Use cases → Admin and governance
Review and audit third-party app permissions with domain delegation
Enumerate which external apps have access to Workspace data and who has granted what, using a delegated account for accurate audits.
| Who it is for | Security and compliance teams responsible for data exposure risk. |
|---|---|
| APIs | Admin SDK |
| Typical scopes | admin.directory.user.security |
The problem
Third-party apps accumulate over time, often with broad or outdated permissions. Without regular review, risky access persists long after the original use-case is forgotten.
How it works
- List all users in the domain using the Admin SDK.
- For each user, enumerate OAuth grants via the security API as a delegated service user.
- Aggregate which apps have access, which scopes, and when each grant was last used.
- Flag apps with high-risk scopes or unused grants for review or removal.
What changes
You get a current, authoritative list of third-party app access across all accounts, supporting targeted clean-up and risk reviews.
Watch it explained
“How to create API access to Google Play Console and how to create a service account” — Advanced and improved App Store Management on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.
Questions people ask
Can this catch apps installed via the Marketplace?
Only if they use OAuth and the user has granted permissions. SAML and domain-wide delegated apps won’t show up—those require a separate review.
How often should we run this review?
Monthly or quarterly is typical, but after any security incident or policy change, run it immediately.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Audit which third-party apps can read your mail
List every OAuth grant across the domain and find the retired tools still holding access.
Automate joiners, movers and leavers
Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.
Continuously verify your delegation still works
A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.