Capabilities
Structure Sync
AccessOwl periodically syncs the permissions schema of an application.
User Sync
AccessOwl periodically syncs a list of users along with their assigned permissions.
Provisioning
AccessOwl creates or removes user accounts with the specified permissions during access requests or revocations.
Directory Sync
AccessOwl syncs (creates, removes, or deactivates) users from directories like Slack, Microsoft365, Okta, or Google into the AccessOwl users database.
Required Google Workspace OAuth Permissions
AccessOwl integrates with your Google Workspace organization in order to automate user provisioning, de-provisioning and Shadow IT detection. In order to do so AccessOwl requires customers to confirm the following OAuth permissions. Provision and de-provisioning of users to Google Workspace, read out manager information (if available) and assign them the correct set of permissions and groups:View delegated admin roles for your domain
View delegated admin roles for your domain
View delegated admin roles that are currently defined for your domain.
View and manage Google Workspace licenses
View and manage Google Workspace licenses
View and manage Google Workspace/G Suite licenses.
View organization units on your domain
View organization units on your domain
View metadata (e.g., name and description) of organization units.
View and manage the provisioning of groups on your domain
View and manage the provisioning of groups on your domain
- Provision and delete groups on your domain.
- View and modify details (e.g., members) and metadata (e.g., login details) of groups on your domain.
View and manage the provisioning of users on your domain
View and manage the provisioning of users on your domain
- Provision and delete users on your domain.
- View and modify details (e.g., name, address, and phone number) and metadata (e.g., login details) of users on your domain.
View and manage user aliases on your domain
View and manage user aliases on your domain
View, modify, and delete aliases (alternative emails) for users on your domain.
Manage delegated admin roles for your domain
Manage delegated admin roles for your domain
View and manage delegated admin roles for your domain.
Manage data access permissions for users on your domain
Manage data access permissions for users on your domain
View and revoke OAuth grants for users.
View audit reports for your G Suite domain
View audit reports for your G Suite domain
View audit reports of admin and user activity in your G Suite domain (e.g. OAuth grants/revokes, SAML logins).
User & Group Management
Put a user in the right organizational unit (OU) by using the resource “Assigned Organizational Unit” during an onboarding. You can give a user more roles in other OUs by selecting other resources. Furthermore, groups can be assigned including their role of Member, Manager or Owner.When AccessOwl adds a user to a Google group, that member’s email delivery preference is set to All email by default. This applies to every group and cannot be configured per group or overridden today.
AccessOwl assigns from the licenses you already own and cannot purchase new ones. If no license of the chosen tier is available, buy the seat in the Google Admin console first. AccessOwl then detects it and assigns it automatically.
Application Discovery (Shadow IT Detection)
We analyze usage data in Google Workspace to analyze which applications are used in your organizations. The permissions are granted by an Google Workspace admin on AccessOwl setup. When new applications are used in your organization, Org Admins are notified. You can either approve or ignore these discovered applications before they become available for user requests.User Access Discovery
Based on emails, we can discover which user uses which application. We only use readonly scopes. We don’t read or download your email. Instead we query specifically for vendor emails. For more security related information, check our Security page.Integration Account Setup
The integration account is automatically created in your Google Workspace. To proceed, the following prerequisites must be met:- Gmail must be assigned and active -> invitation email need to be received
- 2-Step Verification need to be enabled in Google Workspace
- The user must be able to set up 2-Step Verification without admin intervention
Disconnecting and Reconnecting
In some cases you need to fully disconnect Google Workspace and connect it again, for example when the OAuth scopes configured for your organization change and AccessOwl needs to request the new set. A full disconnect means revoking AccessOwl’s OAuth grant in Google. Either of these two options works:- In the Google Admin console: Go to Directory > Users and open the user who originally connected the integration. On the Security tab, find the Connected applications section, hover over AccessOwl, and click Remove.
- As the user who connected the integration: Go to Third-party apps & services in your Google Account and select AccessOwl. In the AccessOwl has some access to your Google Account section, click See details, then Remove all access.


- Go to Settings → General → Directory Integrations. You see all your directory integrations listed there.
- On the Google integration, click Re-Auth and follow the steps to reconnect. Google shows the consent screen again and requests the OAuth scopes currently configured for your organization.

Revoke the grant in Google first. If AccessOwl still holds an active grant, the re-authentication completes without requesting a fresh one.
Troubleshooting
2-Step Verification is not enabled
2-Step Verification is not enabled
Follow this guide to ensure that 2-Step Verification is enabled in your organization. Also, check that it’s active for the OU of the integration account.
Gmail is not assigned to the user
Gmail is not assigned to the user
Find out which apps are turned on for the OU of the integration account and ensure that Gmail is turned on.
Google Workspace license missing during User Onboarding
Google Workspace license missing during User Onboarding
If you run out of Google Workspace licenses, AccessOwl notifies your GWS admins and re-assigns the provisioning to them. Once a license is purchased and the user account is created in GWS, AccessOwl automatically detects it and resumes the onboarding flow—no need to cancel or re-run the entire request.

