Skip to main content

Connect Google Workspace

Argus scans a Google Workspace domain read-only with a service account that has domain-wide delegation. Nothing is installed in the domain, and Argus only ever reads.

Before you start​

  • Permission to create a service account with domain-wide delegation, and Google Workspace super admin access to authorize it.
  • An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.

Provider-side setup​

  1. Create a service account and enable domain-wide delegation on it, then create a JSON key.
  2. In the Google Workspace Admin console, authorize the service account's client ID for the read-only scopes Argus needs. Argus only reads.
  3. Pick a delegated admin user for the service account to impersonate.

Required permissions​

Authorize the service account's client ID for these read-only OAuth scopes:

  • https://www.googleapis.com/auth/admin.directory.user.readonly
  • https://www.googleapis.com/auth/admin.directory.domain.readonly
  • https://www.googleapis.com/auth/admin.directory.customer.readonly
  • https://www.googleapis.com/auth/admin.directory.orgunit.readonly
  • https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly
  • https://www.googleapis.com/auth/cloud-identity.policies.readonly

Enable the Admin SDK API and the Cloud Identity API in the project that hosts the service account.

Connect in Argus​

Go to Accounts and click Connect account. Pick Google Workspace, then the Service account + delegation method. Enter:

FieldValue
Primary domainthe Workspace primary domain
Service-account key (JSON)the service-account JSON key with delegation
Delegated userthe admin to impersonate, e.g. admin@yourdomain.com

Connection test​

Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the key, the authorized scopes and the delegated user, then use Test connection on the account card to retry.

Official Google documentation​