Use cases → Admin and governance
Monitor third-party app access with a service account
Audit OAuth app grants across a domain using a delegated account, catching risky permissions before they become a problem.
| Who it is for | Security and compliance teams responsible for app governance in Workspace tenants. |
|---|---|
| APIs | Admin SDK |
| Typical scopes | admin.directory.user.security |
The problem
Unmonitored OAuth grants let third-party apps retain wide permissions, which can expose sensitive data or violate policy. Manual review is too slow and spotty, especially at scale.
How it works
- Use a service account with domain-wide delegation and the admin.directory.user.security scope.
- Enumerate all users and retrieve their OAuth token grants via the Admin SDK.
- Aggregate and flag apps with excessive, deprecated, or unapproved scopes.
- Schedule regular scans and log deltas for investigation.
What changes
You gain a near real-time view of which apps hold access, which users have granted them, and where intervention is needed.
Questions people ask
Does this show tokens granted in the past but since revoked?
No. The API only lists active tokens. Revoked or expired tokens are not returned, so you need to retain historical logs if you require that data.
How often should the monitoring run?
Daily is typical for most domains. High-risk environments may want to scan hourly, but watch out for Admin SDK quota limits.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Audit which third-party apps can read your mail
List every OAuth grant across the domain and find the retired tools still holding access.
Automate joiners, movers and leavers
Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.
Continuously verify your delegation still works
A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.