Skip to main content
We support several features in Google Workspace, e.g. user management, group management etc. More interesting is that we can discover information like which applications are used by which user automatically for you.

Capabilities

Structure Sync

AccessOwl periodically syncs the permissions schema of an application.

User Sync

AccessOwl periodically syncs a list of users along with their assigned permissions.

Provisioning

AccessOwl creates or removes user accounts with the specified permissions during access requests or revocations.

Directory Sync

AccessOwl syncs (creates, removes, or deactivates) users from directories like Slack, Microsoft365, Okta, or Google into the AccessOwl users database.

Required Google Workspace OAuth Permissions

AccessOwl integrates with your Google Workspace organization in order to automate user provisioning, de-provisioning and Shadow IT detection. In order to do so AccessOwl requires customers to confirm the following OAuth permissions. The Google account that grants these permissions must be a super admin at the moment of granting, because Google itself requires a super admin for some of the scopes below. Each scope below is shown without its common https://www.googleapis.com/auth/ prefix. Provisioning and de-provisioning users, reading manager information (if available), and assigning the correct set of permissions, licenses, and groups: Detecting Shadow IT:

User & Group Management

Put a user in the right organizational unit (OU) by using the resource “Assigned Organizational Unit” during an onboarding. You can give a user more roles in other OUs by selecting other resources. Furthermore, groups can be assigned including their role of Member, Manager or Owner.
When AccessOwl adds a user to a Google group, that member’s email delivery preference is set to All email by default. This applies to every group and cannot be configured per group or overridden today.
Google Workspace licenses can be assigned the same way. Select a license tier (for example Business Starter, Business Standard, or one of the Enterprise plans) as a resource during an onboarding or access request, and AccessOwl assigns that license to the user once the request is approved. When a license is not assigned automatically, you can set the license field directly during Google directory onboarding.
AccessOwl assigns from the licenses you already own and cannot purchase new ones. If no license of the chosen tier is available, buy the seat in the Google Admin console first. AccessOwl then detects it and assigns it automatically.
When a personal email address is available for the onboarding user, the initial password will be sent via email to them.

Application Discovery (Shadow IT Detection)

We analyze usage data in Google Workspace to analyze which applications are used in your organizations. The permissions are granted by an Google Workspace admin on AccessOwl setup. When new applications are used in your organization, Org Admins are notified. You can either approve or ignore these discovered applications before they become available for user requests.

User Access Discovery

Based on emails, we can discover which user uses which application. We only use readonly scopes. We don’t read or download your email. Instead we query specifically for vendor emails. For more security related information, check our Security page.

Integration Account Setup

The integration account is automatically created in your Google Workspace. To proceed, the following prerequisites must be met:
  • A Google Workspace license that includes Gmail, any tier, because the integration account has to receive the invitation and verification emails. Cloud Identity licenses, Free or Premium, do not include Gmail and are not sufficient. The integration account therefore occupies one paid Google Workspace seat.
  • 2-Step Verification need to be enabled in Google Workspace
  • The user must be able to set up 2-Step Verification without admin intervention

Disconnecting and Reconnecting

In some cases you need to fully disconnect Google Workspace and connect it again, for example when the OAuth scopes configured for your organization change and AccessOwl needs to request the new set. A full disconnect means revoking AccessOwl’s OAuth grant in Google. Either of these two options works:
  • In the Google Admin console: Go to Directory > Users and open the user who originally connected the integration. On the Security tab, find the Connected applications section, hover over AccessOwl, and click Remove.
  • As the user who connected the integration: Go to Third-party apps & services in your Google Account and select AccessOwl. In the AccessOwl has some access to your Google Account section, click See details, then Remove all access.
Click See details in the AccessOwl has some access to your Google Account section Click Remove all access
After you revoke the grant in Google, AccessOwl keeps showing the integration as connected until the next sync runs. Once a sync runs, the integration shows an error status. It never shows as disconnected, this is expected while you are between disconnecting and reconnecting.
Then reconnect the integration in AccessOwl:
  1. Go to Settings → General → Directory Integrations. You see all your directory integrations listed there.
  2. On the Google integration, click Re-Auth and follow the steps to reconnect. Google shows the consent screen again and requests the OAuth scopes currently configured for your organization. The Google account you use to grant this must be a super admin at that moment, because Google itself requires a super admin to grant some of the OAuth scopes AccessOwl needs.
Click Re-Auth on the Google integration
Revoke the grant in Google first. If AccessOwl still holds an active grant, the re-authentication completes without requesting a fresh one.
If super admin is later removed from the account that granted the connection, the existing connection keeps working. The problem only surfaces the next time you reconnect or re-authenticate, when Google blocks the request.

Troubleshooting

Follow this guide to ensure that 2-Step Verification is enabled in your organization. Also, check that it’s active for the OU of the integration account.
The integration account cannot present a passkey. If your Google Workspace enforces passkey sign-in for the organizational unit the integration account is in, the sign-in fails. See the fix in the integrations overview.
Find out which apps are turned on for the OU of the integration account and ensure that Gmail is turned on.
If you run out of Google Workspace licenses, AccessOwl notifies your GWS admins and re-assigns the provisioning to them. Once a license is purchased and the user account is created in GWS, AccessOwl automatically detects it and resumes the onboarding flow—no need to cancel or re-run the entire request.
This happens when the person exists in Google Workspace only as a member of a group, with no account of their own in an Organizational Unit. AccessOwl needs an account in an Organizational Unit before it can provision anything for that person.Request a Google Account on an Organizational Unit for that person, then the onboarding resumes.Access Templates created before they included the “Assigned Organizational Unit” resource do not set an Organizational Unit for onboarded users, so an older onboarding can run into this even when newer onboardings, built from an updated template, work fine.

FAQ

Order matters. Group memberships, admin roles and licenses are removed first, then the account is suspended, so the paid license is freed instead of staying assigned to a suspended user.Each of these steps is a separate Google API call, so deprovisioning is not instant. Expect it to take 10 to 15 minutes to complete.
Last modified on September 17, 2026