Use cases → Admin and governance
Standardise user profile photos across the domain
Enforce consistent user profile photos by updating them in bulk via a delegated service account, ensuring uniform branding and compliance.
| Who it is for | IT administrators responsible for user identity, branding and compliance across a Workspace domain. |
|---|---|
| APIs | Admin SDK |
| Typical scopes | admin.directory.user |
The problem
Inconsistent user profile photos undermine corporate branding and can introduce compliance risks, especially when users upload personal or inappropriate images. Manually policing or updating photos is error-prone and doesn't scale.
How it works
- Prepare the standardised photo assets, ensuring they meet Google's format and size requirements.
- Fetch the list of users via the Admin SDK Directory API.
- Iterate through each user, updating their photo using the service account with domain-wide delegation.
- Log successes and failures for auditing and troubleshooting.
What changes
All users display the approved photo, supporting a consistent brand presence in Gmail, Calendar and Contacts.
Watch it explained
“Google Workspace (G Suite) Custom Attribute Creation | Collaboration Kernel” — Collaboration Kernel on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.
Questions people ask
How long does it take for updated photos to show everywhere?
Propagation is not immediate. Most Google services update within a few hours, but some caches (notably in Gmail and Contacts) can persist for up to 48 hours.
What happens if a user is suspended or deleted during the update?
The API returns a specific error for suspended or deleted accounts, which should be logged and handled separately to avoid retries or false alarms.
Want this built?
This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.
Talk to us Or read the setup guideRelated use cases
Audit which third-party apps can read your mail
List every OAuth grant across the domain and find the retired tools still holding access.
Automate joiners, movers and leavers
Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.
Continuously verify your delegation still works
A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.