Who Should Have Admin Access to Company Phones?
Which people on a small team should be able to wipe, lock, change or only view company phones, and how to give time-limited admin access in Google Admin.
Fewer people should have admin access to company phones than most owners think. On a small team, one or two people should be able to wipe devices and change security rules. A few more can handle day-to-day jobs. Everyone else who wants to check on the fleet gets read-only access. And anyone who needs more access for a known stretch, such as holiday cover, should get it with an end date.
Security people call this least privilege. In plain words, nobody gets a door code for a room they never go into.
This guide covers how to split access for a team with 5 to 50 phones, what each level should allow, how to give time-limited access in the Google Admin console, and what to do when someone leaves.
Which actions are dangerous?
Start with what can go wrong rather than with job titles. Most actions in a device console are low risk. Two are not.
Erasing a device. A wipe removes everything on the phone. Done to the wrong device, it takes a working employee offline and can destroy data that wasn’t backed up.
Changing policies. A policy decides screen lock rules, whether staff can install apps from outside Google Play, whether USB data transfer is allowed, and more. One careless edit applies to every phone on that policy at once.
Everything else, such as locking a phone, rebooting it or refreshing its status, is easy to undo. That gives you a natural line. The people who can erase and change policies are your admins. The people who can’t are your helpers.
Who should have admin access on a small team?
Here’s how it usually maps out in a business with no IT department.
The owner. Full access. They’re accountable for the business and should always be able to get in.
One backup admin. Usually the office manager or operations lead. If the owner is on a flight when a phone goes missing, someone else has to be able to act. One backup is enough.
Shift leads, dispatchers and front desk leads. Day-to-day access. A delivery dispatcher at 6am needs to see which driver’s phone hasn’t checked in and reboot one that froze. They don’t need to wipe phones or relax the rules.
Bookkeepers, partners and consultants. Read-only. Your bookkeeper might want to see how many devices you’re paying for. A consultant reviewing your setup needs to look, not touch.
Take a cleaning company with 20 phones across three crews. The owner and the office manager are admins. The three crew leads get day-to-day access so they can help their crews. The accountant gets view-only. That’s six people, and only two of them can wipe a phone.
How NounDesk’s four roles map to this
The split is built into four roles:
- Owner: the person who runs the account.
- Admin: for your one backup.
- Operator: day-to-day work. An Operator cannot erase a device or change policies.
- Viewer: read-only.
Two other guardrails help. Erasing a single device needs a typed confirmation, so it can’t happen with one stray tap. And there’s no bulk erase at all, even for admins, so nobody can wipe the whole fleet by mistake.
NounDesk also keeps a complete audit log of what each person did. If a clinic’s receptionist phone suddenly has a new policy, you can see who published it and when, instead of asking around the front desk. Policies keep full version history too, so a bad change can be rolled back with one-click restore.
Any Android MDM you use should let you draw the same line. If yours gives everyone the same access, that’s worth fixing.
Why forgotten admin access is a problem
Most small businesses don’t hand out admin rights on a plan. Someone needs to add a new hire on a Friday afternoon, the owner is busy, and the office manager gets made an admin “for now”. Two years later they still have it, along with a shift lead who helped with a password reset once.
Google’s word for this is standing privileges: access that stays switched on long after the job it was for. Every extra admin account is one more account that can be phished, one more person who can change a setting by mistake, and one more name to chase when someone leaves.
How temporary admin roles work in the Google Admin console
Your phones are one half. Your Google Workspace accounts are the other: the email, calendars and shared drives signed in on those phones. In September 2026 Google added the option to assign administrator roles for a set period. It’s available to all Google Workspace customers, on both Rapid Release and Scheduled Release domains, and staff see no new setting.
The flow is the normal role assignment with one extra choice. When a super admin assigns a role, they pick how long it lasts: a preset length, such as 30 days, or an exact expiry date and time. When it runs out, Google removes the access. Nobody has to remember to take it back.
