Connect Google Workspace
Argus scans a Google Workspace domain read-only with a service account that has domain-wide delegation. Nothing is installed in the domain, and Argus only ever reads.
Before you start
- Permission to create a service account with domain-wide delegation, and Google Workspace super admin access to authorize it.
- An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.
Provider-side setup
- Create a service account and enable domain-wide delegation on it, then create a JSON key.
- In the Google Workspace Admin console, authorize the service account's client ID for the read-only scopes Argus needs. Argus only reads.
- Pick a delegated admin user for the service account to impersonate.
Required permissions
Authorize the service account's client ID for these read-only OAuth scopes:
https://www.googleapis.com/auth/admin.directory.user.readonlyhttps://www.googleapis.com/auth/admin.directory.domain.readonlyhttps://www.googleapis.com/auth/admin.directory.customer.readonlyhttps://www.googleapis.com/auth/admin.directory.orgunit.readonlyhttps://www.googleapis.com/auth/admin.directory.rolemanagement.readonlyhttps://www.googleapis.com/auth/cloud-identity.policies.readonly
Enable the Admin SDK API and the Cloud Identity API in the project that hosts the service account.
Connect in Argus
Go to Accounts and click Connect account. Pick Google Workspace, then the Service account + delegation method. Enter:
| Field | Value |
|---|---|
| Primary domain | the Workspace primary domain |
| Service-account key (JSON) | the service-account JSON key with delegation |
| Delegated user | the admin to impersonate, e.g. admin@yourdomain.com |
Connection test
Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the key, the authorized scopes and the delegated user, then use Test connection on the account card to retry.