Use cases → Multi-tenant and agencies
Synchronise contact directories across multiple tenants
Keep user and shared contacts consistent between Google Workspace tenants using a delegated service account and the Directory API.
| Who it is for | IT teams managing multi-tenant environments or agencies with federated clients. |
|---|---|
| APIs | Admin SDK |
| Typical scopes | admin.directory.user, admin.directory.user.readonly |
The problem
When users move between tenants or need to collaborate across domains, inconsistent contact directories result in lost context, failed sharing, and extra manual work. Manual updates do not scale and quickly drift out of sync.
How it works
- Fetch all users from the source tenant using the Admin SDK with a service account.
- Map and transform attributes as needed to match the target tenant’s schema.
- Upsert users into the target tenant’s directory using the Admin SDK.
- Repeat for any shared contacts, handling deletions and updates.
- Schedule periodic syncs to maintain consistency.
What changes
Users across tenants see up-to-date contact details, and changes propagate automatically without manual intervention.
Questions people ask
Can I sync custom attributes or just basic contact fields?
You can sync custom schema fields, but you must provision the same custom schema in the target tenant before syncing or writes will silently drop those fields.
How often should the sync run?
Daily is typical, but the right interval depends on your user movement and tolerance for staleness. Watch for API quota limits when increasing frequency.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Synchronise contact directories across Workspace domains
Keep contacts in sync between separate Google Workspace domains using a delegated service account, avoiding manual exports and stale data.
Synchronise user directories across multiple domains
Keep user records in sync between Workspace tenants using a delegated service account with directory read and write access.
Operate several Workspace tenants from one service account
Authorize the same client ID in each domain and switch tenants simply by changing who you impersonate.