Capabilities
| Resource | Sync | Provision |
|---|---|---|
| Accounts | ||
| Groups | ||
| Folders | ||
| Roles | ||
| Projects | ||
| Organizations | ||
| Workforce Identity pools* | ||
| Workforce Identity pool providers* | ||
| Secrets - API keys | ||
| Secrets - Service account keys |
Gather Google Cloud Platform with Google Workspace credentials
Configuring the connector requires you to pass in credentials generated in Google Cloud Platform with Google Workspace. Gather these credentials before you move on.Create a new project
As a Google Cloud Platform with Google Workspace Super Admin, sign in to https://console.cloud.google.com.
Create a new project for your organization:
- Project Name: Choose a names, such as “ConductorOne Integration”
-
Organization/Location: Choose the appropriate Organization/Location

Enable the API
Create a service account
Under Service account details, fill in the following:
- Service account name: ConductorOne Integration
- Service account description: for example, “Service account for ConductorOne Google Cloud Platform with Google Workspace Integration”
Under Grant this service account access to a project, grant the following permissions to either the Editor role or a custom role on the org level, and assign that role to the service account:
You’ll need these permissions to give ConductorOne READ access (syncing access data):You’ll need these permissions to give ConductorOne READ/WRITE access (syncing access data and provisioning access):
Get credentials
Add the service account to Google Cloud Platform with Google Workspace
Go to https://admin.google.com as a SUPER ADMIN.
Click Add new and fill out the form:
- Client ID: The saved ID
-
OAuth Scopes: Copy and paste in the relevant scopes
-
Use the following scopes to give ConductorOne READ access (syncing access data):
-
Use the following scopes to give ConductorOne READ/WRITE access (syncing access data and provisioning access):
-
Use the following scopes to give ConductorOne READ access (syncing access data):
Locate your primary domain
That’s it! Next, move on to the connector configuration instructions.
Configure the Google Cloud Platform with Google Workspace connector
- Cloud-hosted
- Self-hosted
Follow these instructions to use a built-in, no-code connector hosted by ConductorOne.That’s it! Your Google Cloud Platform with Google Workspace connector is now pulling access data into ConductorOne.
Choose how to set up the new Google Cloud Platform with Google Workspace connector:
- Add the connector to a currently unmanaged app (select from the list of apps that were discovered in your identity, SSO, or federation provider that aren’t yet managed with ConductorOne)
- Add the connector to a managed app (select from the list of existing managed apps)
- Create a new managed app
Set the owner for this connector. You can manage the connector yourself, or choose someone else from the list of ConductorOne users. Setting multiple owners is allowed.If you choose someone else, ConductorOne will notify the new connector owner by email that their help is needed to complete the setup process.
In the Administrator email field, enter the email address associated with your domain or a super admin.
Optional. Uncheck the box (which is checked by default) if you want to sync Google Cloud Platform default projects.
Optional. In the Project IDs field, enter a list of project IDs to limit the connector’s sync to only those projects. Be sure to enter project IDs, not project names.
Optional. Check the box to Enable Workforce Identity Federation, which allows the connector to sync Workforce Identity pools and pool providers.
- If you want the connector to provision Workforce Identity pools, enter the relevant Workforce Identity Pool ID and Workforce Identity Pool Provider ID in the relevant fields.
By default, the connector only syncs roles that are assigned to an IAM policy. These settings allow you to configure the connector to sync roles regardless of their IAM policy status.
- Optional. Check the box to Always sync custom roles.
- Optional. In the List of role IDs to always sync field, enter a list of role IDs that should be synced. Be sure to enter role IDs, not role names.
If enabling Workforce Identity Federation, complete these additional steps:
- In the Shared identity source area of the page, click Edit.
- Select the connector from which you want to pull identities.
- Optional. Limit the identities pulled from the connector you selected to only those with a certain entitlement by setting the entitlement.
- Click Save.












