Read-only integration

Connect Google Workspace to Polara

Read-only OAuth connection. Six evidence types collected automatically: directory users, 2-Step Verification status, groups, admin roles, and 30-day login + admin audit logs. Closes the 2SV and admin-action-history gaps without a screenshot.

Super Admin required. Only a Workspace Super Admin can connect this. Non-admins will see an error and no connection is created. Polara verifies admin status before recording anything.

One connection covers both. Google Workspace and Google Cloud share a single Polara connection. Connecting either one grants both.

Go to dashboard to connect

What we collect

Six evidence types map to the AICPA Common Criteria controls in your SOC 2 report. Same set every sync, no extras.

EvidenceWhat it showsSOC 2 controls
Directory users
workspace:directory:users
All users in the Workspace domain with admin, suspended, and 2SV-enrollment status.CC6.1, CC6.3
2SV status
workspace:directory:2sv_status
Per-user 2-Step Verification enrollment summarized for the domain.CC6.1, CC6.2
Directory groups
workspace:directory:groups
All groups in the Workspace domain with member counts.CC6.3
Admin roles
workspace:admin:roles
Workspace admin roles defined in the domain, including super-admin and system roles.CC6.1, CC6.3
Login audit
workspace:reports:login_audit
Login activity audit over the last 30 days (configurable per tenant).CC7.2
Admin audit
workspace:reports:admin_audit
Admin-console action audit over the last 30 days, covering admin action history.CC7.2

Permissions we request

All scopes are read-only.

Polara never writes to your directory, groups, roles, or settings. No user changes, no role grants, no admin actions. It only reads the configuration and audit data needed for your SOC 2 evidence.

OAuth scopeWhy we need it
admin.directory.user.readonlyList Workspace users and read each user's admin, suspended, and 2-Step Verification status.
admin.directory.group.readonlyList Workspace groups and read their member counts.
admin.reports.audit.readonlyRead the login and admin-console audit logs (restricted scope, requires Google verification).

The same consent screen also requests three Google Cloud scopes. Connecting Workspace grants Google Cloud too. See the Google Cloud setup doc for what those collect.

Super Admin required

The Google Workspace connector can only be connected by a Workspace Super Admin. The Admin SDK Directory and Reports APIs Polara uses require admin privileges. A regular user account simply can't read the directory or audit logs.

When a non-admin account attempts to connect, Polara verifies admin status against the Workspace directory and refuses to create the connection. You'll see a clear error instead. Reconnect with a Super Admin account and the six evidence types collect normally.

If your org separates Google Cloud access from Workspace admin, the Cloud-only path is fully supported. See the Google Cloud setup doc. Untick the Workspace scopes on the consent screen and Polara collects just the GCP evidence.

How to connect

Three steps. About a minute start to finish.

  1. 1

    Sign in as a Workspace Super Admin

    Make sure you are signed into a Google account with the Super Admin role on your Workspace domain. Non-admin accounts will be rejected. No connection is created.

  2. 2

    Click Connect in Polara

    On your Integrations tab, click Connect on the Google Workspace card. A disclosure modal lists exactly what Polara will read, for both Workspace and Google Cloud.

  3. 3

    Authorize and come back

    Google opens the consent screen in a new tab. Review the read-only scopes, click Allow, and Google redirects you back to Polara. The Workspace card flips to Connected and the first sync starts automatically.

How to disconnect

Disconnecting in Polara revokes the Google OAuth grant and stops future evidence pulls. Because Google Workspace and Google Cloud share one grant, disconnecting either one revokes the shared token. If you have both connected, you'll need to reconnect the other.

  1. In Polara: dashboard → Integrations tab → Google Workspace card → Disconnect.
  2. Optionally, also review and revoke at myaccount.google.com/permissions under Google Account → Security → Third-party access.

Note: previously collected evidence stays attached to your assessment for audit reproducibility. Future syncs simply stop once the grant is revoked.

Troubleshooting

I got a "not a Workspace admin" error.
The Google account you authorized with is not a Workspace Super Admin. The Admin SDK APIs require admin privileges, so Polara refuses to create the connection. Sign out, sign back in with a Super Admin account, and click Connect again.
The login or admin audit shows zero events.
Polara pulls the last 30 days of login and admin audit activity. If the window is genuinely empty (a brand-new domain, or admin actions older than 30 days), the evidence row records zero events. The admin audit log is the source for the admin-action-history gap (F4). It closes when there is at least one admin event in the window.
The consent screen warns the app is unverified.
The Workspace audit-log scope is a Google "restricted" scope that goes through Google's verification review. If you see an "unverified app" warning, verification is still in progress. Contact founder@polaralabs.com and we'll confirm status.

Sign in as a Super Admin, then it's about a minute. Polara handles the rest.

Go to your dashboard
polara labs

Polara Labs builds both sides of the audit: the readiness platform startups use to earn a SOC 2 report or an ISO 27001 certificate, and the practice OS audit firms use to run the examination. Every price is published on the page it belongs to.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.