IT CanvassTalk to an advisor
Connectors · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Google Workspace

Governing Google Workspace users, groups and org units.

Quick answer

SailPoint uses Google Admin SDK APIs to aggregate users and groups and provision membership and account changes.

Key takeaways
  • Google Workspace connector type: a REST/API-based connector
  • Onboarding: aggregate then correlate
  • SailPoint can create/suspend Google users and manage group and org-unit membership.
  • Common issues covered in troubleshooting

Google Workspace is the productivity backbone for many organisations, so governing who has a Google account, which groups and org units they belong to, and when accounts are suspended, is core lifecycle hygiene. SailPoint aggregates Google users and groups and provisions changes automatically.

Connector type and how it connects

The Google Workspace integration is a REST/API-based connector. It uses the Google Admin SDK APIs authenticated with a service account (domain-wide delegation). As with every connector, the flow is the same: authenticate to Google Workspace, read accounts and entitlements during aggregation, and write changes during provisioning.

Onboarding the source

  • 1. Configure the connection and credentials for Google Workspace.
  • 2. Map the account schema, mapping Google users, group memberships and organisational units to SailPoint accounts and entitlements.
  • 3. Set the correlation logic so Google Workspace accounts attach to the right identities (typically on a stable key such as employee ID or email).
  • 4. Run account aggregation and confirm accounts and entitlements load.
  • 5. Verify correlation, watching for uncorrelated/orphan accounts.

Provisioning capabilities

SailPoint can create and suspend Google users and manage group and org-unit membership, driven by roles, requests and lifecycle events. Prompt suspension on leaver is a key control and licence saver.

Entitlements and what to govern

Govern group memberships and org-unit placement, which drive access to shared resources and policies. Enrich significant groups as Managed Attributes.

Troubleshooting

When Google Workspace aggregation or provisioning fails, work through the usual causes in order:

  • Verify the service account and domain-wide delegation scopes.
  • Confirm the delegated admin has rights over the users/groups in scope.
  • Check API enablement and quotas in the Google admin console.
  • Validate group/OU schema mapping.

Common pitfalls

  • Credential expiry (tokens/secrets/certs) silently breaking the connector.
  • Insufficient rights on the Google Workspace service account for the operations you need.
  • Schema or correlation misconfiguration leaving accounts uncorrelated.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What type of connector is Google Workspace?

Frequently asked questions

What does the term Google Workspace connector refer to in SailPoint?
Google Workspace is the productivity backbone for many organisations, so governing who has a Google account, which groups and org units they belong to, and when accounts are suspended, is core lifecycle hygiene. SailPoint aggregates Google users and groups and provisions changes automatically.
What is another point to note about Google Workspace connector?
As with every connector, the flow is the same: authenticate to Google Workspace, read accounts and entitlements during aggregation, and write changes during provisioning.
What tends to go wrong with Google Workspace connector?
Credential expiry (tokens/secrets/certs) silently breaking the connector. Insufficient rights on the Google Workspace service account for the operations you need. Schema or correlation misconfiguration leaving accounts uncorrelated.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support