Connect: a Super Admin adds our service account Client ID and read-only OAuth scopes under Admin Console → Security → API controls → Domain-wide delegation, then verifies the connection in the portal. Start from the free scan (choose Google Workspace).
Users counted: active Directory users from Admin SDK. Guests and disabled accounts are excluded.
Example alert: “Alex Chen was assigned the Super Admin role on 2026-05-31 14:22 UTC. 2-Step Verification: not enrolled. Evidence: snapshot 8c4f… SHA-256 a91d…”
Honest parity: some sub-controls have limited Google API signal (e.g. Windows desktop patching, native Google Docs macros). Those are scored as no visibility or not applicable — not guessed.
MSP onboarding: share the Google connect wizard — Client ID, scopes, and DWD steps — no new contract per client tenant.
Full Google Workspace scope list →