domainwidedelegation.comStart free

Use cases → Multi-tenant and agencies

Synchronise contact directories across multiple tenants

Keep user and shared contacts consistent between Google Workspace tenants using a delegated service account and the Directory API.

Who it is forIT teams managing multi-tenant environments or agencies with federated clients.
APIsAdmin SDK
Typical scopesadmin.directory.user, admin.directory.user.readonly

The problem

When users move between tenants or need to collaborate across domains, inconsistent contact directories result in lost context, failed sharing, and extra manual work. Manual updates do not scale and quickly drift out of sync.

How it works

  1. Fetch all users from the source tenant using the Admin SDK with a service account.
  2. Map and transform attributes as needed to match the target tenant’s schema.
  3. Upsert users into the target tenant’s directory using the Admin SDK.
  4. Repeat for any shared contacts, handling deletions and updates.
  5. Schedule periodic syncs to maintain consistency.

What changes

Users across tenants see up-to-date contact details, and changes propagate automatically without manual intervention.

The trap in this one. The Directory API enforces rate limits and sometimes returns HTTP 409 on upserts if a user was recently deleted or is pending restore—these are not retriable in the same cycle and must be handled with backoff and state tracking. Failing to record the exact sync state leads to repeated 409s or orphaned contacts, especially when automation retries blindly.

Questions people ask

Can I sync custom attributes or just basic contact fields?

You can sync custom schema fields, but you must provision the same custom schema in the target tenant before syncing or writes will silently drop those fields.

How often should the sync run?

Daily is typical, but the right interval depends on your user movement and tolerance for staleness. Watch for API quota limits when increasing frequency.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Synchronise contact directories across Workspace domains

Keep contacts in sync between separate Google Workspace domains using a delegated service account, avoiding manual exports and stale data.

Synchronise user directories across multiple domains

Keep user records in sync between Workspace tenants using a delegated service account with directory read and write access.

Operate several Workspace tenants from one service account

Authorize the same client ID in each domain and switch tenants simply by changing who you impersonate.