Skip to content

Connect Google Workspace to Black Cat SSPM

Version française

Connect your Google Workspace so Black Cat can review users, two-step verification, admin roles, groups, OAuth applications, Drive sharing and Gmail settings.

≈ 15 min · audit access · write-capable permissions are flagged below

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
https://www.googleapis.com/auth/admin.directory.user.readonlyLets Black Cat list users, their admin status, last login and two-step verification.Required
https://www.googleapis.com/auth/admin.directory.group.readonlyLets Black Cat list groups and their membership.Required
https://www.googleapis.com/auth/admin.directory.domain.readonlyLets Black Cat check that your domains are verified and that DKIM is configured.Required
https://www.googleapis.com/auth/admin.directory.user.securityLets Black Cat see each user's security settings, including app passwords and authorised OAuth applications. The write side of this permission is not used.Optional Write (write-capable permission)
https://www.googleapis.com/auth/gmail.settings.basicLets Black Cat review mail forwarding and delegation settings — never message contents. The write side of this permission is not used.Optional Write (write-capable permission)
https://www.googleapis.com/auth/cloud-identity.inboundsso.readonlyLets Black Cat see whether single sign-on is configured for your organization.Optional
https://www.googleapis.com/auth/apps.groups.settingsLets Black Cat review group settings such as external membership, open joining and public conversations. The write side of this permission is not used.Optional Write (write-capable permission)
https://www.googleapis.com/auth/apps.licensingLets Black Cat see which licences, Gemini included, are assigned to your users. The write side of this permission is not used.Optional Write (write-capable permission)
https://www.googleapis.com/auth/drive.readonlyLets Black Cat review Drive sharing settings on personal and shared drives — file metadata only, never file contents.Optional
https://www.googleapis.com/auth/admin.reports.audit.readonlyLets Black Cat review admin and login activity for dormant accounts and administrative changes.Optional
https://www.googleapis.com/auth/cloud-identity.policies.readonlyLets Black Cat review organization policies such as data protection and application access rules.Optional

What you'll need

  • Customer identifier Required — Shown in the Google Admin console under Account settings.
  • Service account key (JSON) Required — The JSON key of the read-only service account you create for Black Cat.
  • Administrator email Required — The super administrator whose access Black Cat borrows to read directory settings.

Where to create it

What we check on Google Workspace →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan