Connect Google Workspace to Black Cat SSPM
Connect your Google Workspace so Black Cat can review users, two-step verification, admin roles, groups, OAuth applications, Drive sharing and Gmail settings.
≈ 15 min · audit access · write-capable permissions are flagged below
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
https://www.googleapis.com/auth/admin.directory.user.readonly | Lets Black Cat list users, their admin status, last login and two-step verification. | Required |
https://www.googleapis.com/auth/admin.directory.group.readonly | Lets Black Cat list groups and their membership. | Required |
https://www.googleapis.com/auth/admin.directory.domain.readonly | Lets Black Cat check that your domains are verified and that DKIM is configured. | Required |
https://www.googleapis.com/auth/admin.directory.user.security | Lets Black Cat see each user's security settings, including app passwords and authorised OAuth applications. The write side of this permission is not used. | Optional Write (write-capable permission) |
https://www.googleapis.com/auth/gmail.settings.basic | Lets Black Cat review mail forwarding and delegation settings — never message contents. The write side of this permission is not used. | Optional Write (write-capable permission) |
https://www.googleapis.com/auth/cloud-identity.inboundsso.readonly | Lets Black Cat see whether single sign-on is configured for your organization. | Optional |
https://www.googleapis.com/auth/apps.groups.settings | Lets Black Cat review group settings such as external membership, open joining and public conversations. The write side of this permission is not used. | Optional Write (write-capable permission) |
https://www.googleapis.com/auth/apps.licensing | Lets Black Cat see which licences, Gemini included, are assigned to your users. The write side of this permission is not used. | Optional Write (write-capable permission) |
https://www.googleapis.com/auth/drive.readonly | Lets Black Cat review Drive sharing settings on personal and shared drives — file metadata only, never file contents. | Optional |
https://www.googleapis.com/auth/admin.reports.audit.readonly | Lets Black Cat review admin and login activity for dormant accounts and administrative changes. | Optional |
https://www.googleapis.com/auth/cloud-identity.policies.readonly | Lets Black Cat review organization policies such as data protection and application access rules. | Optional |
What you'll need
- Customer identifier Required — Shown in the Google Admin console under Account settings.
- Service account key (JSON) Required — The JSON key of the read-only service account you create for Black Cat.
- Administrator email Required — The super administrator whose access Black Cat borrows to read directory settings.
Where to create it
- Setup guide (Google Workspace) ↗ (opens in new tab)
- Developer documentation (Google Workspace) ↗ (opens in new tab)
What we check on Google Workspace →