How to Create a Google Cloud Organization for Your Domain

Google Cloud

How to Create a Google Cloud Organization for Your Domain

A Google Cloud project without an organization belongs to whoever created it. Here is how to set up a free organization for your domain and move projects in.

Updated October 2, 2026

·

9 min read

A Google Cloud project that sits outside an organization is owned by people, not by your company. Whoever created it, often a freelancer, an agency, or an employee with a personal Gmail, holds the keys. When that person leaves, your GA4 export and your BigQuery warehouse can leave with them. Fixing this takes about an hour, costs nothing, and does not require Google Workspace.

This guide covers how to check whether your domain already has an organization, how to create one with Cloud Identity Free when it does not, and how to move existing projects in without breaking anything.

What a Google Cloud organization is

A Google Cloud organization is the top level container for all cloud resources that belong to one company. It is tied to exactly one domain, such as yourbrand.com, and it sits above every folder and project. Access you grant at the organization level flows down to every project underneath, and so do security policies.

Without an organization, each project stands alone. You see "No organization" in the project picker, there is no central place to see who has access to what, and the only safeguard against losing a project is that at least one Owner is still around and reachable.

Project without organizationProject inside an organization
Who ultimately controls itIndividual Owner accountsYour company, through its domain
Recovery when an Owner leavesDepends on that personOrganization admins can always regain access
Central access overviewNoYes, per organization, folder, or project
Security policies (org policies)Not availableAvailable and inherited by every project
CostFreeFree

If your warehouse holds data you care about, and your marketing data qualifies, it belongs inside an organization. We make the broader case in You Should Own Your Marketing Data Warehouse.

Check whether your domain already has one

You cannot create an organization directly. Google creates it automatically for every domain that has a Google Workspace or Cloud Identity account. So the first question is whether one of those already exists for your domain. Three quick checks:

1. Look at the mail records. If your email runs through Gmail, you have Workspace, and almost certainly an organization.

dig +short MX yourbrand.com

Results ending in aspmx.l.google.com or smtp.google.com mean Workspace. Anything else, for example your hosting provider's mail filter or Microsoft 365, means your mail does not run on Google. That still leaves the possibility of a Cloud Identity account without Gmail, so keep going.

2. Try the admin console. Sign in at admin.google.com with an address on your domain. If it opens, an account exists. If Google tells you the account does not exist, it does not.

3. Ask gcloud. If you already use the Google Cloud CLI with an account on your domain:

gcloud organizations list

If your domain appears with a numeric ID, the organization exists and you only need someone with the right role to give you access.

A google-site-verification TXT record in your DNS is not proof either way. Search Console, Google Analytics, and Tag Manager use the same kind of record.

Create the organization with Cloud Identity Free

If none of the checks turned anything up, set up Cloud Identity Free. It is Google's identity service without Gmail, Docs, or Drive, it is free for up to 50 users by default, and it is the cheapest way to get an organization. It does not touch your email: your MX records stay exactly as they are.

Step 1. Sign up. Go to cloud.google.com/identity and choose the free edition. Enter your company name and the domain you want to use.

Step 2. Create the super admin. Google asks you to create the first administrator account, for example [email protected]. This is a new Google account on your domain. Use a strong password and turn on two step verification right away. This account can reset everything else, so treat it like a master key and do not use it for daily work.

Step 3. Verify the domain. Google gives you a TXT record to add to your DNS. Add it at whoever hosts your DNS, which may be your registrar or a service like Cloudflare, not necessarily your web host. Verification usually completes within minutes, occasionally a few hours.

Step 4. Open the Cloud console. Sign in to console.cloud.google.com as the super admin and accept the terms. This is the moment Google provisions the organization. Confirm it with:

gcloud organizations list

You should now see your domain with an organization ID. Note that number, you need it to move projects.

