Docs
Open app

integrations

Google Workspace

Sync users, groups, and app access from Google Workspace.

Connect Google Workspace when Doow needs users, groups, and login activity from your company directory.

What you need

  • A Google Workspace domain for your company.
  • A Google Workspace admin account that can approve the requested read scopes.
  • Permission to approve third-party app access in the Google Admin console if your organization restricts OAuth apps.

You do not need to create API credentials manually. Doow uses Google OAuth and asks an admin to approve read access.

Approve the app your organization expects

If Google Workspace app access controls are enabled, the Doow OAuth app may need to be trusted in the Google Admin console before the connection can read directory and audit data.

What Doow reads

FieldDescription
UsersFull name, primary work email, aliases where available, account status, and organizational unit
GroupsGroup names, email addresses, and membership where the approved scopes allow it
Login activityGoogle Workspace login audit events and timestamps where available
DomainThe Workspace domain used to scope imported records to your organization

What Doow does not read

  • Passwords or authentication secrets
  • Email content, calendar events, or Drive files
  • Personal (non-Workspace) Google accounts
  • Unrelated Google Cloud projects or resources
  • Data outside the approved directory, group, and audit scopes

How to connect

  1. Go to Company Settings, then Integrations in your Doow workspace.
  2. Find Google Workspace and select Connect.
  3. Sign in with the Google Workspace admin account that owns approval.
  4. Review the requested read scopes on Google's consent screen.
  5. Select Allow.
  6. Wait for Doow to verify the authorization and begin the initial sync.

The initial sync may take a few minutes depending on directory size. After that, Doow refreshes identity data on a scheduled basis.

Permissions requested

Doow requests Google OAuth scopes for the data it reads:

ScopePurpose
admin.directory.user.readonlyRead user profiles, aliases, and account status
admin.directory.group.readonlyRead groups and group metadata
admin.directory.group.member.readonlyRead group membership
admin.reports.audit.readonlyRead Workspace audit reports, including login activity

These are read-only scopes. Doow cannot create, modify, or delete data in your Google Workspace.

Confirm the sync worked

After connecting, open the integration detail page from Company Settings, then Integrations. A healthy Google Workspace sync shows a connected state, a recent sync timestamp, imported users, groups, and login activity where Google provides it.

If the connection succeeds but no users appear, verify that the admin account belongs to the intended Workspace domain and approved the required read scopes.

Troubleshooting

Use these checks when Google Workspace data is missing or incomplete:

  • Confirm the OAuth grant belongs to the intended Workspace domain.
  • Confirm the Google Admin console allows the Doow OAuth app to access the requested services.
  • Confirm the admin account can read users, groups, and audit reports.
  • Check the integration event log for permission or sync errors.

Google Workspace-specific checks

SymptomLikely causeNext action
OAuth completes but no users appearThe admin account cannot read directory users for the domainReconnect with a Workspace admin that can read the directory
Groups are missingThe approved scopes do not include group or group member read accessTrust the Doow app if required, then reconnect and approve the group scopes
Login activity is missingThe approved scopes do not include audit report access or Google has not produced matching audit rowsReconnect with the audit scope approved and check a broader date range
Wrong domain appearsThe OAuth flow used the wrong Google accountDisconnect and reconnect with the intended Workspace admin account

Disconnecting

Go to Company Settings, then Integrations, find Google Workspace, and select Disconnect. Doow deletes the stored authorization immediately. Remove or block the Doow OAuth app in Google Admin console app access controls when you want to remove provider-side access too.

Next steps

After Google Workspace users and groups appear, connect HRIS if Doow needs department, manager, or employment status. Connect a usage source when Doow needs to compare access against AI, cloud, or app usage.

Was this page helpful?