Learn
Guide


Managing app access during an employee’s probationary period is one of the most overlooked security and operational tasks in a growing business. The principle is straightforward: a new hire on a 90-day probation has different trust, role confirmation, and tool requirements than a permanent employee. Yet most Google Workspace environments handle both identically from day one, either over-provisioning access that creates real security exposure, or under-provisioning and slowing people down. The right approach is a deliberate, staged access model tied directly to employment milestones, not a one-time setup that nobody revisits.
TL;DR
The industry standard for new hire probation is 90 days, during which access should be role-appropriate but deliberately scoped
Google Workspace offers native access controls, but dynamic group management that auto-adjusts on employment milestones requires Enterprise-tier licensing
Excess privileges are a meaningful security risk: misuse of privileged credentials is a leading cause of data breaches
Transitioning from probationary to permanent access should trigger a structured review, not a manual email chain
Platforms purpose-built for Google Workspace can automate this entire lifecycle without requiring a dedicated IT team
About the Author: ShiftControl was founded by operators who scaled IT at ExpressVPN from 100 to over 700 employees across 7 global offices. The platform is purpose-built for Google Workspace, and the team has direct, firsthand experience designing access control systems for fast-growing companies without large IT departments.
Why does app access during probation actually matter for security?
Probationary access management sits at the intersection of HR process and IT security, and the gap between them is where risk lives. Misuse of privileged credentials is a leading cause of data breaches. Access tends to accumulate across cloud systems, creating excess privilege risks that compound as new hires take on more responsibilities.
For a new hire, the risk compounds. The employee’s role may not be fully confirmed yet. Their need for sensitive tools, financial data, or production systems is unproven. Giving permanent-employee-level access on day one means you are extending full trust to someone still in a trial phase. That is a reasonable decision for some roles and an unnecessary exposure for others.
The 90-day probation period is the industry norm, not a regulatory mandate in most jurisdictions. The Affordable Care Act does prohibit withholding health benefits for longer than 90 days, which has helped cement the period as a standard HR milestone. Tying app access reviews to that same 90-day mark creates a natural, defensible checkpoint.
What does Google Workspace natively offer for staged access control?
Building on the security case above, the practical question is what Google Workspace can actually do on its own. The answer is: quite a lot, with some important constraints.
Google Workspace provides role-based access control through Organizational Units (OUs), Google Groups, and custom admin roles. These allow granular control over which data and apps an employee can reach. For probationary employees, an admin can place new hires in a dedicated OU or group with a more restricted app policy, then manually move them to a permanent-employee group at the 90-day mark.
The limitation is that dynamic group management, which adjusts membership automatically based on user attributes or employment status, is only available in Google Workspace Enterprise Standard, Enterprise Plus, Enterprise for Education, and Cloud Identity Premium accounts. It is also capped at 500 groups and cannot include other groups as members or query admin roles directly. For companies on Business Starter or Business Standard plans, staged access tied to probation milestones requires manual admin intervention every time.
That manual step is exactly where things slip. A HR team signs off on an employee passing probation. Nobody tells IT. Access stays identical to day one. The review never happens.
What should a staged access model actually look like across 90 days?
A related but distinct question is how to structure the access tiers themselves. There is no universal template, but a practical framework looks like this:
Day 1 to Day 90 (Probationary)
Grant access to the core tools required to do the job: email, calendar, project management, communication tools
Restrict access to sensitive systems: financial platforms, HR data, production infrastructure, admin-level dashboards
Enable SSO for all provisioned apps so access is centrally trackable and revocable
Set a calendar reminder or automated alert for the 90-day review date
Day 90 Review Checkpoint
HR confirms pass/extend/fail status in writing
IT or operations receives a structured trigger to adjust access
If passing: promote to permanent-employee access group, add role-specific app entitlements
If extending: document the reason, maintain current access or restrict further if warranted
If not continuing: immediately revoke all access, following standard offboarding procedure
Post-Probation (Permanent Employee)
Full role-based access appropriate to department and seniority
Add to relevant team groups and collaboration tools
Consider access to higher-sensitivity systems on a role-by-role basis
The extension scenario is worth pausing on. When a probationary period is extended, many companies do nothing differently on the access side. That is a missed signal. An extended probation indicates unresolved uncertainty about the hire, and the access model should reflect that.
