Google Workspace admin setup
One-time setup, about 5 minutes. After it, a super admin can ask Claude to check which apps your team connected to Google Workspace.
What ToastBit asks Google for
| Permission Google shows | Why ToastBit needs it | What ToastBit does with it |
|---|---|---|
| See info about users on your domain | To know which accounts to check | Reads the user list. Suspended users are skipped. |
| Manage data access permissions for users on your domain | This is the only Google permission that can list each user's connected apps | Reads the list only. Google's permission would allow removing an app's access, but the extension is built to send read requests to two list addresses and nothing else. It does not remove or change apps. |
Google names the second permission "Manage" because Google offers no read-only version. ToastBit never uses the change or delete side of it. Sign-in is kept in memory only and never saved to disk. Asking Claude to sign out revokes it, and ToastBit tells you if Google did not confirm. Otherwise the access ends when Claude quits and expires at Google within an hour.
Step 1. Mark ToastBit as trusted
You need the Service Settings admin privilege (a super admin has it).
- Open the Google Admin console.
- Go to Menu → Security → Access and data control → API controls.
- Click Manage App Access, then Configure new app.
- Search for this client ID and select ToastBit AI Check:
169582214226-lmtk199dnssb9an4fe8gh8cb27gt1bea.apps.googleusercontent.com - Choose who it applies to. Your admin team's organizational unit is enough.
- Choose Trusted, click Continue, then Finish.
Until Google finishes reviewing ToastBit, Google may show an "unverified app" screen. Trusting the app in your console is Google's documented way for your own domain to use it.
Step 2. Run the check
- On the admin's computer, install the extension.
- In Claude Desktop, type: Check our Google Workspace for connected AI apps
- A Google sign-in page opens. Sign in as a super admin and allow both permissions.
- Return to Claude. It lists connected apps, what each can access, and which look like AI tools. People appear only as counts.
- To see who uses each app, ask Claude to save the report with user emails. That file stays on your computer. ToastBit never sends the emails to Claude.
Remove ToastBit's access at any time
- Ask Claude to sign out of Google. This revokes the session.
- In the Admin console, change ToastBit AI Check to Blocked under API controls → Manage App Access.
What the Google check does not cover
- Personal accounts, and AI tools used in a browser without Google sign-in.
- Service accounts or domain-wide access set up by an admin.
- Users whose list could not be read; the report counts them as "not checked", never as clean.