Chad's CASA Tier 2 Assessment Milestone for Google Integrations


In May 2026, Chad reached an important milestone in its Google integration work: TAC Security submitted the Letter of Validation for our CASA Tier 2 assessment to Google. The assessment work supports our approach to building customer-service integrations that handle business information with defined security requirements.

This article preserves that May milestone. The assessment, Google's app-verification decision and the rollout of a particular customer workflow are distinct steps. For current integration availability and the documentation relevant to your setup, contact the Chad team.

What the assessment means

CASA stands for Cloud Application Security Assessment. Google's security-assessment guidance describes its use in the review of applications requesting restricted scopes and the assessor's Letter of Validation. The letter is evidence within that process; it does not itself describe every feature a product has launched.

Our work with TAC Security included the assessment process and supporting evidence. By May 27, the team had confirmed that TAC had submitted the validation letter to Google. This is the milestone described here, rather than a claim that every Google Workspace connection became available to every store on that date.

Why the terminology matters

The original announcement used “Tier 2,” the terminology used for that assessment. The App Defense Alliance's current assurance-level guidance describes AL1 and AL2 and annual revalidation. Use the current guidance and the application's actual assessment documentation when evaluating a deployment, rather than treating an older tier comparison as a permanent product specification.

The requested API scopes and the specific application matter. Gmail, Google Sheets and Google Docs are different APIs with different operations and permissions. An assessment milestone should not be read as blanket authorization to read or change any Google Workspace data.

Start with the workflow your business needs

A useful integration discussion begins with the task, not a list of application logos. For example, a business may want help preparing replies to incoming inquiries, recording a lead or making approved information available to an agent. Each workflow needs a defined source, permitted action and owner.

For an email workflow, clarify whether the system drafts for review or sends under an approved process. For a spreadsheet workflow, define the destination and fields. For information used in answers, confirm how updates become available and what happens when the source cannot be read.

These are setup questions to work through with the team, not a promise that every example is enabled by default. Review Chad's integrations and tell us the business outcome you need so we can confirm the supported path.

Evaluate the operating details too

Before enabling an integration, agree on the account being connected, the permissions requested, the actions allowed and the route for exceptions. Test a representative case and verify the result in the destination system. Keep a person responsible for reviewing failures and changes to the workflow.

Our AI support and data privacy guide provides practical questions about access, retention and vendor responsibilities. The Monday.com walkthrough illustrates the separate steps of connecting an account, choosing its destination and checking the result.

Build on the milestone

The CASA work is part of the foundation for Chad's integration work. If your business needs a particular Google connection, bring the intended task and approval requirements to our team. We can discuss current availability, the relevant assessment information and the setup needed for that workflow, without relying on an old rollout forecast.