ExpenseBot

How do I install ExpenseBot for my whole Google Workspace organization?

Short answer: In the Google Admin console, go to Menu → Apps → Google Workspace Marketplace apps → Apps list, click Install app, search for ExpenseBot, choose Admin install, review the data access, and install it for Everyone at your organization (or a specific organizational unit / group). The admin install makes the app available under the scope you choose;…

Short answer: In the Google Admin console, go to Menu → Apps → Google Workspace Marketplace apps → Apps list, click Install app, search for ExpenseBot, choose Admin install, review the data access, and install it for Everyone at your organization (or a specific organizational unit / group). The admin install makes the app available under the scope you choose; users still sign in to connect their own ExpenseBot account. Changes can take up to 24 hours to propagate.

You can also start from the ExpenseBot Google Workspace Marketplace listing and choose Admin install there.

Step-by-step: install for everyone

  1. Sign in to the Google Admin console as a super admin.
  2. Go to Menu → Apps → Google Workspace Marketplace apps → Apps list.
  3. Click Install app and search for ExpenseBot.
  4. Select ExpenseBot, click Admin install, then Continue.
  5. Review the data access the app requests and the developer's policies.
  6. Choose Everyone at your organization (or Certain groups or organizational units to scope it — see the pilot pattern below).
  7. Click Finish.

Menu labels above are Google's current wording; Google occasionally renames these screens, so if a label differs, look for the nearest equivalent under Apps → Google Workspace Marketplace apps.

Allowlisting if your org restricts third-party apps

If your organization blocks third-party apps by default (a common security posture), admin-installing ExpenseBot isn't enough on its own — you also mark it Trusted so its OAuth scopes are allowed:

  1. Go to Menu → Security → Access and data control → API controls.
  2. Click Manage App Access (Manage Third-Party App Access).
  3. Under Configured apps, click Configure new app.
  4. Search for and select ExpenseBot.
  5. Set the access level to Trusted and complete the configuration.

API controls override the Marketplace allowlist, so setting ExpenseBot to Trusted here is what lets it access the Google services it needs when your org restricts unconfigured apps.

What scopes it asks for, and why

ExpenseBot requests the narrowest scopes that do the job:

  • Gmail read-only — to find receipt-like messages (vendor names, totals, attachments) so it can capture receipts and income notifications. It doesn't scan your inbox broadly.
  • Gmail modify (labels only) — used only to apply ExpenseBot's own "Processed" / "Receipt" labels so the same message isn't processed twice.
  • Drive / Sheets file access (drive.file) — ExpenseBot can access files it creates and files a user explicitly selects for the app. It cannot enumerate the user's entire Drive.

ExpenseBot has completed a CASA Tier 2 independent, OWASP-based application security assessment through an authorized assessment lab. Tier 2 is lab validated; it is not Google's highest CASA tier.

Roll out to a pilot OU first (recommended)

For a low-risk deployment, install to a small organizational unit or group first (step 6 → Certain groups or organizational units), let that pilot group connect their Gmail and run a scan for a week, then widen the install to Everyone at your organization once you're comfortable. This is the pattern most admins use for new Marketplace tools.

Common admin questions

Can I install it for just one department? Yes. At the install step choose Certain groups or organizational units and select the OU or group instead of Everyone.

Do users have to grant access individually after a domain install? The admin install makes ExpenseBot available for the selected organization, groups, or units and can pre-approve its OAuth access under your policy. Each user still signs in to connect their own ExpenseBot account. The exact consent screen a user sees depends on the organization's Google configuration.

Where does the data live? Durable receipt files, spreadsheets, and reports are written to each user's Google Drive. ExpenseBot services also process receipt, email, and account data and retain operational records as described in the privacy policy. The drive.file scope is limited to files ExpenseBot creates or files the user explicitly selects; it does not provide full-Drive access.

Related

Share:

Try ExpenseBot Free

AI extracts every receipt into a Google Sheet you own. Gmail scan, mileage, tax reports, profit-by-client. No credit card needed.

No credit card required · Setup in 30 seconds