> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/documentation/management-console/integrations/google-workspace.md).

# Google Workspace

GuardWare can scan and monitor Gmail and Google Drive for sensitive data using a Google Cloud service account. A service account is a non-human Google account that represents an application rather than an individual user.

The service account uses domain-wide delegation to access Google Workspace data on behalf of users in the organisation. The Google Workspace super admin authorises the service account and specifies the OAuth scopes that GuardWare can use when accessing Google Workspace data.

This page explains how to create the Google Cloud service account, configure the required APIs and permissions, create a Security Group in Google Workspace Admin Console, authorise domain-wide delegation, and connect Google Workspace to GuardWare.

## Prerequisites

Before connecting Google Workspace to GuardWare, ensure the following are in place:

* A Google Cloud project with billing enabled
* A Google Workspace super admin account
* A Google Workspace admin account

## Set Up a Google Cloud Service Account

{% stepper %}
{% step %}

### Create a Google Cloud Project

1. Go to [**Google Cloud Console**](https://console.cloud.google.com) and sign in with an account that has sufficient Google Cloud permissions to create and manage a project.
2. Click the project dropdown at the top of the page and click **New Project**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FCdseoUoZm4To6Gm3qF6L%2Fimage.png?alt=media&amp;token=feaeee09-642c-4b68-bbe2-b4e2593dd3df" alt="" width="563"><figcaption></figcaption></figure></div>
3. Enter a project name and click **Create**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FWE05VNsWp0nNTZ4skkU3%2Fimage.png?alt=media&amp;token=7ed99cb6-f6dc-4441-995a-b49506a34f39" alt="" width="563"><figcaption></figcaption></figure></div>
4. After creating the project, select it from the project selection dropdown or click **Select Project** in the **Notifications** panel.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FeE8wT2ZGo7Y0Lh3O86XV%2Fimage.png?alt=media&amp;token=45f5f9aa-aff3-4735-ac5b-a94ed3bd4149" alt="" width="563"><figcaption></figcaption></figure></div>

{% endstep %}

{% step %}

### Enable Required APIs

Enable the Google APIs required for the GuardWare integration. These APIs provide the interfaces GuardWare uses to authenticate and interact with Google Workspace services.

1. In the [**Google Cloud Console**](https://console.cloud.google.com), click the <i class="fa-bars">:bars:</i> **menu** icon and go to **APIs & Services > Library**.
2. Search for the following APIs:

   <table><thead><tr><th width="177.888916015625">API</th><th>Function</th></tr></thead><tbody><tr><td><strong>Admin SDK API</strong></td><td>Used to retrieve Google Workspace directory information, including users, groups, and organisational units.</td></tr><tr><td><strong>Gmail API</strong></td><td>Used to access Gmail messages and attachments for scanning.</td></tr><tr><td><strong>Google Drive API</strong></td><td>Used to access files and folders stored in Google Drive for scanning, including supported shared-drive content.</td></tr></tbody></table>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FkMGhAbtiFZH06HSaqy4d%2Fimage.png?alt=media&amp;token=7a89815d-3e91-4d1c-95f0-a7f771e5dd46" alt="" width="563"><figcaption></figcaption></figure></div>
3. Click **Enable** to start all the API services in their respective pages. <br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FiWLR9jvB8N4wA611USY9%2Fimage.png?alt=media&amp;token=210054ca-cd63-461a-82cf-25f334a29c00" alt="" width="563"><figcaption></figcaption></figure></div>
4. Go to **APIs & Services > Enabled APIs & Services** and confirm that all three APIs are enabled.
   {% endstep %}

{% step %}

### Create a Service Account

The service account acts as the identity GuardWare uses to access Google's APIs. The roles assigned here allow it to read organisation-level information during a scan.

