Google Workspace is Google's cloud identity management system and office productivity suite. This connector queries the Google Workspace admin API to produce indicators (numerical values tracked over time on a perimeter) about your users and groups.
This article is for Tenacy Admins in charge of configuring connectors, as well as the person with the necessary admin rights on the Google Workspace console to perform the domain delegation.
This connector collects the following information:
Built-in metrics (always active): active users, dormant accounts, admin accounts.
Configurable metric: users in a group, set up by specifying the Google Workspace group to track.
Add and configure the connector
To add this connector, go to Catalog > Connectors > Google Workspace > Add connector.
After adding it, you must configure:
Operating perimeter: the perimeter that operates and prescribes identity management rules. Indicators will be attached here by default.
Frequency: how often the Google Workspace API is queried and indicators are updated (daily, weekly, monthly, half-yearly, or yearly).
⚠️ For this connector to work, domain-wide delegation must be granted to the Tenacy application from the Google Workspace admin console. Without this step, the connector won't be able to query your Workspace.
Domain-wide delegation authorizes a third-party application, here Tenacy, to access certain resources in your Google Workspace without requesting individual consent from each user. To grant it:
Sign in to the Google admin console, Domain-wide delegation section, using an account with the privileges required to perform a delegation.
Add a new API client with the following Client ID: 112499870299322945714.
Enter the following OAuth scopes:
Authorize the API client.
💡 Only an account with the necessary admin privileges on the Google Workspace console can grant this delegation.
To enable the configurable Users in a group metric, specify the Google Workspace group(s) you want to track in the connector configuration.
Run your first test
Once the connector is properly configured and domain-wide delegation has been granted, test the integration by running an initial execution.
Go to ⚙️ > Connectors > click on the Google Workspace connector > Run now:
💡 Feel free to contact Tenacy support if you have any questions regarding this.
Expected result
Once the test runs successfully, the connector automatically queries the Google Workspace API according to the chosen frequency. The Active users, Dormant accounts, and Admin accounts indicators start updating, along with the Users in a group indicator if you've configured that metric.
FAQ
What happens if I don't have the necessary rights to grant domain-wide delegation?
You'll need to have this step performed by an account with adequate admin privileges on your Google Workspace console. Without delegation granted, the connector can't query any data.
What happens if one of the OAuth scopes isn't entered?
The connector won't be able to retrieve the corresponding data. For example, without the group.member.readonly scope, the Users in a group metric can't be calculated.
Can I track several groups with the Users in a group metric?
Yes, you can configure this metric for one or several Google Workspace groups depending on your tracking needs.
What happens if domain-wide delegation is revoked after the connector is configured?
The connector can no longer query the Google Workspace API: indicators stop updating until delegation is granted again.



