Use cases → Admin and governance
Report application access across the entire organisation
Survey which third-party and internal apps have OAuth access in your Workspace tenant using a service account with domain-wide delegation.
| Who it is for | IT security teams and Workspace administrators responsible for monitoring external app access. |
|---|---|
| APIs | Admin SDK |
| Typical scopes | admin.reports.audit.readonly, admin.directory.user.readonly |
The problem
Untracked app authorisations create security gaps and compliance risks. Manual spot-checking misses users and does not scale, leaving dormant or malicious apps undetected.
How it works
- Use a service account with domain-wide delegation to impersonate users.
- List all users in the domain via the Directory API.
- Iterate over users and fetch each user's authorised OAuth clients using the Tokens API.
- Aggregate and report which apps have access and which scopes they hold.
What changes
You see a current record of all app authorisations in the domain, with enough detail to audit or remediate risky access.
Questions people ask
Can I see which scopes each app has for a user?
Yes, the Tokens API returns the list of scopes granted to each OAuth client per user. Parse these carefully, as scope strings are case-sensitive and not always documented.
How often should I run the report?
Daily or weekly is typical. Note that revocations or new grants can appear with a delay of several hours in the API.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Audit which third-party apps can read your mail
List every OAuth grant across the domain and find the retired tools still holding access.
Automate joiners, movers and leavers
Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.
Continuously verify your delegation still works
A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.