Oten KMS Support
  • Welcome
  • Getting Started
    • What is Oten KMS
    • Why Oten KMS
  • USER GUIDE
    • User guide center
    • For Workspace Member
      • Google Drive
      • Google Calendar
      • Google Meet
      • Google Gmail
    • For Workspace Admin
      • Key management
      • Manage key version and rotation
      • Key lifecycle policies
      • Key usage history
      • Google CSE
        • Default Key Setup
        • CSE configuration
        • CSE Key Selection Rules
      • API Platform
        • Manage API keys
        • SDK guide
        • Rate limit
        • History log
    • For Organization Admin
      • Dashboard
      • Audit Logs
      • Workspace Routing Rules
      • Controlling Key Access in Your Organization
        • Workspace & Organization Routing Rules
        • CSE Key Selection Rules (Within a Workspace)
        • Combining Both Methods (Recommended)
        • Best Practices
      • Gmail provisioning setup
      • CA management
      • API Platform
        • Quota & Policy
        • Workspace quota
  • Google CSE Integration
    • Overview
    • CSE Integration Guideline
    • Google DEK Wrapping
    • Google DEK Unwrapping
    • View Google CSE Files Wrapped by Workspace Key
    • Google CSE Backup & Re-wrap
  • Supported services, applications, and data types with Google CSE
  • API Platform
    • Introduction
  • What's News
    • 2026
      • v1.0.15 - Jul 08, 2026
      • v1.0.14 - Jul 01, 2026
      • v1.0.13 - Jun 23, 2026
      • v1.0.12 - Jun 03, 2026
      • v1.0.11 - May 20, 2026
      • v1.0.10 - May 06, 2026
      • v1.0.9 - Apr 08, 2026
      • v1.0.8 - Apr 01, 2026
      • v1.0.7 - Mar 11, 2026
      • v1.0.6 - Mar 4, 2026
      • v1.0.5 - Feb 11, 2026
      • v1.0.4 - Feb 4, 2026
      • v1.0.3 - Jan 8, 2025
    • 2025
      • v1.0.2 - Dec 22, 2025
      • v1.0.1 - Dec 09, 2025
      • v1.0.0 - Nov 07, 2025
  • Privacy & Terms
    • Privacy Policy
    • Terms of Service
On this page
  1. USER GUIDE
  2. For Organization Admin

Workspace Routing Rules

PreviousAudit LogsNextControlling Key Access in Your Organization

Last updated 5 months ago

  • Objective
  • Function Purpose
  • Current MVP Limitation
  • Setup Impact

Objective

Establish a rule-based key routing mechanism for Google Workspace that automatically determines which workspace key is used to encrypt files, based on predefined conditions such as file name, user, or application.

This ensures that data is consistently encrypted with the correct key according to organizational policies, without relying on user decisions.


Function Purpose

Centralized Encryption Governance

Allow Organization Admins to define routing rules that control how files are encrypted across shared workspaces and individual user workspaces.

Automatic Key Selection

Ensure encryption key selection is fully automated based on rule priority and matching conditions, eliminating manual intervention and reducing misconfiguration risks.

Data Segregation by Design

Support isolation of:

  • Project-level data into project-specific workspaces

  • Personal or sensitive drafts into Individual Workspaces while maintaining enforceable access boundaries.


Current MVP Limitation

  • Rules are evaluated strictly by priority order (ascending).

  • The first matching Active rule is applied.

  • Archived rules are skipped but retain their priority number for audit consistency.

  • Routing is applied at the workspace level, not per key.

  • Per-rule key override inside the same workspace is not supported in MVP.


  • Set default rule for routing

  • Create new rule

  • Edit rule

  • Enable/Disable rule


  • Once a routing rule is created and active, all subsequent Google Workspace encryption operations are evaluated against the rule engine.

  • Applies regardless of who creates the file.

  • End users are not exposed to routing logic or workspace selection.

  • All decisions are enforced at the Oten KMS layer.

  • Rule creation, edits, deactivation, and runtime fallback events are recorded for audit and compliance purposes.

Priority-Based Single-Match Engine

Workspace-Level Routing Scope

Fallback-First Safety Model

  • If a rule target cannot be applied at runtime, the system falls back to:

  • This ensures encryption never fails silently.

Action

Setup Impact

Immediate Enforcement

No User Awareness Required

Audit-First Operation

The next valid rule, or

  • The Org Default Workspace