Google Workspace
Sync users, groups, and app access from Google Workspace.
Connect Google Workspace when Doow needs users, groups, and login activity from your company directory.
What you need
- A Google Workspace domain for your company.
- A Google Workspace admin account that can approve the requested read scopes.
- Permission to approve third-party app access in the Google Admin console if your organization restricts OAuth apps.
You do not need to create API credentials manually. Doow uses Google OAuth and asks an admin to approve read access.
Approve the app your organization expects
If Google Workspace app access controls are enabled, the Doow OAuth app may need to be trusted in the Google Admin console before the connection can read directory and audit data.
What Doow reads
| Field | Description |
|---|---|
| Users | Full name, primary work email, aliases where available, account status, and organizational unit |
| Groups | Group names, email addresses, and membership where the approved scopes allow it |
| Login activity | Google Workspace login audit events and timestamps where available |
| Domain | The Workspace domain used to scope imported records to your organization |
What Doow does not read
- Passwords or authentication secrets
- Email content, calendar events, or Drive files
- Personal (non-Workspace) Google accounts
- Unrelated Google Cloud projects or resources
- Data outside the approved directory, group, and audit scopes
How to connect
- Go to Company Settings, then Integrations in your Doow workspace.
- Find Google Workspace and select Connect.
- Sign in with the Google Workspace admin account that owns approval.
- Review the requested read scopes on Google's consent screen.
- Select Allow.
- Wait for Doow to verify the authorization and begin the initial sync.
The initial sync may take a few minutes depending on directory size. After that, Doow refreshes identity data on a scheduled basis.
Permissions requested
Doow requests Google OAuth scopes for the data it reads:
| Scope | Purpose |
|---|---|
admin.directory.user.readonly | Read user profiles, aliases, and account status |
admin.directory.group.readonly | Read groups and group metadata |
admin.directory.group.member.readonly | Read group membership |
admin.reports.audit.readonly | Read Workspace audit reports, including login activity |
These are read-only scopes. Doow cannot create, modify, or delete data in your Google Workspace.
Confirm the sync worked
After connecting, open the integration detail page from Company Settings, then Integrations. A healthy Google Workspace sync shows a connected state, a recent sync timestamp, imported users, groups, and login activity where Google provides it.
If the connection succeeds but no users appear, verify that the admin account belongs to the intended Workspace domain and approved the required read scopes.
Troubleshooting
Use these checks when Google Workspace data is missing or incomplete:
- Confirm the OAuth grant belongs to the intended Workspace domain.
- Confirm the Google Admin console allows the Doow OAuth app to access the requested services.
- Confirm the admin account can read users, groups, and audit reports.
- Check the integration event log for permission or sync errors.
Google Workspace-specific checks
| Symptom | Likely cause | Next action |
|---|---|---|
| OAuth completes but no users appear | The admin account cannot read directory users for the domain | Reconnect with a Workspace admin that can read the directory |
| Groups are missing | The approved scopes do not include group or group member read access | Trust the Doow app if required, then reconnect and approve the group scopes |
| Login activity is missing | The approved scopes do not include audit report access or Google has not produced matching audit rows | Reconnect with the audit scope approved and check a broader date range |
| Wrong domain appears | The OAuth flow used the wrong Google account | Disconnect and reconnect with the intended Workspace admin account |
Disconnecting
Go to Company Settings, then Integrations, find Google Workspace, and select Disconnect. Doow deletes the stored authorization immediately. Remove or block the Doow OAuth app in Google Admin console app access controls when you want to remove provider-side access too.
Next steps
After Google Workspace users and groups appear, connect HRIS if Doow needs department, manager, or employment status. Connect a usage source when Doow needs to compare access against AI, cloud, or app usage.