Skip to main content

Connect Google Workspace for your organization

Connect a Google service account once so Chief can access your organization’s Gmail, Calendar, and Drive on behalf of your users. You configure this a single time for the whole organization, then assign it to the Projects that should use it — individual users don’t each connect their own Google account.
⚠️ Important: Only an organization owner can configure Google Workspace. If you’re not an owner, you’ll see “Only an organization owner can configure the Google Workspace integration. Ask your administrator to set it up.” This integration is also plan-gated — if your plan doesn’t include it, you’ll be prompted to upgrade.

Before you start

Open the Setup instructions panel on the integration page and follow these steps in Google Cloud and your Workspace Admin Console:
  1. Create a service account in your Google Cloud project.
  2. Enable the Gmail, Calendar, Drive, People, and Admin SDK APIs in that project.
  3. In the Workspace Admin Console, go to SecurityAccess and data controlAPI controlsDomain-wide delegation, and authorize the service account’s client ID with the scopes listed in the panel. Use the Copy button to copy the full scope list, and the Open Domain-wide delegation link to jump to the right Admin Console page.
  4. Download the service account JSON key.

Add the integration in Chief

  1. Go to your organization’s Integrations page (under the org’s settings).
  2. Click Add Google workspace.
  3. Under Select projects, check the Projects this integration should serve.
  4. In Google Workspace domain, enter your domain (for example, example.com).
  5. In Service account JSON key, paste the key contents, or click Upload JSON file to load the downloaded file.
  6. Click Connect workspace.
The saved integration card shows the service account email, service account client ID, the Google Cloud project ID, and the assigned Projects.

Enable Shared Drive ingestion

During setup, expand Step 6, Enable Drive ingestion, to use Shared Drives. Enter a Workspace administrator’s email and save it. Chief verifies the address and lists only Shared Drives that administrator belongs to; their personal files are never read. Files and folders shared directly with the service account work without this setting. Use Copy share address when you need the address to share content with.

Choose what a Project syncs

After deploying the integration, select Edit Drive content for that Project. Choose a Sync mode:
  • Selected content — sync only the Shared Drives and folders you select.
  • Everything shared — sync everything shared with the service account, now and later, plus selected Shared Drives or folders.
Use the Drive picker to select Shared Drives, shared folders, or shared files, then click Save. Narrowing the selection opens Remove Drive content? because deselected files and their indexed content will be removed from the Project. Select Sync now to re-read the current selection. Chief warns that files no longer in scope will be removed, then runs the sync in the background.

Check access and manage deployment

The Access health section shows whether all required Google scopes are granted. Select Check access to refresh it. If access is missing, send the displayed service-account client ID and scope list to your Google Workspace administrator. Each connected Workspace can be Deployed to project, Undeployed, or Removed. Undeploy removes every synced Drive file and its indexed content from that Project. Removing the Workspace integration does the same across every Project using it.

Manage an existing integration

  • Add a Project: select Deploy to project, then choose the Project.
  • Change Drive content: select Edit Drive content for a deployed Project.
  • Remove a Project: select Undeploy.
  • Remove the integration: select Remove.
ℹ️ Good to know: Each Project in an organization can have only one Google Workspace integration. If every Project already has one, you’ll see “Every project in this organization already has a Google Workspace integration.”

What this enables for users

Once a Project is covered, members can use Gmail, Calendar, and Drive features in Chief without connecting their own Google accounts. If a user requests a Google capability that isn’t set up, Chief shows a Google Workspace setup required card explaining why (workspace not connected, tools not enabled in the project, domain mismatch, or a scope not authorized).

FAQ

The file must be valid service account JSON. If the contents aren’t a JSON object, Chief rejects the key before saving. Re-download the key from Google Cloud and upload it again. Make sure you selected a Project, entered the domain, and pasted the key — all three are required to save.
The requested capability needs a scope that isn’t authorized for the service account. In the Admin Console, open Domain-wide delegation and add the missing scope from the Setup instructions panel to the service account’s client ID.
Their account isn’t part of the connected Google Workspace domain. Confirm they’re on the domain you configured, or add the appropriate integration for their domain.