The "conflicting account" message

If someone on your team already signed up for a Google account using their work address, for example to use Google Analytics before you had Workspace, Google calls that a conflicting account. It is a personal Google account that happens to use your domain. During setup you are asked how to handle these. The usual choice is to invite those people to transfer their account into your new Cloud Identity account, which keeps their access to Analytics, Tag Manager, and anything else they used it for.

Give yourself the right roles

The super admin can manage users, but on the Google Cloud side you want explicit roles. In the console, select the organization in the project picker, open IAM, and grant these to the people who manage your cloud setup. Use their own accounts, not the super admin:

RoleWhat it lets you do
Organization AdministratorManage access for the whole organization
Project CreatorCreate projects and move existing ones in
Billing Account AdministratorManage billing accounts under the organization

One default deserves attention. When Google creates an organization, it grants Project Creator and Billing Account Creator to everyone in your domain. In a small company that is convenient. As you grow, you probably want to remove those domain wide grants and give them to named people instead.

Move existing projects into the organization

A project without an organization can be moved in with one command. You need two things: Owner (or the Project Mover role) on the project, and Project Creator on the organization.

gcloud beta projects move your-project-id --organization=123456789012

Replace the project ID and the organization ID with your own. The move takes seconds and changes nothing inside the project:

  • BigQuery datasets, tables, and scheduled queries stay where they are.
  • The GA4 BigQuery export keeps running, because it writes to the project, not to the organization.
  • The billing account stays linked.
  • Existing IAM grants on the project stay in place.

What changes is that the project now inherits the organization's access and policies. That leads to the one thing to check afterwards.

Watch out for secure by default policies

Organizations created in the last two years come with a set of security policies switched on from day one. Most of them are sensible. One regularly catches marketing teams off guard: domain restricted sharing, the iam.allowedPolicyMemberDomains policy, which only lets you grant access to accounts in your own organization.

Existing access keeps working after a move. But the next time you try to give an agency, a freelancer, or an external data platform access to a dataset, you get an error saying the member does not belong to an allowed customer.

The fix is not to switch the policy off. Add the outside party's Google customer ID to the list of allowed customers, so you keep the protection and still decide exactly who gets in. You find this under IAM and admin, then Organization policies, in the console. Review the other default policies at the same moment, such as the block on creating service account keys, so none of them surprise you later.

Access control is one of the first things a security reviewer asks about when AI tools meet company data. Our checklist in The Security Review for AI on Your Marketing Data covers the rest.

Where Verity fits

Verity runs on your own BigQuery, in your own Google Cloud project, under your own IAM. That only means ownership if the project itself belongs to your company, which is why we recommend setting up an organization before anything else. With the project in place, our managed pipelines load your marketing sources into it, and you keep everything if you ever leave.

Frequently asked questions

Do I need Google Workspace to create a Google Cloud organization?

No. Cloud Identity Free gives you an organization without Gmail or any other Workspace app, and without changing your email setup. If you already have Workspace, you already have an organization and do not need Cloud Identity.

Does moving a project into an organization cause downtime?

No. The move changes the project's place in the hierarchy, not its contents. BigQuery tables, the GA4 export, scheduled queries, and billing all keep running during and after the move.

Can I create an organization with the gcloud CLI?

No. Organizations are only created by Google, automatically, when a domain has a Workspace or Cloud Identity account and a user from that domain signs in to the Cloud console. Once it exists, you can manage it and move projects in with gcloud.

What happens to the people who currently own the project?

Their Owner role on the project stays exactly as it was. The difference is that organization administrators can now always see and change access, so the project no longer depends on any single person. That is a good moment to review who still needs Owner and remove anyone who has left.

Can one organization cover more than one domain?

An organization has one primary domain, but you can add secondary domains to the same Cloud Identity or Workspace account. Users on those domains then belong to the same organization. This is useful when a brand runs several web shops on different domains.

Stop Guessing. Start Asking.

Verity turns your data into a conversation. Ask questions in plain language, get trusted answers backed by your actual data.