Sign InStart Free Trial

Connect Google Workspace

Vigil assesses Google Workspace against CISA's SCuBA Secure Configuration Baselines using ScubaGoggles. It connects through a read-only service account with domain-wide delegation — your super admin authorizes Vigil's service-account client ID and a fixed list of read-only scopes once, and Vigil never writes to your tenant.

What you need

  • A Google Workspace super admin to authorize the delegation (one-time).
  • Your Workspace primary domain (e.g. example.com).
  • An admin email on that domain for Vigil to read as (the service account impersonates this user; it must have admin privileges).

Steps

  1. In Vigil, go to Settings → Integrations and click Connect Google Workspace. The panel reveals your Client ID and the OAuth scopes — both non-secret, with copy buttons.
  2. In a new tab, open the Google Admin console → Security → Access and data control → API controls → Domain-wide delegation, and click Add new.
  3. Paste Vigil's Client ID into the Client ID field.
  4. Paste the full comma-separated scope list from the Vigil panel into the OAuth scopes field — copy it verbatim, do not trim it — then click Authorize.
  5. Wait 2–5 minutes for Google to propagate the delegation.
  6. Back in Vigil, enter your primary domain and the admin email to impersonate, then click Connect.
  7. Click Run check. The scan takes roughly 30 seconds and produces a verified, API-sourced posture assessment.

Troubleshooting: "unauthorized_client"

If a scan fails with unauthorized_client: Client is unauthorized to retrieve access tokens using this method, or client not authorized for any of the scopes requested, the scopes authorized in your Admin console do not exactly match the scopes Vigil requests.

Domain-wide delegation is all-or-nothing: if Vigil asks for even one scope that wasn't authorized, Google refuses the entire token request. Re-copy the complete scope list from the connect panel, replace the scopes on the existing delegation entry, and re-authorize. Also confirm the Client ID matches, and give it a few minutes to propagate.

The most common cause is a partial scope list — pasting a subset, or an older list from a previous version. Always copy the list straight from the Vigil connect panel, which is kept in sync with what the scanner actually requests.

What it covers

A Google Workspace scan contributes verified scores to your Identity & Access, Email Security, Data Protection, and Monitoring & Logging domains — one connection, several domains. Those domains then show as Verified in your posture, and blend into your single resolved grade.

Is it read-only?

Yes. Every scope Vigil requests is a .readonly Admin SDK scope (plus Groups Settings and Cloud Identity policy reads). Vigil reads configuration only — it never writes to, modifies, or stores credentials for your tenant.

Related

Connect Microsoft 365Connect AWSCoverage modes & how your grade is calculated
Stuck on something this doesn't answer?Email support