Capabilities
Structure Sync
AccessOwl periodically syncs the permissions schema of an application.
User Sync
AccessOwl periodically syncs a list of users along with their assigned permissions.
Provisioning
AccessOwl creates or removes user accounts with the specified permissions during access requests or revocations.
Directory Sync
AccessOwl syncs (creates, removes, or deactivates) users from directories like Slack, Microsoft365, Okta, or Google into the AccessOwl users database.
Required Google Workspace OAuth Permissions
AccessOwl integrates with your Google Workspace organization in order to automate user provisioning, de-provisioning and Shadow IT detection. In order to do so AccessOwl requires customers to confirm the following OAuth permissions. The Google account that grants these permissions must be a super admin at the moment of granting, because Google itself requires a super admin for some of the scopes below. Each scope below is shown without its commonhttps://www.googleapis.com/auth/ prefix.
Provisioning and de-provisioning users, reading manager information (if available), and assigning the correct set of permissions, licenses, and groups:
Detecting Shadow IT:
User & Group Management
Put a user in the right organizational unit (OU) by using the resource “Assigned Organizational Unit” during an onboarding. You can give a user more roles in other OUs by selecting other resources. Furthermore, groups can be assigned including their role of Member, Manager or Owner.When AccessOwl adds a user to a Google group, that member’s email delivery preference is set to All email by default. This applies to every group and cannot be configured per group or overridden today.
AccessOwl assigns from the licenses you already own and cannot purchase new ones. If no license of the chosen tier is available, buy the seat in the Google Admin console first. AccessOwl then detects it and assigns it automatically.
Application Discovery (Shadow IT Detection)
We analyze usage data in Google Workspace to analyze which applications are used in your organizations. The permissions are granted by an Google Workspace admin on AccessOwl setup. When new applications are used in your organization, Org Admins are notified. You can either approve or ignore these discovered applications before they become available for user requests.User Access Discovery
Based on emails, we can discover which user uses which application. We only use readonly scopes. We don’t read or download your email. Instead we query specifically for vendor emails. For more security related information, check our Security page.Integration Account Setup
The integration account is automatically created in your Google Workspace. To proceed, the following prerequisites must be met:- A Google Workspace license that includes Gmail, any tier, because the integration account has to receive the invitation and verification emails. Cloud Identity licenses, Free or Premium, do not include Gmail and are not sufficient. The integration account therefore occupies one paid Google Workspace seat.
- 2-Step Verification need to be enabled in Google Workspace
- The user must be able to set up 2-Step Verification without admin intervention
Disconnecting and Reconnecting
In some cases you need to fully disconnect Google Workspace and connect it again, for example when the OAuth scopes configured for your organization change and AccessOwl needs to request the new set. A full disconnect means revoking AccessOwl’s OAuth grant in Google. Either of these two options works:- In the Google Admin console: Go to Directory > Users and open the user who originally connected the integration. On the Security tab, find the Connected applications section, hover over AccessOwl, and click Remove.
- As the user who connected the integration: Go to Third-party apps & services in your Google Account and select AccessOwl. In the AccessOwl has some access to your Google Account section, click See details, then Remove all access.


- Go to Settings → General → Directory Integrations. You see all your directory integrations listed there.
- On the Google integration, click Re-Auth and follow the steps to reconnect. Google shows the consent screen again and requests the OAuth scopes currently configured for your organization. The Google account you use to grant this must be a super admin at that moment, because Google itself requires a super admin to grant some of the OAuth scopes AccessOwl needs.

Revoke the grant in Google first. If AccessOwl still holds an active grant, the re-authentication completes without requesting a fresh one.
Troubleshooting
2-Step Verification is not enabled
2-Step Verification is not enabled
Follow this guide to ensure that 2-Step Verification is enabled in your organization. Also, check that it’s active for the OU of the integration account.
A passkey is required to sign in
A passkey is required to sign in
The integration account cannot present a passkey. If your Google Workspace enforces passkey sign-in for the organizational unit the integration account is in, the sign-in fails. See the fix in the integrations overview.
Gmail is not assigned to the user
Gmail is not assigned to the user
Find out which apps are turned on for the OU of the integration account and ensure that Gmail is turned on.
Google Workspace license missing during User Onboarding
Google Workspace license missing during User Onboarding
If you run out of Google Workspace licenses, AccessOwl notifies your GWS admins and re-assigns the provisioning to them. Once a license is purchased and the user account is created in GWS, AccessOwl automatically detects it and resumes the onboarding flow—no need to cancel or re-run the entire request.
A user's onboarding is blocked and no Google account was created
A user's onboarding is blocked and no Google account was created
This happens when the person exists in Google Workspace only as a member of a group, with no account of their own in an Organizational Unit. AccessOwl needs an account in an Organizational Unit before it can provision anything for that person.Request a Google Account on an Organizational Unit for that person, then the onboarding resumes.Access Templates created before they included the “Assigned Organizational Unit” resource do not set an Organizational Unit for onboarded users, so an older onboarding can run into this even when newer onboardings, built from an updated template, work fine.
FAQ
What does AccessOwl remove when it offboards a Google Workspace user?
What does AccessOwl remove when it offboards a Google Workspace user?
Order matters. Group memberships, admin roles and licenses are removed first, then the account is suspended, so the paid license is freed instead of staying assigned to a suspended user.Each of these steps is a separate Google API call, so deprovisioning is not instant. Expect it to take 10 to 15 minutes to complete.

