If your company runs on Google Workspace, you have already done much of the work a chat tool needs. Your people, teams, managers and offices are written down in one place, and someone keeps that record current.
The useful question about any chat tool is whether it reads that record and keeps up with it, or asks an admin to type everything in again and then slowly drifts out of date. This guide covers what to check. Most of it applies whichever tool you choose.
Sign-in that follows your domain
Sign in with Google is expected. The detail is what matters.
- Restrict it to your domains. Anyone with a Google account can sign in with Google. You want only accounts from your Workspace domains to get in. If you have more than one domain, after an acquisition or for a subsidiary, check that you can list several.
- Decide how outsiders join. Contractors and clients often won't have an account on your domain. A good tool lets you invite them deliberately, with a limited role, rather than loosening the domain rule for everyone.
Directory sync, and what it really syncs
"Works with Google" can mean anything from a one-off import of names to a proper scheduled sync. Ask which fields come across:
- people, with names and job titles
- departments
- managers, so the tool knows reporting lines
- locations
- Google Groups
Then ask how often it runs, and whether directory fields are locked in the chat tool. Locking sounds fussy. It keeps the directory the single source of truth, and stops someone changing their title to something creative.
When someone is suspended
The most important sync event is the one nobody plans for. When you suspend or delete someone in Google Workspace, what happens in chat?
The right answer is that their account is deactivated and their sessions are ended, so they are signed out everywhere, including the phone app. The wrong answer is that new sign-ins are blocked while an existing session carries on for weeks. Ask how long the gap is between the change in Google and the effect in chat, and whether "deactivated" includes "signed out".
Mentions that know your org chart
Once a chat tool knows who reports to whom, it can use that. Org-aware mentions let people address a relationship rather than a list of names:
@my-managerreaches your manager@my-teamreaches your direct reports@department:Financereaches everyone in Finance@location:Viennareaches everyone based in Vienna
The question to ask is when these are resolved. If they are worked out from directory data at the moment of sending, a mention follows people as they move teams, and nobody maintains anything. If they are static groups someone set up once, they will be wrong by next quarter.
Groups as handles
Your Google Groups already describe who is in support, who leads design, who is on call. A chat tool that turns those groups into @handles saves someone from keeping a second copy of every list. Ask whether membership follows the group when it changes in Google, and whether nested groups are handled.
Profiles with reporting lines
A profile that shows title, department, location, manager and direct reports answers the first question about an unfamiliar name: who is this, and who do they work with? New starters use it most. It is only as good as the directory behind it.
Calendar and Drive
Most Workspace companies want their chat tool to connect to Google Calendar and Google Drive. Ask:
- whether each person connects their own account, or an admin grants access for everyone
- what the connection actually does, in plain terms
- what the vendor stores, such as access tokens, and how it protects them
A narrow, personal connection is usually easier to justify to your security team than a broad, organisation-wide one.
Admin roles and an audit log
You want to separate who can change sign-in rules and billing from who can tidy up channels. Look for distinct roles, at least owner, admin, member and guest, and check what each can do.
You also want an audit log: who changed a setting, who removed whom, when the sign-in rules were edited. When something goes wrong, a record is more useful than a recollection.
A checklist for vendor calls
| Question to ask a vendor | Why it matters |
|---|---|
| Can sign-in be limited to our Workspace domains, and can we list more than one? | Stops personal accounts joining, and covers companies with several domains. |
| Which fields does directory sync bring across, and how often does it run? | Names alone are not enough for org-aware features, and a slow sync means stale data. |
| When we suspend someone in Google, are they deactivated and signed out, and how quickly? | This is the moment access control matters most. |
| Are directory-managed profile fields locked in the app? | Keeps the directory as the one source of truth. |
| Are org mentions resolved at send time from directory data? | Otherwise they are static lists that go out of date. |
| Do Google Groups become mentionable handles that follow group changes? | Avoids maintaining the same list in two places. |
| How do Calendar and Drive connections work, and what is stored? | Your security team will ask. |
| What roles exist, and is there an audit log of admin actions? | Separates duties and gives you a record when something goes wrong. |
| Which of these features are on which plan? | Directory features are often reserved for higher tiers. |
How Tandly does it
Briefly, and with the plan for each:
- Sign-in. Sign in with Google uses OpenID Connect with PKCE, and can be limited to your Google Workspace domains. E-mail sign-up is also available, for people outside your domain. Every plan.
- Directory sync. Users, titles, departments, managers, locations, and Google Groups as
@handles, synced on a schedule. Suspended or deleted people are deactivated and signed out. Directory-managed profile fields are locked in the app. This is on the Business plan. - Org-aware mentions.
@my-manager,@my-team,@my-peers,@department:Nameand@location:Name, resolved from directory data when the message is sent. Team plan and up. - Calendar and Drive. Personal connections to Google Calendar and Google Drive.
- Roles and audit. Owner, admin, member and guest roles, with guests on Team and up. An audit log on Business.
Full message history and search are included on every plan, Free included. The plan comparison lists what sits where, and the security overview covers the rest.
Questions people ask
Do we need directory sync if we are a small company?
Probably not at first. With a dozen people, domain-restricted sign-in covers most of what matters, and profiles are quick to fill in by hand. Sync starts to pay off when people join, leave and change teams often enough that nobody can keep up manually, or when you want org-aware features that depend on accurate reporting lines.
What happens to the messages of someone who has been deactivated?
In most chat tools, deactivating an account keeps that person's messages in place, so conversations still make sense afterwards. Check this with any vendor, along with who can still see their direct messages.
Can contractors without a Google account join?
Usually, yes, through e-mail sign-up or an invitation with a guest role. Keep the domain restriction for Google sign-in, and bring outsiders in deliberately with the narrowest role that works.
Are org-aware mentions just user groups with a different name?
No. A user group is a list someone maintains. An org-aware mention is worked out from the directory each time it is used, and it is relative to the person sending it: @my-manager means a different person for everyone. If you are also moving from another tool, the guide to moving your team's chat in an afternoon covers the practical steps.