Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Next Generation API Data Protection Platform
    Bring Your Own Project (BYOP) for Google Apps

    Bring Your Own Project (BYOP) for Google Apps

    Google is introducing usage-based charges for Google Workspace API calls. To protect your Google Workspace scanning from any shared quota limitations and give you full control over your own API usage, Netskope is moving Next Generation API Data Protection for Google apps — Google Drive, Google Calendar, and Gmail — to a Bring Your Own Project (BYOP) model. Under this model, you create and own the Google Cloud Platform (GCP) project and service account used for your Google Workspace integration, instead of relying on a project and service account that Netskope owns and shares across customers.

    This page explains what’s changing, why, and where to go next. It does not contain setup steps — for those, see the links below.

    Existing customers must complete the required migration steps for their Google app instances well before September 30, 2026. After this date, instances still using Netskope’s shared service account may experience degraded performance due to Google-imposed rate limits.

    What’s changing and why?

    Starting in October 2026, Google will charge the owner of a Google Cloud project for Workspace API calls above a free-tier threshold. Until now, all Netskope customers have shared a single Netskope-owned GCP project and service account for these API calls, which means Google attributes all customer-driven API traffic to Netskope.

    Under BYOP, you create and own the GCP project and service account used for your Google Next Generation API Data Protection integration. This means:

    • Your API quota is dedicated to your organization. You are not affected by other Netskope customers’ usage.

    • If you need more quota, you can request it directly from Google for your own project.

    • You have full visibility into your own Google API usage and any associated costs.

    What do I need to do?

    The action required depends on your current Google app configuration in Netskope. Find your scenario below.

    Use this article to find the migration steps for your specific Google app configuration in Next Generation API Data Protection. This applies to Google Drive, Google Calendar, and Gmail. Find the scenario that matches your current setup below.

    Complete the required steps for your scenario well before September 30, 2026. After this date, Google app instances still using Netskope’s shared GCP project may experience degraded performance due to Google-imposed rate limits.
    Your current setupRequired action
    Classic API Data Protection only.Upgrade to Next Generation API Data Protection and complete BYOP onboarding.
    Next Generation API Data Protection (instance created before BYOP).Switch your existing instance to your own GCP project.
    Both Classic and Next Generation API Data Protection instance created before BYOP).Complete both of the actions above.
    New customer onboarding on Next Generation API Data Protection.No migration needed. Follow the standard BYOP setup during onboarding.

    Classic API Data Protection only

    Classic API Data Protection does not support BYOP. To keep your Google Workspace protection uninterrupted, upgrade to Next Generation API Data Protection using the new BYOP onboarding flow.

    1. Create your GCP project and service account.

    2. Grant your service account the required domain-wide delegation scopes.

    3. Add a new Next Generation API Data Protection instance for your Google app using your own service account.

    4. Confirm the new Next Generation instance is active and scanning as expected.

    5. Recreate your Classic policies in the Next Generation interface. Classic policies do not migrate automatically.

    6. Remove the Classic API Data Protection instance for the Google app.

    Next Generation API Data Protection only (instance created pre-BYOP)

    Your existing Next Generation instance created before BYOP release 140.0.0 currently uses Netskope’s shared service account. Switch it to your own service account to keep it in Next Generation API Data Protection. This preserves your existing policies and configuration.

    1. Create your GCP project and service account.

    2. Grant your service account the required domain-wide delegation scopes.

    3. In the Netskope tenant UI, go to Settings > Configure App Access > Next Gen > CASB API, locate your existing instance, and click Edit.

    4. Override the prefilled Service Account Email and Service Account Private Key fields (and Project ID for Gmail) with your own service account’s values, then save/grant again.

    5. Confirm the switch completed successfully and your policies are unchanged.

    Classic and Next Gen API Data Protection (pre-BYOP)

    1. Create your GCP project and service account. You can reuse the same project across apps, as long as required APIs are enabled for each.

    2. Upgrade your Classic instance to Next Generation using the BYOP onboarding flow (see above).

    3. Recreate your Classic policies, confirm the new instance is active, then remove the Classic instance.

    4. Switch your existing Next Generation instance using Edit (see above).

    New Customer Onboarding on Next Generation API Data Protection

    No special migration action is needed. Follow the steps in the configure article for your Google app.

    New Onboarding Documentation

    You can find the new onboarding steps documented here:

    • Gmail

    • Google Calendar

    • Google Drive

    Frequently asked questions

    Does switching to BYOP affect my existing policies?

    No. Switching an existing Google app instance to your own GCP project only updates the underlying service account credentials. All your existing policies, rules, and configurations are preserved.

    What happens if I do not complete the required action by the deadline?

    If your Google app instance still uses Netskope’s shared service account after the deadline, you may experience degraded Next Generation API Data Protection performance due to Google-imposed rate limits. Netskope cannot guarantee API performance for instances that have not migrated.

    Will I be charged for Google API usage?

    Google has announced usage-based pricing for Workspace API calls above a free-tier threshold. Any charges are billed to your own GCP project. Most organizations’ usage is expected to remain within the free tier. You can monitor your API usage in the GCP console under APIs & Services > Dashboard.

    Does Next Generation API Data Protection have feature parity with Classic API Data Protection for Google apps?

    Yes, for Google Workspace protection. However, you configure your policies in the Next Generation interface — your Classic policies do not automatically migrate. Contact your Netskope sales representative or support for help with policy migration.

    Can I use one GCP project for multiple Google app instances?

    Yes. You can create a single GCP project and use separate service accounts (or the same one, where scopes allow) across your Google Drive, Google Calendar, and Gmail instances, as long as you enable the required APIs for each in that project.

    What if I have multiple Google Workspace domains connected to Netskope?

    Each Google app instance in Netskope that you regrant will need domain-wide delegation authorized in the corresponding Google Workspace admin console. You can use the same GCP project and service account for all instances.

    Where can I get help?

    Contact Netskope support at support.netskope.com or reach out to your Netskope sales representative for a guided migration session.

    In this Topic
    • Bring Your Own Project (BYOP) for Google Apps