You can give a time-limited role to:
- A user, for example the person covering for someone on leave.
- A group, which suits a seasonal team where several people need the same access for the same stretch.
- A service account, for a tool or integration that only needs access during a project.
One limit: you can’t give the primary admin a temporary role. That account keeps permanent super admin rights, which makes sense, because someone has to be able to get back in. Make sure it belongs to the owner or someone permanent.
When should access be temporary?
A simple test: if you can say when the job ends, set an expiry. Google lists short projects, covering for a colleague and audits as typical uses.
- Holiday or sick cover. Set it to end the day the regular person comes back, plus a day’s buffer.
- A hiring push. A clinic front desk lead adding accounts for three new receptionists doesn’t need user management rights once they’ve started.
- An outside review. An auditor or consultant gets the narrowest role that lets them look, for the days they’re booked.
- A one-off project, such as moving a team to a new group structure.
Pick the smallest prebuilt role that covers the task, not super admin. A short expiry doesn’t fix a role that’s too broad. It only means it’s too broad for less time.
Matching temporary access on your phones
Google’s expiry covers the Google Admin console only. Your phones are managed in a separate tool with its own list of people who can sign in, and that list needs the same care.
NounDesk roles don’t expire on their own. So when you give someone temporary access in Google, write down the matching step for your devices: add them as an Operator for the cover period and put a removal date in your calendar. Every change they make is recorded in the audit log, so you can check afterwards what was done and by whom.
Take a delivery dispatcher covering the late shift for a month. They need to keep an eye on the drivers’ phones and help when one misbehaves. They don’t need the power to wipe a phone or loosen the screen lock rules, and an Operator doesn’t have it.
What happens when an admin leaves?
This is where most small businesses slip. An employee leaves, their phone gets handled, and their admin access to everything else stays open.
Make removing access part of offboarding, in this order:
- Remove or downgrade their role in your device console.
- Remove their admin roles in the Google Admin console.
- Check the audit log for anything they changed in their last weeks.
- Then deal with their phone. See what to do when an employee quits and keeps the company phone if it doesn’t come back.
A front desk lead who moves to a new job elsewhere shouldn’t still be an Operator a month later. It takes two minutes to remove them.
What to do this week
- Write the list. Every person who can sign in to your device console and your Google Admin console, and what they can do in each. Anyone without a current reason is a candidate for removal.
- Cut admins to two. The owner and one backup. Move everyone else down.
- Move helpers to Operator or Viewer. Shift leads and dispatchers get day-to-day access. Anyone who only needs to look gets read-only.
- Convert the “for now” admins. In Google Admin, reassign their roles with an expiry. For device roles, add a calendar reminder.
- Add phones to your cover checklist. When someone covers for a colleague, note both accesses on one line: the Google role with its expiry, and the device role with a removal date.
- Read your audit log once. Ten minutes of scrolling tells you who actually uses their access and who doesn’t.
FAQ
How many admins should a small business have for its company phones?
Two. The owner and one backup who can act when the owner can’t. Everyone else should get day-to-day or read-only access.
What can an Operator do in NounDesk?
An Operator handles day-to-day device work but cannot erase a device or change policies. It’s the right role for shift leads, dispatchers and front desk leads who help with phones but shouldn’t be able to wipe them.
What is a temporary admin role in Google Workspace?
A normal admin role with an end date. A super admin sets a preset length, such as 30 days, or a custom expiry date and time, and Google removes the access automatically when it runs out. The primary admin can’t be given one.
Do Google’s temporary roles control access to my phone management tool?
No. They govern the Google Admin console. Most device tools keep their own user list, so remove device access by hand when the cover period ends.
Should an outside consultant get admin access?
Usually not. Give them read-only access to your device console and the narrowest Google Workspace role that fits, set to expire when their work is done.
Getting access right is mostly a list and an afternoon. If you want roles that draw the line between helpers and admins for you, try NounDesk free and set them up on your own fleet.