admin.directory.user.readonlyEnumerate workspace usersadmin.directory.group.readonlyResolve group membershipsadmin.directory.orgunit.readonlyMap users to organizational unitsadmin.directory.token.readonlyInventory OAuth grants per user across third-party appsadmin.reports.audit.readonlyPull Admin and Login audit log events
Google Workspace
Domain-wide install inventory, OAuth grant ledger, and per-user app rosters.
WHAT IT DOES
What ScopeMantle can do with Google Workspace.
- Inventory every domain-wide installed application and OAuth-granted third-party app
- Capture every per-user OAuth grant with the full scope set, install date, and last-used timestamp
- Resolve users into the live workspace directory with org unit and group context
- Stream Admin SDK and Login audit log events into the normalized event schema
- Revoke OAuth tokens individually or in bulk via opt-in governance write scope
LEAST PRIVILEGE
What we read, and what we don't.
- Read email bodies, calendar contents, or Drive file contents, ever
- Modify user records, mailbox settings, group memberships, or sharing permissions
- Initiate API calls on behalf of users, every read is authenticated as the ScopeMantle service account, not as your employees
- Touch Google Vault, Voice, or any service outside the governance read scopes
SETUP
Connect in a few steps.
- 01
Create a Google Cloud project and service account
Spin up a dedicated GCP project, enable the Admin SDK and Reports APIs, and create a service account scoped to ScopeMantle's use.
- 02
Enable domain-wide delegation
From the Google Workspace admin console, authorize the service account's client ID for the read-only scopes listed above. ScopeMantle does not request any write scopes by default.
- 03
Connect from ScopeMantle and run the first sync
Paste the service account JSON into ScopeMantle's connect flow. We seal the credential at rest with AES-GCM. First inventory completes in 15–60 minutes depending on workspace size.
- 04
Enable real-time event streaming
Optional but recommended. Enable Reports API event subscriptions; events flow into the normalized stream within a few minutes of occurrence.
Find the Context.ai in your org before the attacker does.
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.