Connect Google Workspace for your organization
Connect a Google service account once so Chief can access your organization’s Gmail, Calendar, and Drive on behalf of your users. You configure this a single time for the whole organization, then assign it to the Projects that should use it — individual users don’t each connect their own Google account.Before you start
Open the Setup instructions panel on the integration page and follow these steps in Google Cloud and your Workspace Admin Console:- Create a service account in your Google Cloud project.
- Enable the Gmail, Calendar, Drive, People, and Admin SDK APIs in that project.
- In the Workspace Admin Console, go to Security → Access and data control → API controls → Domain-wide delegation, and authorize the service account’s client ID with the scopes listed in the panel. Use the Copy button to copy the full scope list, and the Open Domain-wide delegation link to jump to the right Admin Console page.
- Download the service account JSON key.
Add the integration in Chief
- Go to your organization’s Integrations page (under the org’s settings).
- Click Add Google workspace.
- Under Select projects, check the Projects this integration should serve.
- In Google Workspace domain, enter your domain (for example,
example.com). - In Service account JSON key, paste the key contents, or click Upload JSON file to load the downloaded file.
- Click Connect workspace.
Enable Shared Drive ingestion
During setup, expand Step 6, Enable Drive ingestion, to use Shared Drives. Enter a Workspace administrator’s email and save it. Chief verifies the address and lists only Shared Drives that administrator belongs to; their personal files are never read. Files and folders shared directly with the service account work without this setting. Use Copy share address when you need the address to share content with.Choose what a Project syncs
After deploying the integration, select Edit Drive content for that Project. Choose a Sync mode:- Selected content — sync only the Shared Drives and folders you select.
- Everything shared — sync everything shared with the service account, now and later, plus selected Shared Drives or folders.
Check access and manage deployment
The Access health section shows whether all required Google scopes are granted. Select Check access to refresh it. If access is missing, send the displayed service-account client ID and scope list to your Google Workspace administrator. Each connected Workspace can be Deployed to project, Undeployed, or Removed. Undeploy removes every synced Drive file and its indexed content from that Project. Removing the Workspace integration does the same across every Project using it.Manage an existing integration
- Add a Project: select Deploy to project, then choose the Project.
- Change Drive content: select Edit Drive content for a deployed Project.
- Remove a Project: select Undeploy.
- Remove the integration: select Remove.
ℹ️ Good to know: Each Project in an organization can have only one Google Workspace integration. If every Project already has one, you’ll see “Every project in this organization already has a Google Workspace integration.”
What this enables for users
Once a Project is covered, members can use Gmail, Calendar, and Drive features in Chief without connecting their own Google accounts. If a user requests a Google capability that isn’t set up, Chief shows a Google Workspace setup required card explaining why (workspace not connected, tools not enabled in the project, domain mismatch, or a scope not authorized).FAQ
I uploaded the JSON key but saving failed.
I uploaded the JSON key but saving failed.
The file must be valid service account JSON. If the contents aren’t a JSON object, Chief rejects the key before saving. Re-download the key from Google Cloud and upload it again. Make sure you selected a Project, entered the domain, and pasted the key — all three are required to save.
A user gets "Your Google Workspace admin needs to grant this permission."
A user gets "Your Google Workspace admin needs to grant this permission."
The requested capability needs a scope that isn’t authorized for the service account. In the Admin Console, open Domain-wide delegation and add the missing scope from the Setup instructions panel to the service account’s client ID.
A user sees "domain mismatch."
A user sees "domain mismatch."
Their account isn’t part of the connected Google Workspace domain. Confirm they’re on the domain you configured, or add the appropriate integration for their domain.