How can growing companies automate this without a dedicated IT team?
Stepping back from the mechanics, the harder operational question is who owns this process when there is no IT department. For most small and mid-sized businesses on Google Workspace, the answer is: whoever is least busy, which means it often does not happen consistently.
This is where a platform purpose-built for Google Workspace changes the operational picture. ShiftControl is built for exactly this situation: companies that run on Google Workspace, grow fast, and cannot afford to hire a full IT function to manage access lifecycle.
With ShiftControl, provisioning rules can be tied to employee attributes synced from HRIS systems like HiBob, BambooHR, or Deel. When an employee transitions from a probationary to a permanent status in the HRIS, that status change can trigger an automatic access update in Google Workspace and connected SaaS apps, without a manual admin step, without an email chain, and without waiting for someone to remember.
Dynamic group management handles the role-to-app mapping. SSO enforcement means every app access is traceable. The permissions visibility tools surface any third-party apps that may have accumulated access during the probationary period, so the 90-day review becomes a genuine security checkpoint, not just an HR formality.
Setup takes about 10 minutes via a single Google Workspace login. No implementation project. No IT hire required.
Frequently Asked Questions
Is the 90-day probationary period a legal requirement?
No. It is an industry standard, not a federal requirement in most jurisdictions. Montana has a default 12-month period. The ACA’s 90-day rule on health benefits has reinforced the norm for many employers.
What happens to app access if an employee fails probation?
Offboarding should begin immediately. All SSO sessions should be terminated, app access revoked, and credentials rotated for any shared accounts the employee accessed.
Can Google Workspace handle probation-based access tiers natively?
Yes, through OUs and Groups, but automating transitions based on employment milestones requires Enterprise-tier licensing for dynamic groups, or manual admin steps on lower-tier plans.
What is the biggest risk of not reviewing access at the 90-day mark?
Accumulated excess privileges. A probationary employee who has quietly accrued additional access over 90 days, through ad hoc requests or workarounds, becomes a permanent employee with an unaudited access footprint.
Does ShiftControl work with HRIS tools to trigger access changes?
Yes. ShiftControl integrates with HiBob, BambooHR, Omni HR, Deel, Gusto, Shapes, and others, allowing employment status changes in the HRIS to drive access changes automatically.
Do we need to inform the employee of a probation extension in writing?
Best practice and some jurisdictions require it. In California, for example, CalHR guidance specifies written notification for probationary period extensions, including the reason.
Is incident response included if a probationary access issue leads to a breach?
For ShiftControl subscribers, yes. Cyber incident response (IR-1) via Blackpanda is included in the subscription, covering containment, initial investigation, and 24/7 access to expert responders.
About ShiftControl
ShiftControl is an IT operations and SaaS management platform purpose-built for Google Workspace, designed for small and growing businesses that need enterprise-grade access control without the cost or complexity of a dedicated IT team. Founded by operators who scaled IT at ExpressVPN across 7 global offices, the platform covers provisioning and access, SaaS spend management, app-permission visibility, and incident response in one place. ShiftControl is SOC 2 compliant, ISO-aligned, and has signed the CISA Secure by Design Pledge. Cyber incident response via Blackpanda is included in every subscription as a standard feature. Transparent, public pricing is available for both standard and startup tiers.
Ready to automate your access lifecycle from probation to permanent? Visit shiftcontrol.io to see a live demo with no login required, or start a free trial with no commitment.
References
Probationary Periods for New Employees
90-Day Probation Period: Small Business Guide | FirstHR
Factorial - How to set employees’ probationary period?
Probationary Period Policy: Best Practices for Evaluating New Hires
Human Resources Manual - CalHR
