domainwidedelegation.comStart free

Use cases → Admin and governance

Review and audit third-party app permissions with domain delegation

Enumerate which external apps have access to Workspace data and who has granted what, using a delegated account for accurate audits.

Who it is forSecurity and compliance teams responsible for data exposure risk.
APIsAdmin SDK
Typical scopesadmin.directory.user.security

The problem

Third-party apps accumulate over time, often with broad or outdated permissions. Without regular review, risky access persists long after the original use-case is forgotten.

How it works

  1. List all users in the domain using the Admin SDK.
  2. For each user, enumerate OAuth grants via the security API as a delegated service user.
  3. Aggregate which apps have access, which scopes, and when each grant was last used.
  4. Flag apps with high-risk scopes or unused grants for review or removal.

What changes

You get a current, authoritative list of third-party app access across all accounts, supporting targeted clean-up and risk reviews.

The trap in this one. The Admin SDK’s OAuth grants endpoint only returns apps authorised via OAuth, not SAML or other methods. Service accounts miss delegated grants not issued to users directly, so your audit will silently exclude SAML-based or domain-wide delegated apps—leading to a misleadingly clean bill of health if you don’t cross-check. Always clarify what is and isn’t covered by the API, or risk missing entire categories of access.

Watch it explained

“How to create API access to Google Play Console and how to create a service account” — Advanced and improved App Store Management on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.

Questions people ask

Can this catch apps installed via the Marketplace?

Only if they use OAuth and the user has granted permissions. SAML and domain-wide delegated apps won’t show up—those require a separate review.

How often should we run this review?

Monthly or quarterly is typical, but after any security incident or policy change, run it immediately.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Audit which third-party apps can read your mail

List every OAuth grant across the domain and find the retired tools still holding access.

Automate joiners, movers and leavers

Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.

Continuously verify your delegation still works

A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.