Realsmart Help

← Realsmart Help

Shared Google domain trusts (trust-level authority)

Shared Google domain trusts (trust-level authority)

Some trusts run one Google domain for every school — so [email protected] is a single Google account, even though Sam is a separate record in School A, School B and School C.

The problem this solves

Sync runs per school. Each school compares Sam's real Google groups against its own groups and treats anything it doesn't recognise as stale:

  • School A removes the groups that belong to Schools B and C.
  • School B then removes A's and C's, and re-adds its own — and so on.

Each school is "correct" from its own view, but they're fighting over one shared account: Sam's groups (and Classroom memberships) are torn down and rebuilt every sync cycle.

What trust-level authority does

Turn on Shared Google domain (trust authority) in MAT sync settings and removal becomes a trust-wide decision:

  • Adding stays per school — each school still contributes its own memberships.
  • Removing requires trust-wide agreement — a group or Classroom membership is only removed when no school in the trust owns it (no live record of that person is in a matching, synced group at any school on the shared domain).
  • Genuinely stale memberships are still cleaned up — if no school owns a membership any more, it is removed as normal. The trust check doesn't stop cleanup; it stops schools removing each other's memberships.

The result is a stable end state: the person keeps the union of all their schools' memberships, and only trust-wide orphans are removed.

How to turn it on

  1. Switch to MAT overview (All schools) and open MAT sync settings.
  2. If your schools share a Google domain, a "Shared Google domain detected" notice shows which domain and how many schools.
  3. Select those schools, set Shared Google domain (trust authority) to Enable, and apply. Schools with it on show a Trust authority badge.

MAT sync settings showing the Shared Google domain detected banner and a Trust authority badge

Enable it for all the schools on the shared domain. A school without it can still remove the other schools' memberships.

Normal schools and trusts with separate domains per school are unaffected by this setting.

The account itself is protected too

Trust authority is about memberships. Separately — and with no setting to turn on — the sync will not let one school perform a destructive change to the account while another school still has that person as an active user. Renaming the address, suspending, the leaver purge that renames an account to …_purged_by_realsmart@ and strips its aliases, and outright deletion all check first whether a sibling school on the shared domain still uses the account. If one does, the action is skipped and recorded rather than carried out.

This matters most at the end of the year: a person who leaves School A but still teaches at School B has one Google account, and A's leaver processing must not close it. If the check can't establish who owns the account, the destructive action is refused rather than attempted — the safe direction for something that can't be undone.

The same is true on the Microsoft side, where several schools commonly share one Entra tenant.

How to see it working

  • Open User log trace (Users & Groups) for a shared user: a banner confirms one Google account across N schools and whether trust authority is protecting it.
  • Protected removals appear in the timeline and Logs as "Retained — owned by [school] (shared Google domain — trust-level authority)" — set the Outcome filter to All to include them.
  • The thrashing stops: you'll no longer see the same memberships removed and re-added every cycle.

Related

Was this helpful?