Workspace Migrator

Enter the access token printed when the server started.

Workspace Migrator Google → Google

Tenants, step by step

each company moves on its own; the button runs its next step
Source tenantUsersProgressNext step

Everything, by state

View as table

Progress by data type

View as table

Progress by domain

Automatic batches

large accounts start first; the tool paces itself to Google's quotas

Speed: items per minute

Data rate: MB per minute

Time to finish

Add a tenant

Add one destination and every source tenant you are merging into it.

The key is encrypted at rest and never shown again. Delete the downloaded file afterwards.

Allow API access (once per tenant)

  1. Google Cloud console: enable Admin SDK, Gmail, Google Drive, Google Calendar, People, Google Tasks, Groups Settings, Enterprise License Manager and Cloud Identity APIs.
  2. Create a service account, download its JSON key.
  3. That tenant's Admin console → Security → Access and data control → API controls → Domain-wide delegation: add the client ID (shown on the tenant card) with these scopes:
Source tenants
Destination tenant

Optional scopes (group settings, licences, policy report) can be left out; their checks show amber.

Tenants

Address rewriting

Used for sharing, attendees and group members that point at other migrated people. Filled in on verification.

Source domainRewrite to

Reset

Nothing in any Google tenant is changed by a reset. Your sign-in token, 2FA and the audit trail always stay.

Bring all domains into the destination

  1. Migrate first. While a domain still lives in its source tenant, its users land on a temporary address (for example john.acme@newco.com). People keep working in the source meanwhile.
  2. Move the domain. Google allows a domain in one tenant only: remove it from the source tenant (Admin console → Account → Domains), then click Add to destination and verify it with the DNS TXT record Google shows.
  3. Delta sync (Migrate tab → Δ Delta sync): only mail, files, events, contacts and tasks created or changed since the last run move; edited files are refreshed.
  4. Cut over. Every account and group is renamed to its original address; the temporary address stays as an alias.

Domains

DomainSource tenantIn destination UsersOn original address
Loading…
Export CSV

SourceBatchDestination account (type or pick)Destination OU

Destination accounts

Accounts that already exist in the destination tenant. Pick one in a user's row to merge into it.
AccountNameOUReceives data from
Verify the destination tenant to load its accounts.

What to migrate

Policy report and cut-over run only when ticked. Cut-over renames accounts, so run it last.

Scope

Options

Check readiness before starting.

Job

Speed (items per minute)

updates every 10 seconds
TenantSourceDataStatusProgress FoundMigratedAlready thereFailedDataSpeed

Live log

Export CSV

Export CSV

TenantSourceDestinationDataStatus CompleteFoundMigratedAlready there FailedRemainingData
Export CSV

WhenScopeKindSource id Destination idStatusError

Every failure with its reason. Retrying re-runs only these users; successful items are never moved twice.

WhenUser / scopeKindItemReason

Google's Policy API can read Admin-console settings but can write almost none of them, so settings are compared, not copied. Tick Policy report on the Migrate tab to refresh the snapshot.

TenantSource OUDestination OUSetting StatusSource valueDestination value
#StartedStatusData MigratedFailedData moved

Security checks

    Protection layers

    1. Loopback-only by default; optional IP allowlist; Host allowlist blocks DNS rebinding.
    2. Access token stored as a scrypt hash; optional TOTP second factor; lockout after 5 failures.
    3. Server-side sessions bound to this browser, 30-minute idle timeout, HttpOnly + SameSite=Strict cookies.
    4. CSRF token and Origin check on every change; strict Content-Security-Policy; no framing.
    5. Service-account keys, temporary passwords and the 2FA secret encrypted at rest (AES + HMAC).
    6. Drive files spool through AES-256 encrypted, anonymous temp files; nothing readable stays on disk.
    7. All Google traffic is TLS; source access is read-only except a temporary Drive share that is removed at once.
    8. Tokens and keys are scrubbed from logs; every admin action goes into a hash-chained audit trail.

    Audit trail

    WhenWhoActionDetail

    Confirm it's you

    Needed for actions that delete, reset or rename. Valid for 5 minutes.