calendar reminder or automated alert for the 90-day review date

Day 90 Review Checkpoint

  • HR confirms pass/extend/fail status in writing

  • IT or operations receives a structured trigger to adjust access

  • If passing: promote to permanent-employee access group, add role-specific app entitlements

  • If extending: document the reason, maintain current access or restrict further if warranted

  • If not continuing: immediately revoke all access, following standard offboarding procedure

Post-Probation (Permanent Employee)

  • Full role-based access appropriate to department and seniority

  • Add to relevant team groups and collaboration tools

  • Consider access to higher-sensitivity systems on a role-by-role basis

The extension scenario is worth pausing on. When a probationary period is extended, many companies do nothing differently on the access side. That is a missed signal. An extended probation indicates unresolved uncertainty about the hire, and the access model should reflect that.

How can growing companies automate this without a dedicated IT team?

Stepping back from the mechanics, the harder operational question is who owns this process when there is no IT department. For most small and mid-sized businesses on Google Workspace, the answer is: whoever is least busy, which means it often does not happen consistently.

This is where a platform purpose-built for Google Workspace changes the operational picture. ShiftControl is built for exactly this situation: companies that run on Google Workspace, grow fast, and cannot afford to hire a full IT function to manage access lifecycle.

With ShiftControl, provisioning rules can be tied to employee attributes synced from HRIS systems like HiBob, BambooHR, or Deel. When an employee transitions from a probationary to a permanent status in the HRIS, that status change can trigger an automatic access update in Google Workspace and connected SaaS apps, without a manual admin step, without an email chain, and without waiting for someone to remember.

Dynamic group management handles the role-to-app mapping. SSO enforcement means every app access is traceable. The permissions visibility tools surface any third-party apps that may have accumulated access during the probationary period, so the 90-day review becomes a genuine security checkpoint, not just an HR formality.

Setup takes about 10 minutes via a single Google Workspace login. No implementation project. No IT hire required.

Frequently Asked Questions

Is the 90-day probationary period a legal requirement?

No. It is an industry standard, not a federal requirement in most jurisdictions. Montana has a default 12-month period. The ACA’s 90-day rule on health benefits has reinforced the norm for many employers.

What happens to app access if an employee fails probation?

Offboarding should begin immediately. All SSO sessions should be terminated, app access revoked, and credentials rotated for any shared accounts the employee accessed.

Can Google Workspace handle probation-based access tiers natively?

Yes, through OUs and Groups, but automating transitions based on employment milestones requires Enterprise-tier licensing for dynamic groups, or manual admin steps on lower-tier plans.

What is the biggest risk of not reviewing access at the 90-day mark?

Accumulated excess privileges. A probationary employee who has quietly accrued additional access over 90 days, through ad hoc requests or workarounds, becomes a permanent employee with an unaudited access footprint.

Does ShiftControl work with HRIS tools to trigger access changes?

Yes. ShiftControl integrates with HiBob, BambooHR, Omni HR, Deel, Gusto, Shapes, and others, allowing employment status changes in the HRIS to drive access changes automatically.

Do we need to inform the employee of a probation extension in writing?

Best practice and some jurisdictions require it. In California, for example, CalHR guidance specifies written notification for probationary period extensions, including the reason.

Is incident response included if a probationary access issue leads to a breach?

For ShiftControl subscribers, yes. Cyber incident response (IR-1) via Blackpanda is included in the subscription, covering containment, initial investigation, and 24/7 access to expert responders.

About ShiftControl

ShiftControl is an IT operations and SaaS management platform purpose-built for Google Workspace, designed for small and growing businesses that need enterprise-grade access control without the cost or complexity of a dedicated IT team. Founded by operators who scaled IT at ExpressVPN across 7 global offices, the platform covers provisioning and access, SaaS spend management, app-permission visibility, and incident response in one place. ShiftControl is SOC 2 compliant, ISO-aligned, and has signed the CISA Secure by Design Pledge. Cyber incident response via Blackpanda is included in every subscription as a standard feature. Transparent, public pricing is available for both standard and startup tiers.

Ready to automate your access lifecycle from probation to permanent? Visit shiftcontrol.io to see a live demo with no login required, or start a free trial with no commitment.

References

  1. Probationary Periods for New Employees

  2. 90-Day Probation Period: Small Business Guide | FirstHR

  3. Factorial - How to set employees’ probationary period?

  4. Probationary Period Policy: Best Practices for Evaluating New Hires

  5. Human Resources Manual - CalHR

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.