Google Workspace
This is the first system an agent changes. Connecting your workspace lets an approved run add somebody to a group, remove them when the period ends, and lets you build the list of what people can ask for by picking real groups instead of typing identifiers. The only scope that changes anything is used after a decision has been made.
What we ask for, and why
- admin.directory.user.readonly
- Read the list of people in your Workspace, so a request can be for somebody by name and a grant lands on the right account.
- admin.directory.group.readonly
- Read your groups, so the catalog is built by picking from a list rather than typing identifiers.
- admin.directory.group.member
- Add somebody to a group when a request is approved, and remove them when access is revoked. This is the only permission that changes anything.
Nothing here reads mail, files or calendars. The product needs to know who works at your company, what groups exist, and how to add somebody to one.
What the administrator does
A Workspace super administrator opens the consent link. It can be forwarded, which matters when the person who signed up is not the person with the admin console.
Google may show an 'unverified app' screen while our verification review is in progress. The setup guide shows exactly what to click, and the review clears it.
They grant offline access, so the connection keeps working without somebody re-authorizing it every hour. The refresh token is encrypted before it is stored.
The consenting account's domain is checked against your organization's domain, so connecting the wrong Workspace by mistake is refused rather than syncing another company's directory into your catalog.
The first sync starts on its own and reports how many people and groups it found.
If you disconnect it
Syncing stops and approvals stop changing anything in your directory. Access somebody already has is left alone, because removing it because an integration was disconnected is not what the word promises. Requests carry on being approved and recorded.