This guide is for the official SheetOps add-on. Install it to manage Google Workspace at spreadsheet speed.
Managed service providers, Google Workspace resellers, and IT consultants rarely administer a single domain. They juggle client organizations — each with its own users, organizational units, device fleet, and license inventory — while the Google Admin Console only ever shows one domain at a time.
Multi-tenant management in SheetOps changes that. By connecting a single Partner Service Account with domain-wide delegation (DWD), you register each client Google Workspace domain once and then export, create, update, or delete directory records across all of them from one spreadsheet — with the same visual change tracking you already use on your own domain.
Multi-tenant management is optional. Your own organization keeps working exactly as before through the native Admin Directory and License Manager APIs.
Every client you manage is a separate Google Workspace tenant with its own directory, devices, and billing. By default, SheetOps operates on the domain of the administrator running the add-on. With multi-tenant settings enabled, SheetOps can also act on your registered client domains.
Once configured, every entity workflow works across client domains:
OWNER, MANAGER, MEMBER).A single sheet can even contain rows belonging to different client domains. SheetOps resolves the target domain for every row when you tick Apply Changes and routes each operation to the correct tenant.
SheetOps multi-tenant mode is built on one Partner Service Account that you create in your own Google Cloud project:
The five scopes you authorize in each client domain:
https://www.googleapis.com/auth/admin.directory.userhttps://www.googleapis.com/auth/admin.directory.grouphttps://www.googleapis.com/auth/admin.directory.orgunithttps://www.googleapis.com/auth/admin.directory.device.chromeoshttps://www.googleapis.com/auth/apps.licensingOnly a super administrator of the client domain can authorize domain-wide delegation. Keep your Service Account JSON key private — the OAuth2 Client ID, on the other hand, is designed to be shared with clients. Learn more in Google's domain-wide delegation guide and the service account documentation.
You can manage your own organization and client tenants side by side. Your domain always appears in every export dialog as Current Organization, and client domains appear below it.
Ask each client's super administrator to complete this one-time step:
This authorization is per domain. If it is ever removed, exports and applied changes for that client stop until the Client ID is authorized again.
[email protected]), and optional notes.Use Edit and Delete on any row to maintain your client list. Removing a tenant stops access to that domain until it is added back.
If the test reports "Domain-Wide Delegation not authorized for Client ID", ask the super admin to re-check the Client ID and scopes in the delegation list. An API authorization check failed (403) message usually means the impersonated account does not have admin privileges in that domain.
<Client name> (<domain>), with your own domain listed as Current Organization.Because a spreadsheet can hold multiple domains at once, SheetOps resolves the target domain for every row:
primaryEmail.email.groupEmail.userId).Domain column.When a Partner Service Account is configured, SheetOps automatically adds a Domain column to Org Units and Chrome OS device sheets — including sheets that already exist, which are updated without losing unapplied edits. New items you create with an empty Domain cell go to your own organization; set the cell to a client domain to create the item there. Bulk device operations, such as OU moves and status changes, are automatically grouped per domain before they are executed.
| Capability | Google Admin Console | GAM (CLI) | SheetOps Multi-Tenant |
|---|---|---|---|
| Client onboarding | Log in to each domain's console separately | Per-domain service account setup in config files | Authorize one shared Client ID per domain |
| Interface | A browser session per domain | Terminal with per-domain scripts | A single Google Sheet |
| Cross-domain work | Not available — one domain at a time | Separate command runs per domain | One sheet with per-row domain routing |
| Change review | Click-through confirmations | Command output logs | Visual diffs with Apply Changes checkboxes |
Yes. Add each client domain in Multi-Tenant Settings, and every SheetOps dialog gains an Organization Domain selector so you can export and manage users, groups, members, OUs, devices, and licenses for any registered client — without signing out or switching browser profiles.
Domain-wide delegation lets a Google Cloud service account impersonate users in a Workspace domain, with access limited to the OAuth scopes a super admin authorizes. SheetOps uses it so that one approved service account can call the Admin Directory API for each client domain — no shared admin passwords, no per-user consent prompts. Google documents the mechanism in Control API access with domain-wide delegation.
Not for day-to-day work. After the client's super admin authorizes your Client ID once, SheetOps impersonates the admin email you configured for that tenant. The client's super admin is only needed for that initial authorization — and to revoke it if you stop managing the domain.
Yes. Users, groups, members, and license rows carry their domain in the identifier email; org units and Chrome OS devices use the Domain column. When you apply changes, SheetOps routes each row to its own domain, so a single batch can span several clients.
Usually the client domain does not yet have your Client ID authorized, or the scopes were saved incorrectly. Ask the super admin to open Manage Domain Wide Delegation and compare the entry with the Client ID and scopes copied from SheetOps. If the test instead reports API authorization check failed (403), the impersonated account likely lacks admin privileges in that domain.
Multi-tenant access is disabled until a service account is configured again — client exports and applied changes stop, while native single-domain operations continue normally. Your existing sheets and their data are untouched.
No. SheetOps runs inside Google Apps Script: access tokens and directory data flow directly between the spreadsheet and Google's official APIs. No client directory data is stored or proxied on third-party servers, and the Service Account key stays in your own Google account.
Last updated: September 29, 2026

Install SheetOps from the Google Workspace Marketplace today and start performing bulk directory updates, onboarding, and audits directly inside Google Sheets.