Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

All integrations
GW
IDENTITY·GA

Google Workspace

Domain-wide install inventory, OAuth grant ledger, and per-user app rosters.

WHAT IT DOES

What ScopeMantle can do with Google Workspace.

  • Inventory every domain-wide installed application and OAuth-granted third-party app
  • Capture every per-user OAuth grant with the full scope set, install date, and last-used timestamp
  • Resolve users into the live workspace directory with org unit and group context
  • Stream Admin SDK and Login audit log events into the normalized event schema
  • Revoke OAuth tokens individually or in bulk via opt-in governance write scope

LEAST PRIVILEGE

What we read, and what we don't.

We read
  • admin.directory.user.readonlyEnumerate workspace users
  • admin.directory.group.readonlyResolve group memberships
  • admin.directory.orgunit.readonlyMap users to organizational units
  • admin.directory.token.readonlyInventory OAuth grants per user across third-party apps
  • admin.reports.audit.readonlyPull Admin and Login audit log events
We never
  • Read email bodies, calendar contents, or Drive file contents, ever
  • Modify user records, mailbox settings, group memberships, or sharing permissions
  • Initiate API calls on behalf of users, every read is authenticated as the ScopeMantle service account, not as your employees
  • Touch Google Vault, Voice, or any service outside the governance read scopes

SETUP

Connect in a few steps.

  1. 01

    Create a Google Cloud project and service account

    Spin up a dedicated GCP project, enable the Admin SDK and Reports APIs, and create a service account scoped to ScopeMantle's use.

  2. 02

    Enable domain-wide delegation

    From the Google Workspace admin console, authorize the service account's client ID for the read-only scopes listed above. ScopeMantle does not request any write scopes by default.

  3. 03

    Connect from ScopeMantle and run the first sync

    Paste the service account JSON into ScopeMantle's connect flow. We seal the credential at rest with AES-GCM. First inventory completes in 15–60 minutes depending on workspace size.

  4. 04

    Enable real-time event streaming

    Optional but recommended. Enable Reports API event subscriptions; events flow into the normalized stream within a few minutes of occurrence.

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.