Skip to content

Google Workspace admin guide

Audience: Google Workspace administrators at organizations using Scale Platform. All identifiers in this guide are real. Maintained by Scale Company; questions to support@scale-company.com.

Max Scale, the AI co-worker in Scale Platform, can evaluate your innovation projects against documents your team keeps in Google Drive, without your team uploading copies into Scale Platform. This guide explains exactly what access Scale Platform requests, what it does and does not do with it, and how to enable it for your organization: with one admin action (recommended), or per user.

Scale Platform requests a single OAuth scope: drive.readonly, user-delegated and read-only. Both capabilities below run on that one scope. There is no lesser-privilege tier to start with, and Google’s narrower per-file scope (drive.file) is not used.

Linked files Linked folders
Who acts Each user, via the file picker in Scale Platform Each user, via the file picker in Scale Platform
What Scale Platform can read Only the files a user explicitly links Files the authorizing user can see, directly inside a folder your team links to a project. Subfolder contents are not included
New-file discovery in a linked folder n/a Yes, when someone refreshes the project’s sources. Scale Platform does not poll Drive in the background
Google Meet transcripts as evidence Only if explicitly linked Yes (via the linked folder)
OAuth scope drive.readonly drive.readonly

Because drive.readonly is one of Google’s restricted scopes, connecting requires either your one-time approval (recommended, see below) or, where your domain allows it, each user accepting Google’s unverified-app warning.

What Scale Platform does, and does not do, with this access

Section titled “What Scale Platform does, and does not do, with this access”
  • User-delegated, read-only. Scale Platform reads through the Google account of the specific team member who connects a folder. It can never see more than that person can see. There is no domain-wide or admin-level access of any kind.
  • Explicit linking only. Scale Platform touches only the folders and files your team explicitly links to a project, never a general scan of anyone’s Drive.
  • No copies stored. Scale Platform stores references (file IDs, names, revision info), not file contents. Document content is fetched transiently at evaluation time, processed, and discarded. Details: the Scale Platform workspace-integrations design (available on request) and Scale Company’s DPA.
  • A short classification is kept beside the reference. After reading a document, Max records its kind, the dates it covers, its language and length, and what it is evidence for. It adds a one-line note of what the document is for, at most 200 characters. Never the content. Max is told not to write a person’s name into that note, and a note that names one is dropped before it is stored. A person may also attach a short note of their own to a file, stored as typed. All of it is deleted with the file, when the folder is unlinked, and when the grant is revoked.
  • Read-only scope. drive.readonly cannot modify, share, or delete anything.
  • Revocable at any time, see below. Unlinking a folder in Scale Platform also stops all access to it.
  • Scale Company is ISO/IEC 27001:2022 certified (INTERCERT, reg. IC-IS-2605087). Processing runs on Google Cloud (EU); Google is a sub-processor under Scale Company’s DPA.
  • Our certificate, DPA, sub-processor list and security documentation are published at trust.scale-company.com.

Google requires a third-party security assessment (CASA Tier 2) before an app using drive.readonly is publicly listed as verified. Scale Company’s assessment is in progress (status available on request). Google explicitly supports admins granting access ahead of that by marking a specific app as trusted for their domain. That is the action below, and it is scoped to your domain only.

What your users hit until then depends on your own API access-control settings:

  • If you have not restricted third-party access to Drive, users see Google’s “Google hasn’t verified this app” screen and can proceed via Advanced → Go to scale-company.com (unsafe).
  • If you have restricted it (common in security-managed domains), the connection is blocked outright and there is nothing for the user to click.

While unverified, Google identifies the app by its domain, scale-company.com, rather than the name Scale Platform, on both the warning and the consent screen. The name (and the removal of these warnings) arrives with Google’s verification.

Either way, the admin approval below removes the friction for everyone in scope. We recommend it over the per-user route, see If you prefer not to approve centrally.

  1. Sign in to the Google Admin console as a super admin.

  2. Open API controls, or go to Menu → Security → Access and data control → API controls.

  3. Click Manage App Access, then Configure new app.

  4. Search by the Scale Platform OAuth client ID:

    223193156439-t64guqhka2u5tn8skt8hsb8prhr1p2np.apps.googleusercontent.com
  5. Select the app, choose the org units it applies to (you may pilot with one OU), click Continue, set access to Trusted, click Continue, then Finish.

  6. Done. Team members in scope can now connect their Google account in Scale Platform, under Profile → Connected accounts or from a project’s Files → Link files menu, and link files and folders. See Google Drive.

Reference: Google’s own documentation for this flow, Authorize unverified third-party apps and Control which third-party & internal apps access Google Workspace data.

  • Per user: the user disconnects Google Drive in Scale Platform under Profile → Connected accounts, or revokes the grant at myaccount.google.comThird-party apps & services, or you revoke it in Admin console → user → Security → Connected applications.
  • Whole domain: set the app’s access from Trusted back to Blocked under API controlsManage App Access. All access stops immediately; previously linked folders show as disconnected in Scale Platform.
  • Per folder: anyone on the project team can unlink a folder at any time.

When a team member first connects, Google shows a consent screen listing the read-only Drive scope and the authorizing account. Each user still consents individually. Approving the app centrally does not grant Scale Platform access to anyone’s Drive, and no data moves until a user connects and links something. What approval changes is that those users no longer meet Google’s unverified-app warning (or block).

The integration also works without the admin step, provided your API access-control settings don’t block third-party access to Drive. Each user who connects will:

  1. Reach Google’s “Google hasn’t verified this app” screen (“Back to safety”).
  2. Click Advanced, then Go to scale-company.com (unsafe).
  3. Continue to the consent screen, headed “scale-company.com wants access”, with an amber unverified-app notice, and grant read-only Drive access.

The wording is Google’s, and it is deliberately alarming: it means “not yet independently assessed”, not “known to be unsafe”. Everything in What Scale Platform does, and does not do still applies.

Two things to weigh before choosing this route:

  • Google caps unverified apps at 100 users in total, counted across all organizations and for the lifetime of the application. It cannot be reset. Users covered by an admin approval are not shown the warning and so do not consume that budget. Centrally approving keeps the capacity available.
  • Your users are asked to override a security warning. If your security policy discourages that, the admin route avoids putting them in that position at all.

Tell your users which route you have chosen, so nobody is surprised by an “unsafe” screen, or files a security ticket about one.

Questions this guide should answer, and a contact for the rest

Section titled “Questions this guide should answer, and a contact for the rest”

Security questionnaire, DPA, sub-processor list, ISO 27001 certificate, and the technical design of the no-copies reference architecture are available from our trust center trust.scale-company.com and via support@scale-company.com.