Skip to main content

Google Workspace Configuration Guide for TAC Integration

This procedure describes the secure, traceable, and reversible configuration of Google Workspace to allow TAC to access the company directory and synchronize authorized users and groups.

1. Registering the Client ID with Domain-Wide Delegation

To allow TAC to query the company directory, Domain-Wide Delegation must be configured from the Admin Console.

Operational Steps

  1. Log in to the Google Workspace Admin Console

  2. Navigate to:

    Security β†’ API controls β†’ Domain-wide delegation

  3. Register the following Client ID:

  4. Associate the following OAuth scopes:

Security Considerations

The granted scopes allow read-only access to users and groups.

There is no access to:

  • email content

  • Google Drive files

  • calendars or personal data

The delegation can be revoked at any time from the Google Workspace Admin Console.

Save the configuration.


2. Configuring the Integration in the TAC Portal

Once the configuration on the Google side is completed, the integration must be finalized in TAC.

  1. Log in to the TAC portal: app.touchandcontact.com

  2. Go to: Integrations β†’ Google

  3. Enter:

  • the service account associated with the Google Cloud project

  1. Save the configuration.

This operation allows TAC to access the directory in an authenticated way and in compliance with corporate IT policies.


3. Importing and Managing Users in TAC

Once the integration is active, user administration remains fully under IT control.

Did this answer your question?