Resmo Documentation
SupportStatuspageTwitterLinkedIn
  • Welcome!
  • Getting Started
    • Quick Start Guide for Admins
    • SaaS Security Guide for Employees
    • Glossary
    • FAQ
    • Support
    • Resources documentation (automated)
  • Guides
    • Query Your First Resources
    • Create Your First Rule
  • Resources
    • Resources
    • Resource Changes
  • Notebooks
    • Notebooks
  • Audit Logs
    • Audit Logs
  • API
    • Basics
    • Query API
  • Resource Tags
    • Tag Rules
    • Manual Tagging
  • Queries
    • Query Types
    • Standard SQL Queries
    • Change SQL Queries
  • SaaS Discovery
    • SaaS Discovery Methods
    • Browser Extension Admin Guide
    • AI Email Scanning
    • Resmo Agent (Beta)
    • Apps Page
    • Users Page
  • Rules
    • Rules
    • Suppression
    • AWS Config Rules vs Resmo Rules
  • Dashboards
    • Dashboards
  • Packs (Compliance and Security Best Practices)
    • Packs
    • Pack Exports
  • Alerts
    • Alerts
  • Variables
    • Variables
  • integrations
    • Integrations Guide
    • Custom Data Integration
    • AWS Integration
    • Azure Integration
    • GCP Integration
    • Google Drive Integration
    • Kubernetes Integration
    • Google Workspace Integration
    • GitHub Integration
    • Slack Integration
    • GitLab Integration
    • New Relic Integration
    • Jira Integration
    • PagerDuty Integration
    • Opsgenie Integration
    • MongoDB Atlas Integration
    • Azure Active Directory Integration
    • Cloudflare Integration
    • Confluence Integration
    • Bitbucket Integration
    • Okta Integration
    • Datadog Integration
    • Gandi Integration
    • Snyk Integration
    • Duo Integration
    • Jamf Integration
    • Snowflake Integration
    • Heroku Integration
    • Fastly Integration
    • Hubspot Integration
    • BambooHR Integration
    • Azure DevOps Integration
    • Kolide Integration
    • Flyio Integration
    • Upstash Integration
    • Qualys Integration
    • Sentry Integration
    • Brex Integration
    • JumpCloud Integration
    • Webflow Integration
    • Tenable Integration
    • SonarCloud Integration
    • Salesforce Integration
    • LastPass Integration
    • Microsoft Teams Integration
    • Zendesk Integration
    • Segment Integration
    • Terraform Cloud Integration
    • Tailscale Integration
    • Vercel Integration
    • GoDaddy Integration
    • Kandji Integration
    • LaunchDarkly Integration
    • PlanetScale Integration
    • Zoom Integration
    • Jotform Integration
    • Auth0 Integration
    • Wizer Integration
    • Linear Integration
    • Figma Integration
    • Trello Integration
    • Mixpanel Integration
    • Trivy Integration
    • CSV Integration
    • DocuSign Integration
    • Tinybird Integration
    • MonoSign Integration
    • DigitalOcean Integration
    • Sophos Integration
    • Firebase Integration
    • MySQL Integration
    • PostgreSQL Integration
    • MongoDB Integration
    • ClickHouse Integration
    • Help Scout Integration
    • Intercom Integration
    • Atlassian Integration
    • Drata Integration
    • Hetzner Cloud Integration
    • Vanta Integration
    • Microsoft Intune Integration
    • Microsoft Defender Integration
    • Microsoft 365 Integration
    • NPM Integration
    • CrowdStrike Integration
    • 1Password Integration
    • Lucid Integration
    • OneDrive Integration
    • JetBrains Integration
    • Google Analytics Integration
    • Hexnode Integration
    • SendGrid Integration
    • WordPress Integration
  • Notifications
    • Notification Channels
    • Email Notification Channel
    • Slack Notification Channel
    • Webhook Notification Channel
    • Opsgenie Notification Channel
    • PagerDuty Notification Channel
    • Amazon SNS Notification Channel
    • Parny Notification Channel
    • Linear Notification Channel
    • Jira Notification Channel
    • Microsoft Teams Notification Channel
  • Plugins
    • Raycast
  • Users and Permissions
    • User
    • User Roles
    • RBAC (Role-Based Access Control)
      • Custom Roles and Policies
    • SSO - Social Login
  • Settings
    • Accounts
    • Billing Policy
    • Pricing
      • Resource Count Calculation
Powered by GitBook
On this page
  • Resmo + Google Workspace Integration Fundamentals
  • What does Resmo offer to Google Workspace users?
  • How does the integration work?
  • Available resources
  • Common queries and rules
  • Integration Walkthrough
  • How to install
  • How to grant domain-wide delegation access to your organization
  • How to uninstall
  • FAQ

