domainwidedelegation.comStart free

Use cases → Admin and governance

Export user activity audit logs via delegation

Pull activity audit logs from multiple tenants using a service account, so you can inspect and archive user actions across your estate.

Who it is forSecurity, compliance, or operations teams responsible for cross-tenant audit and traceability.
APIsAdmin SDK
Typical scopesadmin.reports.audit.readonly

The problem

Workspace audit logs are per-tenant and only accessible through the Reports API, which can be slow and paginated. Manual export is infeasible at scale, and reliable automation is needed for compliance or incident response.

How it works

  1. Delegate the service account to an admin role with Reports API access.
  2. Call the Admin SDK's Activities.list endpoint for each tenant and event type.
  3. Paginate through results, handling time windows and nextPageToken correctly.
  4. Persist the logs with timestamp and tenant identifiers for downstream processing.

What changes

You have a reliable, machine-driven export of all relevant user activity, ready for analysis or archive, without manual intervention.

The trap in this one. The Reports API can silently omit recent events due to propagation lag. If you export up to 'now', you'll miss actions that haven't landed yet—these may only appear several minutes later. Always re-fetch the trailing window (e.g., last 15 minutes) in subsequent runs to avoid permanent gaps.

Watch it explained

“Export active users in Google Workspace using Foresight | xFanatical” — xFanatical on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.

Questions people ask

How far back can I fetch audit logs?

The API supports up to 180 days of retention for most event types, but availability varies; check Google's documentation for specifics.

How do I avoid missing late-arriving log events?

Always overlap the end of your export window on each run, and de-duplicate by event ID or timestamp when ingesting.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Audit which third-party apps can read your mail

List every OAuth grant across the domain and find the retired tools still holding access.

Automate joiners, movers and leavers

Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.

Continuously verify your delegation still works

A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.