Identity
OnTrackio + Google Workspace
Google sign-in on every tier, plus a shadow-IT view built from OAuth grants your users have already made.
What you get
- Google sign-in on every tier, with just-in-time account creation for invited users
- Allowed-domains restriction so only your workspace's domains authenticate
- Shadow-IT discovery: a scan of the OAuth grants your users have made surfaces the SaaS estate nobody procured
- Seat-utilisation signals for the license register, so paid seats map to actual use
How it connects
Sign-on is Google's standard OAuth flow, live on every tier. The shadow-IT scan connects to your Workspace with read scopes and lists the third-party applications holding OAuth grants from your users: the fastest honest answer to what SaaS is actually in use here, because it is built from grants that already exist rather than another agent or proxy.
What it deliberately does not do
The scan reads OAuth grants; it does not read email, files, or browsing. What it finds feeds the software register as candidates, and deciding what is sanctioned stays a human call.
Frequently asked questions
What exactly does the shadow-IT scan see?
The third-party applications your users have granted OAuth access to, with the scopes granted. It does not read message content, files, or browsing history, and the agent's own data collection policy is published separately and is similarly boring on purpose.
Is Google sign-in available on the cheapest tier?
Yes. Google and Microsoft sign-in are on every tier, because password hygiene should not be a premium feature. SAML and SCIM are the Enterprise-tier rails.
Does this replace an MDM for Google-managed devices?
No. The endpoint agent covers device inventory on macOS and Windows, and your MDM keeps doing enforcement. The Workspace integration is about identity and the SaaS estate, not device management.
All integrations: the full list. Identity posture, sub-processors, and residency: the security page.
See Google Workspace connected to a live workspace
A 30-minute demo covers the setup, the day-two behaviour, and the honest boundaries. Public pricing, no discovery-call gauntlet.