Earlier quoted context omitted.
I took that to mean use both identity management as well as OAuth.
1. Why use OAuth unless you want to grant 3rd parties access to your services data, on behalf of your customers? 2. Security best practices subject to "open for interpretation."
Can you explain me this? How Google will be able to access my service data?