Connect Google Workspace to Polara
Read-only OAuth connection. Six evidence types collected automatically: directory users, 2-Step Verification status, groups, admin roles, and 30-day login + admin audit logs. Closes the 2SV and admin-action-history gaps without a screenshot.
Super Admin required. Only a Workspace Super Admin can connect this. Non-admins will see an error and no connection is created. Polara verifies admin status before recording anything.
One connection covers both. Google Workspace and Google Cloud share a single Polara connection. Connecting either one grants both.
What we collect
Six evidence types map to the AICPA Common Criteria controls in your SOC 2 report. Same set every sync, no extras.
| Evidence | What it shows | SOC 2 controls |
|---|---|---|
Directory users workspace:directory:users | All users in the Workspace domain with admin, suspended, and 2SV-enrollment status. | CC6.1, CC6.3 |
2SV status workspace:directory:2sv_status | Per-user 2-Step Verification enrollment summarized for the domain. | CC6.1, CC6.2 |
Directory groups workspace:directory:groups | All groups in the Workspace domain with member counts. | CC6.3 |
Admin roles workspace:admin:roles | Workspace admin roles defined in the domain, including super-admin and system roles. | CC6.1, CC6.3 |
Login audit workspace:reports:login_audit | Login activity audit over the last 30 days (configurable per tenant). | CC7.2 |
Admin audit workspace:reports:admin_audit | Admin-console action audit over the last 30 days, covering admin action history. | CC7.2 |
Permissions we request
All scopes are read-only.
Polara never writes to your directory, groups, roles, or settings. No user changes, no role grants, no admin actions. It only reads the configuration and audit data needed for your SOC 2 evidence.
| OAuth scope | Why we need it |
|---|---|
| admin.directory.user.readonly | List Workspace users and read each user's admin, suspended, and 2-Step Verification status. |
| admin.directory.group.readonly | List Workspace groups and read their member counts. |
| admin.reports.audit.readonly | Read the login and admin-console audit logs (restricted scope, requires Google verification). |
The same consent screen also requests three Google Cloud scopes. Connecting Workspace grants Google Cloud too. See the Google Cloud setup doc for what those collect.
Super Admin required
The Google Workspace connector can only be connected by a Workspace Super Admin. The Admin SDK Directory and Reports APIs Polara uses require admin privileges. A regular user account simply can't read the directory or audit logs.
When a non-admin account attempts to connect, Polara verifies admin status against the Workspace directory and refuses to create the connection. You'll see a clear error instead. Reconnect with a Super Admin account and the six evidence types collect normally.
If your org separates Google Cloud access from Workspace admin, the Cloud-only path is fully supported. See the Google Cloud setup doc. Untick the Workspace scopes on the consent screen and Polara collects just the GCP evidence.
How to connect
Three steps. About a minute start to finish.
- 1
Sign in as a Workspace Super Admin
Make sure you are signed into a Google account with the Super Admin role on your Workspace domain. Non-admin accounts will be rejected. No connection is created.
- 2
Click Connect in Polara
On your Integrations tab, click Connect on the Google Workspace card. A disclosure modal lists exactly what Polara will read, for both Workspace and Google Cloud.
- 3
Authorize and come back
Google opens the consent screen in a new tab. Review the read-only scopes, click Allow, and Google redirects you back to Polara. The Workspace card flips to Connected and the first sync starts automatically.
How to disconnect
Disconnecting in Polara revokes the Google OAuth grant and stops future evidence pulls. Because Google Workspace and Google Cloud share one grant, disconnecting either one revokes the shared token. If you have both connected, you'll need to reconnect the other.
- In Polara: dashboard → Integrations tab → Google Workspace card → Disconnect.
- Optionally, also review and revoke at
myaccount.google.com/permissionsunder Google Account → Security → Third-party access.
Note: previously collected evidence stays attached to your assessment for audit reproducibility. Future syncs simply stop once the grant is revoked.
Troubleshooting
I got a "not a Workspace admin" error.▾
The login or admin audit shows zero events.▾
The consent screen warns the app is unverified.▾
Ready to connect?
Sign in as a Super Admin, then it's about a minute. Polara handles the rest.
Go to your dashboard