FlowAudit
Revenue Recovery Desk
Google OAuth reviewer test path
Google OAuth verification

Reviewer test flow for Gmail read-only and Drive metadata read-only.

This page is for Google reviewers validating the Revenue Recovery Desk OAuth app. It explains the exact user flow, requested scopes, and post-consent app behavior without exposing internal Hermes, Supabase, terminal, or client systems.

Reviewer-safe web flow

How to test the Google Workspace OAuth flow

Use the one-time Google Workspace connect URL supplied in the Google verification response. That URL opens the same Connect Google Workspace screen used by business customers during secure setup.

  1. Open the reviewer-specific Google Workspace connect URL supplied by FlowAudit.
  2. Confirm the page says Connect Google Workspace for the reviewer account.
  3. Click Connect securely. The browser redirects to Google's OAuth consent screen.
  4. Review the requested read-only scopes and approve with a Google account suitable for review testing.
  5. Google redirects back to https://flowaudit.co.uk/revenue-recovery/oauth-callback.
  6. The app records the Google Workspace connection for the reviewer business profile and shows the connection as completed.
Important: the technical /oauth-start route requires a valid one-time token. If opened without the reviewer token, it correctly shows the link as unavailable.

Post-consent connected state

Google Workspace connected

Revenue Recovery Desk can now use read-only Gmail context and Drive metadata to support human-reviewed revenue recovery workflows. Outreach remains approval-gated and no Google data is modified by these scopes.

What reviewers do not need

Google reviewers do not need access to Hermes, the internal recovery agent runtime, Supabase, Orgo/cloud desktops, client secrets, API keys, or terminal sessions. The app-facing test surface is the FlowAudit web OAuth flow and connected-state behavior described above.

All real customer outreach produced by Revenue Recovery Desk remains human-reviewed and approval-gated before send.

Verification URLs

redirect_uri = https://flowaudit.co.uk/revenue-recovery/oauth-callback