domainwidedelegation.comStart free

Use cases → Admin and governance

Monitor third-party app access with a service account

Audit OAuth app grants across a domain using a delegated account, catching risky permissions before they become a problem.

Who it is forSecurity and compliance teams responsible for app governance in Workspace tenants.
APIsAdmin SDK
Typical scopesadmin.directory.user.security

The problem

Unmonitored OAuth grants let third-party apps retain wide permissions, which can expose sensitive data or violate policy. Manual review is too slow and spotty, especially at scale.

How it works

  1. Use a service account with domain-wide delegation and the admin.directory.user.security scope.
  2. Enumerate all users and retrieve their OAuth token grants via the Admin SDK.
  3. Aggregate and flag apps with excessive, deprecated, or unapproved scopes.
  4. Schedule regular scans and log deltas for investigation.

What changes

You gain a near real-time view of which apps hold access, which users have granted them, and where intervention is needed.

The trap in this one. The Admin SDK’s token list endpoint returns only tokens granted directly to users, not tokens granted via group-based access or inherited from marketplace apps. This means some high-risk authorisations are invisible to your scan, so you must cross-check with the installed apps catalogue and not rely on the token list alone.

Questions people ask

Does this show tokens granted in the past but since revoked?

No. The API only lists active tokens. Revoked or expired tokens are not returned, so you need to retain historical logs if you require that data.

How often should the monitoring run?

Daily is typical for most domains. High-risk environments may want to scan hourly, but watch out for Admin SDK quota limits.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Audit which third-party apps can read your mail

List every OAuth grant across the domain and find the retired tools still holding access.

Automate joiners, movers and leavers

Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.

Continuously verify your delegation still works

A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.