1. Click the <i class="fa-bars">:bars:</i> menu and go to **IAM & Admin** > **Service Accounts**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FOfaJ7OYXl75PzvmD22ej%2Fimage.png?alt=media&amp;token=46b23975-9d40-4610-8c82-a69288a93ff3" alt="" width="563"><figcaption></figcaption></figure></div>
2. Click **Create Service Account**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FM3QdENrZMOAOMkwQo1GU%2Fimage.png?alt=media&amp;token=18622468-1c61-4685-8e4c-a97b3e7eece2" alt="" width="563"><figcaption></figcaption></figure></div>
3. Enter a name and description for the service account and click **Create and Continue**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FkiqWHBRb0vfGawr10Ouw%2Fimage.png?alt=media&amp;token=b132f03f-a815-4896-84dc-dd9d26697a6a" alt="" width="563"><figcaption></figcaption></figure></div>
4. In the **Permissions (optional)** tab, click on the dropdown and assign the following roles to the service account. Click **+Add another role** each time to add additional roles.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FTAbwsvNwckOEQXiWfC36%2Fimage.png?alt=media&amp;token=0b305617-4da2-4bad-ad0a-f55a93eb1e8a" alt="" width="563"><figcaption></figcaption></figure></div>

   1. Organisation Administrator
   2. Organisation Policy Viewer
   3. Owner
5. Click **Continue**, leave the **Principals with access (optional)** field as is, then click **Done**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2F4zB4QcZeJft0JhANfUeA%2Fimage.png?alt=media&amp;token=3e30ca5b-904c-4413-b273-ed96a6d5363c" alt="" width="563"><figcaption></figcaption></figure></div>
6. On the **Service Accounts** page, click the service account you created.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2F3q1UjiymaWcc90t2EzKY%2Fimage.png?alt=media&amp;token=0d92d176-ae67-4d1f-a63e-5b18d12b3f43" alt="" width="563"><figcaption></figcaption></figure></div>
7. Search for the **Unique ID** shown in the details and store it in a secure location in your device. The Unique ID will be needed in the [**Authorise the service account in Google Workspace**](#authorise-the-service-account-in-google-workspace) section.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FveHBM34T0N0sATw6sYH5%2Fimage.png?alt=media&amp;token=15478feb-a5ea-4b97-ba62-d477b83f0b28" alt="" width="563"><figcaption></figcaption></figure></div>

{% endstep %}

{% step %}

### Generate a JSON key

The JSON key is the credential file GuardWare uses to authenticate as the service account. It contains a private key that signs API requests, so it **must be kept secure and not shared with anyone**.

1. In **IAM & Admin > Service Accounts**, click the service account you created.
2. Click the **Keys** tab.
3. Click **Add Key** and select **Create new key** from the dropdown.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2F60JCX2KhPQHCTNFNpfkW%2Fimage.png?alt=media&amp;token=8fea5875-2ea1-4ad0-ae7b-2a4db3695bdf" alt=""><figcaption></figcaption></figure></div>
4. Select **JSON**, click **Create,** and click **Close**. <br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2Fey0dYC9oiF0N1gkfouRf%2Fimage.png?alt=media&amp;token=f8db9f06-e2b6-446f-8a0b-6ab6b22f163b" alt="" width="494"><figcaption></figcaption></figure></div>

{% hint style="info" %}
The key file downloads automatically. Store the JSON key securely as you will need to upload it when configuring Google Workspace in GuardWare.
{% endhint %}
{% endstep %}
{% endstepper %}

## Configure Google Workspace

After completing the Google Cloud configuration, switch to [**Google Workspace Admin Console**](https://admin.google.com) to configure the Google Workspace components required by GuardWare.

{% stepper %}
{% step %}

### Create a Security Group

GuardWare uses a Google Workspace Security Group to define the users included in the Google Workspace integration.

1. Navigate to **Directory > Groups** in the admin console.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2F7QdZfDoaBRWDmHhE90jE%2Fimage.png?alt=media&amp;token=fdb33b8c-2795-4eac-a398-c44bb6345a68" alt="" width="563"><figcaption></figcaption></figure></div>
2. Click **Create group** and enter the following details:
   1. **Group Name** — Enter a name for the Security Group.
   2. **Group email** — Enter the email address for the group.
   3. **Description** — Enter a description that identifies the purpose of the group.
3. Add the group owner(s) and tick the **Security** box to add a label to the group.

