Open API Controls
- Sign in to the Google Admin console.
- Open the main menu.
- Go to Security.
- Select Access and data control.
- Select API controls.
If Security is not visible, select Show more or use the Admin console search box to find API controls.
Google Workspace security guide
A practical, step-by-step guide for Australian businesses. Find, classify and restrict unnecessary or over-privileged app access to Gmail, Drive, calendars and contacts.

Recommended method: review, classify and restrict third-party app access every three months
Third-party applications may have ongoing access to Gmail, Google Drive, calendars, contacts and other organisational information. Apps that are no longer required—or have more access than necessary—should be restricted or blocked.
If Security is not visible, select Show more or use the Admin console search box to find API controls.
An application may take approximately 24–48 hours to appear after it is authorised.
Look for applications that are:
Do not block an app solely because its name is unfamiliar. Backup, email-security, CRM, accounting, migration and document-management services may legitimately require extensive access.
Pay particular attention to access allowing an app to:
High-risk Gmail scopes include access to read, modify, compose or send email. High-risk Drive scopes include access to all files, file metadata, documents or scripts.
Before changing access, establish:
Classify each application as:
| Classification | Meaning |
|---|---|
| Approved | Recognised and appropriately permissioned. |
| Restrict | Required, but should have access only to specified data. |
| Block | Obsolete, unauthorised, excessive or suspicious. |
| Investigate | Business purpose or ownership has not yet been confirmed. |
| Access level | Effect |
|---|---|
| Trusted | The app may request access to all Google Workspace services, including restricted services. |
| Limited | The app can access only Google services classified as unrestricted. |
| Specific Google data | The app can access only the OAuth scopes explicitly selected by the administrator. |
| Blocked | The app cannot access Google services or request Google Workspace data. |
Where available, Specific Google data is generally preferable to Trusted because it supports least-privilege access.
Blocking an app prevents users from signing in to it with their managed Google account and prevents it from requesting Google Workspace data. Changes can take up to 24 hours, although they usually apply sooner.
Google notes that access cannot be revoked for individual scopes on this particular Marketplace-app page—Revoke access revokes all access. Users may subsequently be prompted to authorise the app again unless API Controls or Marketplace installation restrictions also block it.
Treat unfamiliar domain-wide delegation as a potentially serious security concern.
When a service is changed to Restricted, previously installed apps that are not trusted or specifically allowed may stop working and their tokens may be revoked. Test this change carefully.
Choose one of the following:
Blocking all unconfigured apps is more secure but can create additional administrative work and interrupt apps that have not yet been documented.
These instructions provide general security guidance and may not account for your Google Workspace edition, organisational structure, third-party integrations, regulatory obligations or business requirements. Google may change Admin console menu names and options without notice.
Incorrectly blocking an application or changing API restrictions may interrupt critical services. Before making changes, document the existing configuration, identify affected users, confirm application dependencies and prepare a rollback plan. If an application’s purpose or permissions are unclear, engage a qualified Google Workspace security engineer rather than removing it without investigation.