Google Workspace
Read user, group and admin activity from Google Workspace and turn each change into a typed event. Use it to provision accounts, offboard leavers and hand over their Drive files.
Identity
Category
Polling
Sync mode
Every 2 min
Latency
9 min
Setup time
What it can do
- User createdPoll
- User suspendedPoll
- Added to a groupPoll
- Look up a userRead
- Create a userWrite
- Add to a groupWrite
- Suspend a userWrite
- Transfer Drive ownershipWrite
Overview
The Google Workspace connector reads the Admin SDK Reports API on a schedule and turns admin activity into typed events. Each event carries the actor, the affected user and the parameters Google recorded, and it appears in the trace of the run it started.
Teams use it to create accounts and add groups when a hire lands in Rippling, to suspend leavers and move their files to a manager with the Data Transfer API, and to post a summary of group changes to Slack each week.
Supported objects
Users, including organizational unit and custom schema fields
Groups and group membership
Admin audit events such as
CREATE_USER,SUSPEND_USERandADD_GROUP_MEMBER
How polling works
Every two minutes Tessel asks the Reports API for admin activities since its last cursor. New activities are checked against the schema, matched to a trigger and delivered in time order. Google can report some events a few minutes late, so Tessel overlaps each window and drops events it has already seen.
Domain-wide delegation
Tessel signs in as a service account that impersonates an admin you choose. Every call it makes shows up under that admin in your Admin console audit log, so your own reviews still see it.
Permissions needed
Create a service account in Google Cloud and authorize its client ID under domain-wide delegation. Add only the scopes you need. The Data Transfer scope, admin.datatransfer, is only needed to move Drive files.
admin.directory.userfor user lookups, creation and suspensionadmin.directory.groupfor groups and membershipadmin.reports.audit.readonlyfor the polling triggers
Five steps. About nine minutes.
Most of the time goes into domain-wide delegation. Tessel lists any scope that is missing.
- Create a service account and download its keyGoogle Cloud3 min
- Authorize the client ID with Admin SDK scopesGoogle Workspace3 min
- Choose an admin for Tessel to act asGoogle Workspace1 min
- Upload the key and pick triggersTessel2 min
- Create a test user and wait for the next pollVerify2 min
Workspace accounts, handled by workflow.
Connect Google Workspace on the free plan. Up to three builders and 10,000 runs a month, no card required.