From what I know about Google, they are serious about least privilege type of stuff internally and employees dont get arbitrary unbound access to systems or data.
And I agree, Google does take security more seriously than most places.
Only* about. GCP and AWS haven't had cross-tenant security bugs, meanwhile Azure have had multiple, and trivial ones to boot. If a multitenant service can have such poor security, it's doubtful internal only stuff is any better.