Was this helpful?

  1. integrations

Google Workspace Integration

Guide for Resmo Google Workspace Integration

PreviousKubernetes IntegrationNextGitHub Integration

Last updated 1 year ago

Was this helpful?

Resmo + Google Workspace Integration Fundamentals

Resmo integrates with Google Workspace to make sure your asset landscape is safe and compliant.

What does Resmo offer to Google Workspace users?

  • Collect and visualize Google Workspace resources

  • Query assets like customers, domains, groups, users, tokens, and more

  • Set up rules for continuous security and compliance evaluation

  • Receive near real-time notifications when a rule breach occurs

  • Use conformance packs to automate security best practices and compliance checks

How does the integration work?

Resmo has an official OAuth application that you can install securely once you sign up for a Resmo account. Our application uses API calls to make the initial polling and receive existing resources.

  • API polling uses API calls to sync your Google Workspace assets with Resmo.

  • Exposing Audit reports over a channel let us track changes with actor information in real-time.

Available resources

Resmo Google Workspace integration collects users, groups, group members, tokens, role assignments, and more for unified monitoring on a single platform.

See the full list:

Common queries and rules

  • List users per assigned role

  • Identify users without a recovery phone number

  • Detect groups with content moderation permission for all users

  • Identify users with public SSH keys

  • See custom roles and privileges

Integration Walkthrough

How to install

  1. Create or log in to your Resmo account.

  2. Go to your Integrations page and select Google Workspace.

  3. Click the Add Integration button from the bottom right corner of the opening modal.

4. Once you click the Create button, you'll be redirected to the Google consent screen. You need to select all permissions and click the Continue button.

5. You are ready! Now you can start querying your Google Workspace resources!

Permissions and Resmo Resources

If you do not give permission View audit reports for your G Suite domain or you do not have that permission at your Google Workspace, Resmo will not be able to track changes with actor information in real-time.

You will be informed about the resources that are not eligible to be accessed by Resmo due to missing permissions on the integration page.

How to grant domain-wide delegation access to your organization

  • Go to Security > Access and data control > API Controls

  • Click Manage Domain Wide Delegation.

  • Click Authorize

How to uninstall

  • If you remove access to Resmo on Google Security, we don't delete the integration on our side, so you can continue seeing your resources and query them.

    • Coming Soon: We are working on adding a mark to show you that you deleted the integration and it is not receiving updates anymore.

  • If you delete the integration on Resmo, you need to remove access of Resmo at Google Security too. The automatic deletion is coming soon.

FAQ

Can I add my personal Gmail account?

No. You can not add your Gmail account since resources obtained from Google Workspace do not exist for personal Gmail Accounts.

I am not an admin of our Google Workspace, can I integrate it to the Resmo account anyway?

If you have at least View customer related information permission at your workspace, integration creation will succeed. You will be informed about the resources that are not eligible to be accessed by Resmo due to missing permissions on the integration page.

Tip: Use for comprehensive monitoring of all Google Workspace activities and system events.

Resmo requires at least View customer related information permission to provide its functionality.

Resmo needs domain-wide delegation access to collect users' gmail settings in your organization. Yo can grant domain-wide delegation access for Resmo using following below steps. Visit official documentation for more .

Go to

Click Add new and enter Cliend Id: 109597776999965244120 Oauth Scopes:

You can remove access to Resmo from .

❗
Audit Logs
information
https://admin.google.com
https://www.googleapis.com/auth/gmail.settings.basic
Google Security
Google WorkspaceResource Directory
Google Workspace consent screen
Logo