Evidence-backed facts
- Each Google Workspace API defines OAuth scopes that state the data type and access level requested; a connector must select the narrowest API-specific scope. informative
- Write capability depends on the exact API method and granted scope and cannot be inferred from successful authentication or a broader product name. informative
- User access uses OAuth consent; server-to-server access can use service accounts, and domain-wide delegation requires Workspace administrator authorization and explicit scopes. informative
- Sensitive or restricted scopes can require additional review, and no connector may infer domain-wide access from a service-account credential alone. informative