Tenants, step by step
each company moves on its own; the button runs its next step| Source tenant | Users | Progress | Next step |
|---|
Everything, by state
View as tableProgress by data type
View as tableProgress by domain
Automatic batches
large accounts start first; the tool paces itself to Google's quotasSpeed: items per minute
Data rate: MB per minute
Time to finish
Add a tenant
Add one destination and every source tenant you are merging into it.
Allow API access (once per tenant)
- Google Cloud console: enable Admin SDK, Gmail, Google Drive, Google Calendar, People, Google Tasks, Groups Settings, Enterprise License Manager and Cloud Identity APIs.
- Create a service account, download its JSON key.
- That tenant's Admin console → Security → Access and data control → API controls → Domain-wide delegation: add the client ID (shown on the tenant card) with these scopes:
Optional scopes (group settings, licences, policy report) can be left out; their checks show amber.
Tenants
Address rewriting
Used for sharing, attendees and group members that point at other migrated people. Filled in on verification.
| Source domain | Rewrite to |
|---|
Reset
Nothing in any Google tenant is changed by a reset. Your sign-in token, 2FA and the audit trail always stay.
Bring all domains into the destination
- Migrate first. While a domain still lives in its source tenant, its users land on a temporary address
(for example
john.acme@newco.com). People keep working in the source meanwhile. - Move the domain. Google allows a domain in one tenant only: remove it from the source tenant (Admin console → Account → Domains), then click Add to destination and verify it with the DNS TXT record Google shows.
- Delta sync (Migrate tab → Δ Delta sync): only mail, files, events, contacts and tasks created or changed since the last run move; edited files are refreshed.
- Cut over. Every account and group is renamed to its original address; the temporary address stays as an alias.
Domains
| Domain | Source tenant | In destination | Users | On original address | |
|---|---|---|---|---|---|
| Loading… | |||||
| Source | Batch | Destination account (type or pick) | Destination OU |
|---|
Destination accounts
Accounts that already exist in the destination tenant. Pick one in a user's row to merge into it.| Account | Name | OU | Receives data from |
|---|---|---|---|
| Verify the destination tenant to load its accounts. | |||
What to migrate
Policy report and cut-over run only when ticked. Cut-over renames accounts, so run it last.
Scope
Options
Job
Speed (items per minute)
updates every 10 seconds| Tenant | Source | Data | Status | Progress | Found | Migrated | Already there | Failed | Data | Speed |
|---|
Live log
| Tenant | Source | Destination | Data | Status | Complete | Found | Migrated | Already there | Failed | Remaining | Data |
|---|
| When | Scope | Kind | Source id | Destination id | Status | Error |
|---|
Every failure with its reason. Retrying re-runs only these users; successful items are never moved twice.
| When | User / scope | Kind | Item | Reason |
|---|
Google's Policy API can read Admin-console settings but can write almost none of them, so settings are compared, not copied. Tick Policy report on the Migrate tab to refresh the snapshot.
| Tenant | Source OU | Destination OU | Setting | Status | Source value | Destination value |
|---|
| # | Started | Status | Data | Migrated | Failed | Data moved |
|---|
Security checks
Protection layers
- Loopback-only by default; optional IP allowlist; Host allowlist blocks DNS rebinding.
- Access token stored as a scrypt hash; optional TOTP second factor; lockout after 5 failures.
- Server-side sessions bound to this browser, 30-minute idle timeout, HttpOnly + SameSite=Strict cookies.
- CSRF token and Origin check on every change; strict Content-Security-Policy; no framing.
- Service-account keys, temporary passwords and the 2FA secret encrypted at rest (AES + HMAC).
- Drive files spool through AES-256 encrypted, anonymous temp files; nothing readable stays on disk.
- All Google traffic is TLS; source access is read-only except a temporary Drive share that is removed at once.
- Tokens and keys are scrubbed from logs; every admin action goes into a hash-chained audit trail.
Audit trail
| When | Who | Action | Detail |
|---|