1. Registering the Client ID with Domain-Wide Delegation
To allow TAC to query the company directory, Domain-Wide Delegation must be configured from the Admin Console.
Operational Steps
Log in to the Google Workspace Admin Console
Navigate to:
Security β API controls β Domain-wide delegation
Register the following Client ID:
Associate the following OAuth scopes:
Security Considerations
The granted scopes allow read-only access to users and groups.
There is no access to:
email content
Google Drive files
calendars or personal data
The delegation can be revoked at any time from the Google Workspace Admin Console.
Save the configuration.
2. Configuring the Integration in the TAC Portal
Once the configuration on the Google side is completed, the integration must be finalized in TAC.
Log in to the TAC portal: app.touchandcontact.com
Go to: Integrations β Google
Enter:
the service account associated with the Google Cloud project
Save the configuration.
This operation allows TAC to access the directory in an authenticated way and in compliance with corporate IT policies.
3. Importing and Managing Users in TAC
Once the integration is active, user administration remains fully under IT control.


