orgs running such ridiculous setups can monitor revokes coming over the wire from google and selectively apply them themselves, if they just care about their busy-work jobs sitting reading security bulletins. I don't really care about the security of their made-up non-jobs and google shouldn't either. they can do what they like.