Skip to main content
We support several features in Google Workspace, e.g. user management, group management etc. More interesting is that we can discover information like which applications are used by which user automatically for you.

Capabilities

Structure Sync

AccessOwl periodically syncs the permissions schema of an application.

User Sync

AccessOwl periodically syncs a list of users along with their assigned permissions.

Provisioning

AccessOwl creates or removes user accounts with the specified permissions during access requests or revocations.

Directory Sync

AccessOwl syncs (creates, removes, or deactivates) users from directories like Slack, Microsoft365, Okta, or Google into the AccessOwl users database.

Required Google Workspace OAuth Permissions

AccessOwl integrates with your Google Workspace organization in order to automate user provisioning, de-provisioning and Shadow IT detection. In order to do so AccessOwl requires customers to confirm the following OAuth permissions. Provision and de-provisioning of users to Google Workspace, read out manager information (if available) and assign them the correct set of permissions and groups:
View delegated admin roles that are currently defined for your domain.
View and manage Google Workspace/G Suite licenses.
View metadata (e.g., name and description) of organization units.
  • Provision and delete groups on your domain.
  • View and modify details (e.g., members) and metadata (e.g., login details) of groups on your domain.
  • Provision and delete users on your domain.
  • View and modify details (e.g., name, address, and phone number) and metadata (e.g., login details) of users on your domain.
View, modify, and delete aliases (alternative emails) for users on your domain.
View and manage delegated admin roles for your domain.
Detecting Shadow IT:
View and revoke OAuth grants for users.
View audit reports of admin and user activity in your G Suite domain (e.g. OAuth grants/revokes, SAML logins).

User & Group Management

Put a user in the right organizational unit (OU) by using the resource “Assigned Organizational Unit” during an onboarding. You can give a user more roles in other OUs by selecting other resources. Furthermore, groups can be assigned including their role of Member, Manager or Owner.
When AccessOwl adds a user to a Google group, that member’s email delivery preference is set to All email by default. This applies to every group and cannot be configured per group or overridden today.
Google Workspace licenses can be assigned the same way. Select a license tier (for example Business Starter, Business Standard, or one of the Enterprise plans) as a resource during an onboarding or access request, and AccessOwl assigns that license to the user once the request is approved. When a license is not assigned automatically, you can set the license field directly during Google directory onboarding.
AccessOwl assigns from the licenses you already own and cannot purchase new ones. If no license of the chosen tier is available, buy the seat in the Google Admin console first. AccessOwl then detects it and assigns it automatically.
When a personal email address is available for the onboarding user, the initial password will be sent via email to them.

Application Discovery (Shadow IT Detection)

We analyze usage data in Google Workspace to analyze which applications are used in your organizations. The permissions are granted by an Google Workspace admin on AccessOwl setup. When new applications are used in your organization, Org Admins are notified. You can either approve or ignore these discovered applications before they become available for user requests.

User Access Discovery

Based on emails, we can discover which user uses which application. We only use readonly scopes. We don’t read or download your email. Instead we query specifically for vendor emails. For more security related information, check our Security page.

Integration Account Setup

The integration account is automatically created in your Google Workspace. To proceed, the following prerequisites must be met:
  • Gmail must be assigned and active -> invitation email need to be received
  • 2-Step Verification need to be enabled in Google Workspace
  • The user must be able to set up 2-Step Verification without admin intervention

Disconnecting and Reconnecting

In some cases you need to fully disconnect Google Workspace and connect it again, for example when the OAuth scopes configured for your organization change and AccessOwl needs to request the new set. A full disconnect means revoking AccessOwl’s OAuth grant in Google. Either of these two options works:
  • In the Google Admin console: Go to Directory > Users and open the user who originally connected the integration. On the Security tab, find the Connected applications section, hover over AccessOwl, and click Remove.
  • As the user who connected the integration: Go to Third-party apps & services in your Google Account and select AccessOwl. In the AccessOwl has some access to your Google Account section, click See details, then Remove all access.
Click See details in the AccessOwl has some access to your Google Account section Click Remove all access
After you revoke the grant in Google, AccessOwl keeps showing the integration as connected until the next sync runs. Once a sync runs, the integration shows an error status. It never shows as disconnected, this is expected while you are between disconnecting and reconnecting.
Then reconnect the integration in AccessOwl:
  1. Go to Settings → General → Directory Integrations. You see all your directory integrations listed there.
  2. On the Google integration, click Re-Auth and follow the steps to reconnect. Google shows the consent screen again and requests the OAuth scopes currently configured for your organization.
Click Re-Auth on the Google integration
Revoke the grant in Google first. If AccessOwl still holds an active grant, the re-authentication completes without requesting a fresh one.

Troubleshooting

Follow this guide to ensure that 2-Step Verification is enabled in your organization. Also, check that it’s active for the OU of the integration account.
Find out which apps are turned on for the OU of the integration account and ensure that Gmail is turned on.
If you run out of Google Workspace licenses, AccessOwl notifies your GWS admins and re-assigns the provisioning to them. Once a license is purchased and the user account is created in GWS, AccessOwl automatically detects it and resumes the onboarding flow—no need to cancel or re-run the entire request.
Last modified on August 7, 2026