Connect Google Cloud to Polara
Read-only OAuth connection. Nine evidence types collected automatically across every accessible project: IAM bindings, service accounts, org policies, audit-log config, logging sinks, storage encryption, KMS keys, and Compute instances.
One connection covers both. Google Cloud and Google Workspace share a single Polara connection. Connecting either grants both. If you only use Google Cloud, untick the Workspace scopes on the consent screen and Polara skips the Workspace-only evidence.
What we collect
Nine evidence types map to the AICPA Common Criteria controls in your SOC 2 report. Same set every sync, no extras.
| Evidence | What it shows | SOC 2 controls |
|---|---|---|
IAM members gcp:iam:members | Project-level IAM policy bindings, showing which roles are granted to which members. | CC6.1, CC6.3 |
Service accounts gcp:iam:service_accounts | Privileged non-human inventory: service accounts per project, with disabled status. | CC6.1, CC6.3 |
Org policies gcp:org:policies | Organization policy constraints in effect on each project. | CC6.1, CC6.6 |
Audit logs config gcp:audit_logs:config | Cloud Audit Logs configuration per project, covering admin-read / data-access log types. | CC7.2 |
Logging sinks gcp:logging:sinks | Log sinks per project, with centralized log export destinations and filters. | CC7.2 |
Storage buckets gcp:storage:buckets | Cloud Storage buckets with default encryption (CMEK vs Google-managed). | CC6.7, CC6.8 |
Cloud KMS keys gcp:cloudkms:keys | Customer-managed Cloud KMS crypto keys across every key ring and location. | CC6.7 |
Compute instances gcp:compute:instances | Compute Engine VMs per project with shielded-VM and disk-encryption status. | CC6.6, CC6.7 |
2SV status (Cloud Identity) gcp:org:2sv_status | Cloud Identity 2-Step Verification posture, used when Workspace is not connected. | CC6.1, CC6.2 |
Permissions we request
All scopes are read-only.
Polara never writes to your projects, IAM policies, or resources. No modifications, no deletions, no admin actions. Polara only reads the configuration needed for your SOC 2 evidence.
| OAuth scope | Why we need it |
|---|---|
| cloud-platform.read-only | Read IAM bindings, service accounts, org policies, audit-log config, storage buckets, KMS keys, and Compute instances across your projects. |
| logging.read | Read Cloud Logging sink configuration to evidence centralized log export. |
| cloud-identity.groups.readonly | Read Cloud Identity groups to evidence 2-Step Verification posture when Workspace is not connected. |
The same consent screen also requests three Google Workspace scopes. If you don't use Workspace, untick them. Polara only collects the GCP evidence above.
How to connect
Three steps. About a minute start to finish.
- 1
Click Connect in Polara
On your Integrations tab, click Connect on the Google Cloud card. A disclosure modal lists exactly what Polara will read, for both Google Cloud and Workspace.
- 2
Authorize with Google
Google opens a new tab with the consent screen. Sign in with an account that has read access to your Google Cloud projects. If you don't use Google Workspace, untick the Workspace scopes. Polara will skip the Workspace-only evidence.
- 3
Click Allow and come back
Review the read-only scopes, click Allow, and Google redirects you back to Polara. The Google Cloud card flips to Connected and the first sync starts automatically.
How to disconnect
Disconnecting in Polara revokes the Google OAuth grant and stops future evidence pulls. Because Google Cloud and Workspace share one grant, disconnecting either one revokes the shared token. If you have both connected, you'll need to reconnect the other.
- In Polara: dashboard → Integrations tab → Google Cloud card → Disconnect.
- Optionally, also review and revoke at
myaccount.google.com/permissionsunder Google Account → Security → Third-party access.
Note: previously collected evidence stays attached to your assessment for audit reproducibility. Future syncs simply stop once the grant is revoked.
Troubleshooting
Polara shows "waiting" for more than 2 minutes after I clicked Continue.▾
Some of my projects show no evidence.▾
The consent screen warns the app is unverified.▾
Ready to connect?
About a minute from here. Polara handles the rest.
Go to your dashboard