CrossTenant
Home / Features

Nine features. One console.

The full catalogue: what each feature page covers, capability by capability, and the job each one shows up in.

Prefer email? Get in touch and we run onboarding with you.

One console across the Google surface you already run

Directory, OUs
& devices
Mail
governance
Drive &
shared drives
Calendars &
resources
Gemini policy
oversight

Operate

Run the fleet

Cross-tenant everything

The scope picker, fleet-wide pages, safe bulk actions, tenant groups, customer health, and guided offboarding.

one scope picker per-tenant attribution writes route to the owning tenant dry-run previews tenant groups guided offboarding customer health
Job: offboarding a leaver

Device lifecycle

ChromeOS, mobile, workstations, and managed Chrome browsers: inventory and security actions with confirmation flows.

chromeos fleet mobile devices workstations managed chrome browsers cross-tenant device search security actions audited

Mail governance

Forwarding, delegates, send-as, IMAP/POP: audited across every mailbox with fleet-wide remediation.

auto-forwarding audit delegate audit send-as and aliases imap/pop posture fleet-wide remediation honest scan reporting complete tier
Job: auditing mailbox exposure

Google Cloud visibility

Projects, IAM posture, and billing links across your customers' Google Cloud estates: read-only, from the same console.

signals before any grant project inventory iam posture findings billing visibility keyless read-only access nothing persisted

Govern

Prove control

Security posture

CIS Benchmark and Cyber Essentials scoring, email authentication, policy drift, alert signals, and the console's own security architecture.

benchmark-based scoring email authentication policy drift and golden baselines breach and alert signals 2-step verification coverage no customer content at rest
Job: running a security review

Approvals & audit

Dry-runs, explicit confirmations, an optional second-approver gate, and a tamper-evident audit trail behind every write.

confirmation and dry-run optional second-approver gate fresh-eyes review approver notifications fail-closed gating tamper-evident audit

Reports & alerts

Branded PDF reports, scheduled delivery, threshold alerts, and operator-defined alert rules across the fleet.

report catalogue branded pdfs schedules threshold alerts operator-defined alert rules ai executive summaries

Extend

Extend the console

AI assistant

Fleet-wide answers, executive summaries, drafted fixes, and the governance model that keeps a human in charge.

fleet-wide answers executive summaries drafted fixes, never direct action dry-run first redaction before every call off until you say otherwise

Customer portal

Scoped, branded seats for co-managed IT: per-area access levels, enforced server-side.

scoped seats read-only or hands-on per area their branding server-side isolation invites and lifecycle everything audited
Job: co-managed IT

Features

See it against your own tenant first

There's a free tier for managing your own Workspace tenant while you evaluate. Then connect customers through the guided consent flow.