> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Workspace

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/google-workspace.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=04bc673fec7e765a9d5507ff6b8fbf09" alt="" noZoom width="24" height="24" data-path="images/connectors/google-workspace.svg" />

  <h1>Google Workspace</h1>
</div>

## Connection

### Setup

<Steps>
  <Step title="Create a service account">
    In a Google Cloud project,
    [create a service account](https://developers.google.com/workspace/guides/create-credentials#service-account) and
    download the JSON key for it.
  </Step>

  <Step title="Delegate the scopes">
    Give the service account [domain-wide delegation](https://support.google.com/a/answer/162106) for
    the scopes under [Permissions](#permissions).
  </Step>

  <Step title="Choose the admin account">
    The service account acts on behalf of the specified admin. We recommend giving that admin only the privileges Klef actually needs.
  </Step>
</Steps>

### Settings

| Setting                    | Required | Description                                                                        |
| -------------------------- | -------- | ---------------------------------------------------------------------------------- |
| Admin email                | Yes      | Admin account the service account acts as. Give it only the privileges Klef needs. |
| Customer ID                |          | Workspace customer ID. Leave empty for your own account.                           |
| Service account key (JSON) | Yes      | JSON key of a service account with domain-wide delegation. Stored encrypted.       |

### Permissions

Minimum permissions the connection requires.

| Capability              | Required | Granted by (any one)                                      |
| ----------------------- | -------- | --------------------------------------------------------- |
| Read and write users    | Yes      | `https://www.googleapis.com/auth/admin.directory.user`    |
| Reset passwords         | Yes      | `https://www.googleapis.com/auth/admin.directory.user`    |
| Manage group membership | Yes      | `https://www.googleapis.com/auth/admin.directory.group`   |
| Create org units        | Yes      | `https://www.googleapis.com/auth/admin.directory.orgunit` |
| Manage licenses         |          | `https://www.googleapis.com/auth/apps.licensing`          |

## google\_workspace.user

### Fields

| Field                                                      | Type               | Required | Description                                                                      |
| ---------------------------------------------------------- | ------------------ | -------- | -------------------------------------------------------------------------------- |
| `primaryEmail`                                             | string, up to 320  | Yes      | Sign-in address. Its domain must belong to the Workspace account.                |
| `givenName`                                                | string, up to 60   | Yes      | First name.                                                                      |
| `familyName`                                               | string, up to 60   | Yes      | Last name.                                                                       |
| `orgUnitPath`                                              | string, up to 255  | Yes      | Organizational unit, such as /Engineering. Klef creates it if it does not exist. |
| `suspended`                                                | bool               | Yes      | Whether the account is suspended.                                                |
| `includeInGlobalAddressList` (Show in Global Address List) | bool               | Yes      | Whether the user appears in the global address list.                             |
| `jobTitle`                                                 | string             |          | Job title.                                                                       |
| `department`                                               | string             |          | Department name.                                                                 |
| `employeeId`                                               | string             |          | Employee number, usually from the HR system.                                     |
| `recoveryEmail`                                            | string, up to 320  |          | Personal address Google uses for account recovery.                               |
| `mobilePhone`                                              | string, up to 64   |          | Mobile phone number.                                                             |
| `workPhone`                                                | string, up to 64   |          | Work phone number.                                                               |
| `homePhone`                                                | string, up to 64   |          | Home phone number.                                                               |
| `streetAddress`                                            | string, up to 1024 |          | Street address.                                                                  |
| `city`                                                     | string, up to 255  |          | City.                                                                            |
| `state`                                                    | string, up to 255  |          | State or region.                                                                 |
| `postalCode`                                               | string, up to 32   |          | Postal code.                                                                     |
| `country`                                                  | string, up to 255  |          | Country or region.                                                               |
| `manager`                                                  | link               |          | The user's manager, set from the worker's manager.                               |
| `licenses`                                                 | grant              |          | Workspace licenses assigned to the user. One row grants one license.             |
| `licenses[]`                                               | string             |          | License SKU ID.                                                                  |
| `groups`                                                   | grant              |          | Groups the user is a member of. One row grants one group.                        |
| `groups[]` (Group)                                         | string             |          | Group ID.                                                                        |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in Google Workspace, it works out whose it is by trying these in order. A connection can override them.

| Account field  | Worker field            |
| -------------- | ----------------------- |
| `primaryEmail` | `worker.business_email` |
| `employeeId`   | `worker.employee_id`    |

## Examples

### Google Workspace accounts

A suspended Google account before day one, licensed when they start, and suspended with its license returned when they leave.

```hcl theme={null}
stage active {
  target google_workspace.user {
    primaryEmail               = worker.business_email
    givenName                  = worker.legal_name.given
    familyName                 = worker.legal_name.family
    orgUnitPath                = "/Employees"
    suspended                  = false
    includeInGlobalAddressList = true
    jobTitle                   = worker.job.name
    department                 = worker.department.name
    employeeId                 = worker.employee_id

    # Google Workspace Business Standard. The editor lists the SKUs your account holds.
    licenses = ["1010020028"]
  }
}
```