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FSFv3hlvYRTZ9AZS8oNDm%2Fimage.png?alt=media&amp;token=7d3940a8-63fb-4e2d-8a95-19052c316c22" alt="" width="563"><figcaption></figcaption></figure></div>
4. Configure the group access settings as required by your organisation.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2F5IX1gcbNDZ4y2eglvV7L%2Fimage.png?alt=media&amp;token=9134778d-f7e2-4fe0-b1d4-80b8d0ef9c8d" alt="" width="563"><figcaption></figcaption></figure></div>
5. Click **Create group**.
   {% endstep %}

{% step %}

### Add Users to the Security Group

Add the users whose Gmail and Google Drive data should be included in the GuardWare integration.

1. In the **Google Workspace Admin Console**, go to **Directory > Groups**.
2. Select the Security Group you created and click **Add members**.

   <figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2Fwe6IwsgY50mALV5vyy2x%2Fimage.png?alt=media&amp;token=d4209fda-ca58-4436-bee8-2a5762f30a2f" alt=""><figcaption></figcaption></figure>
3. Enter the email addresses of the users to add to the group.
4. Select the users and click **Add to group**.

#### Verify Security Group Membership

1. Go to **Directory > Groups** and open the Security Group.
2. View the group members.
3. Confirm that all users whose data should be included in the GuardWare integration are listed.
   {% endstep %}

{% step %}

### Authorise the service account in Google Workspace

Domain-wide delegation grants the service account permission to impersonate users across the organisation. **A super admin must complete this step in the Google Workspace Admin Console.**

1. Go to [**Google Workspace Admin Console**](https://admin.google.com) with **a super admin account** and navigate to **Security** > **Access and data control** > **API controls**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FOfa45oH0nqISqNEfbC12%2Fimage.png?alt=media&amp;token=e3818a86-985e-4d5f-a93e-c50534254427" alt="" width="563"><figcaption></figcaption></figure></div>
2. Click **Manage Domain Wide Delegation**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FseALCRB8paY9euhn8xKT%2Fimage.png?alt=media&amp;token=12a48402-ec58-435e-9194-6a8847b57d84" alt="" width="563"><figcaption></figcaption></figure></div>
3. Click **Add new**.<br>

   <div align="left"><figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FgM0KUxRZ1Z9CxXmzatCn%2Fimage.png?alt=media&amp;token=137b236a-e67b-4338-a80a-9495a283a9dc" alt="" width="563"><figcaption></figcaption></figure></div>
4. Enter the service account's **Unique ID** in the **Client ID** field.
5. Enter the required OAuth scopes for Gmail and Google Drive as comma-separated values:
   1. `https://www.googleapis.com/auth/admin.directory.user.readonly`
   2. `https://www.googleapis.com/auth/admin.directory.group.readonly`
   3. &#x20;`https://www.googleapis.com/auth/admin.directory.group.member`
   4. &#x20;`https://www.googleapis.com/auth/admin.directory.group.member.readonly`
   5. `https://www.googleapis.com/auth/admin.directory.orgunit.readonly`
   6. `https://www.googleapis.com/auth/admin.reports.audit.readonly`
   7. `https://www.googleapis.com/auth/drive`
   8. `https://www.googleapis.com/auth/gmail.readonly`
   9. `https://www.googleapis.com/auth/gmail.modify`
   10. `https://mail.google.com/`
6. Click **Authorise**.

Changes to domain-wide delegation can take time to propagate across the organisation. If GuardWare cannot authenticate immediately after saving, wait and retry.
{% endstep %}
{% endstepper %}

## Connect Google Workspace to GuardWare

After setting up the Google Cloud Service Account, configure the following details in GuardWare Management Console:

1. Navigate to **ORGANISATION** > **Google Workspace.**
2. In **Admin Email,** enter the Google Workspace admin email address that was used to create the JSON Key.
3. Enter the **Security Group** email address.
4. Enable **Gmail Monitoring** for Gmail and **Google Drive Monitoring** for Google Driv&#x65;**.**
5. Upload the [**Google Service Account JSON**](#generate-a-json-key) credentials you generated while setting up the Google Cloud Service Account.
6. Click **Submit**.<br>

   <figure><img src="https://3428346635-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBUWYzeE1fa6LGkJgqgik%2Fuploads%2FVQ9ZAAxLV3WscikbPbJE%2Fimage.png?alt=media&amp;token=06487464-793f-4c8e-8bf4-415d4f067fd6" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/documentation/management-console/integrations/google-workspace.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
