Skip to main content
Google’s domain-wide delegation grants third-party applications access to Google Workspace user data. GoGuardian uses domain-wide delegation to scan Google Docs data and generate GoGuardian Beacon alerts, Flagged Activity, and Smart Alerts in GoGuardian Admin. Domain-wide delegation is required only for users on The GoGuardian App. Extension-only users do not require it.

Configuration Steps

Follow these steps to configure domain-wide delegation.
  1. Sign in to the Google Admin console at admin.google.com.
  2. Navigate to https://admin.google.com/ac/owl/domainwidedelegation.
  3. Click Add new.
    1. Enter client ID 106647513164322986295.
    2. Under OAuth scopes, enter:
      1. https://www.googleapis.com/auth/drive.metadata.readonly
      2. https://www.googleapis.com/auth/drive.readonly
  4. Click Authorize.
  5. Repeat these steps for the second client ID: 116900415090928401393.
Google Admin Console domain-wide delegation configuration showing the client ID and OAuth scopes Google Admin Console domain-wide delegation configuration showing the authorized API clients
Changes may take up to 24 hours to complete.

Verify Permissions

After you complete the configuration, verify domain-wide delegation with a Google Docs URL and an administrator account:
  1. In Organization Management, click Next until Verify Permissions.
  2. On the Verify Permissions tab, enter the URL of a Google Docs document under Document URL.
  3. Under Admin Account, enter the email address of an administrator who has access to the Google document. Enter the email address in all lowercase. The permission test can fail if the address contains uppercase letters.
  4. Click Test Permissions.
  5. Click Next to complete the installation.
Organization Management Verify Permissions page with fields for a document URL and admin account If the configuration is incomplete, errors and the Installation Incomplete page appear. Organization Management permission validation error Organization Management Installation Incomplete page

FAQ

Q: If a student makes a new Google Doc, how long will it take for GoGuardian to generate any Beacon or Admin alerts? A: Processing takes approximately 1–2 minutes. Q: How often is content scanned via domain-wide delegation/Beacon? A: Each visit to a unique Google Docs file triggers this workflow. Content refreshes every 10 seconds while the student works in the file. Q: Can extension-only clients (those not using the GoGuardian App) use domain-wide delegation? A: Not at this time. Q: What types of docs does domain-wide delegation cover? Will it include Gmail, Google Slides, or Sheets? A: At this time, only Google Docs renders content in a way that requires domain-wide delegation. GoGuardian supports other Google products through the GoGuardian Extensions. Q: How does retroactive alerting work? For example, if a student has a Doc with self-harm content inside of it before domain-wide delegation is configured, will it be revealed once domain-wide delegation is set up? A: Domain-wide delegation does not retroactively identify self-harm or other content. An alert can be generated after a student returns to that Google Docs file. Q: Does domain-wide delegation expire or is it perpetual once it’s configured? A: Domain-wide delegation does not expire. Q: How can a school off-board from domain-wide delegation? A: To remove domain-wide delegation, delete app IDs 106647513164322986295 and 116900415090928401393 from domain-wide delegation in the Google Admin console. Q: What level of Google permissions are required for an admin to configure domain-wide delegation? A: Allow only the required scopes to access Google Docs content through the Google Drive API: https://www.googleapis.com/auth/drive.metadata.readonly and https://www.googleapis.com/auth/drive.readonly. These scopes provide read-only access to Google Drive content.
Last modified on August 12, 2026