Google Workspace
Google Workspace (formerly G Suite) is a collection of cloud computing, productivity, and collaboration tools developed by Google. Connecting Google Workspace to Harmony enables automated user provisioning, intelligent license optimization, and seamless access management across your Google ecosystem.
The integration uses secure OAuth-based authentication to establish and maintain the connection between your Google Workspace account and Harmony. Once connected, Harmony automatically saves your credentials and keeps your data in sync - no manual steps required.
What the Google Workspace integration enables
User Provisioning
Automate user lifecycle management across Google services
License Management
Track and optimize Google Workspace licenses to reduce costs
Group Management
Sync organizational units and groups for access control
Application Discovery
Identify all Google Workspace apps, SAML apps, and OAuth integrations
Automation Workflows
Build custom workflows using the Google Workspace Admin API
Multi-Tenant Support
Connect up to two Google Workspace tenants and automate across both of them
Prerequisites
Before connecting Google Workspace to Harmony, ensure you have:
Google Workspace Super Admin access
A Harmony account with admin privileges
Connect Google Workspace
Navigate to Integrations
Log into your Harmony dashboard
Navigate to Settings → Integrations
Find Google Workspace under Identity Provider
Click Connect

Navigate to Google Workspace integration in Harmony dashboard Authorize Google Workspace
You'll be redirected to Google to authorize the connection
Sign in with your Google Workspace Super Admin account
Review the requested permissions
Click Allow to authorize
You'll be redirected back to Harmony

Google Workspace authorization dialog Once you complete the OAuth authorization flow, Harmony automatically receives and stores your integration credentials - no additional configuration is needed to activate the connection.
Verify Connection
Confirm that Google Workspace shows Connected status in your Harmony integrations page.
Connect Multiple Google Workspace Tenants
If your organization operates more than one Google Workspace environment, you can connect multiple tenants to Harmony and manage them all from a single place. This removes the previous limitation of one connection per provider and enables cross-tenant automation for workflows like offboarding.
Harmony supports up to two Google Workspace connections per organization.
To add an additional tenant:
Navigate to Settings → Integrations
Find Google Workspace and click Add Another
Complete the OAuth authorization flow using the Super Admin account for the additional tenant
Give the connection a custom display label (for example, "Google Workspace - Primary" or "Google Workspace - Legacy") so each tenant is easy to identify
Each tenant connection has its own credentials and label, and you can build automation workflows that span all connected tenants.
Approve Harmony in App Access Control
If your Google Workspace organization restricts third-party app access, you need to explicitly approve Harmony before users can sign in with Google.
Navigate to App Access Control
In your Google Admin Console, go to Security → API Controls → App Access Control.
Configure a new app
Click Configure new app (labeled 1 in the screenshot below).

App Access Control - Configure new app Search for Harmony by App ID
In the Configure new app dialog, search for Harmony using its Application ID:

Configure new app - search by App ID Select Harmony from the results and complete the configuration
Follow the remaining steps (Scope → Access to Google Data → Review) and set access to Trusted for the relevant organizational units.
What Harmony Syncs from Google Workspace
Once connected, Harmony automatically syncs:
Users
User profiles (name, email, photo)
User status (active, suspended, archived)
Organizational units and departments
Manager relationships
Last login and creation dates
License assignments
2-Step Verification status
Groups
Group names and descriptions
Group members and managers - including users who belong to the group through nested or indirect group relationships (transitive memberships are resolved automatically)
Group settings and permissions
Distribution lists
Harmony syncs data every 24 hours by default.
Application Discovery
Harmony automatically discovers applications connected to your Google Workspace environment, giving you a complete picture of your SaaS and application landscape without any manual inventory work.
OAuth and SSO Apps
Third-party and internal applications authorized via OAuth in your organization are automatically collected and appear alongside your other discovered software in Harmony's Software Discovery.
SAML Apps
Google Workspace SAML-based applications are now discovered automatically alongside OAuth apps. Harmony ingests SAML login activity from the Google Admin Reports API to surface these applications and their users.
SAML-connected apps appear as application instances in the Instances & Manage tab
Each instance shows the users who have authenticated via SAML SSO
Previously, Harmony could only discover apps granted via OAuth tokens. SAML apps had no discovery path and created a blind spot in your application inventory - this is now resolved automatically.
Group Membership Management
When using the Group Membership Management request type, you can search for Google Workspace groups by either display name or email address.
Searching by a full email address (for example,
engineering@company.com) will correctly match and return the corresponding groupThe
@and.characters in email addresses are handled correctly throughout the searchPreviously, groups could only be found by display name, which made it difficult to locate the right group when only the group's email address was known
Reliability Improvements
Harmony includes several improvements to keep your Google Workspace data accurate and up to date:
Automatic retries for Google API errors - When Google returns temporary service unavailability errors, Harmony automatically retries the request, reducing the chance of missing data due to transient outages on Google's side.
More reliable out-of-office sync - The Google Calendar out-of-office sync process handles employee data more efficiently in the background, reducing the risk of memory-related failures or interruptions during scheduled syncs. Out-of-office statuses are less likely to be delayed or missing, particularly for organizations with large numbers of employees.
Troubleshooting
Best Practices
Need help? Contact support@harmony.io for assistance with your Google Workspace integration.
Data & Privacy
Last updated
Was this helpful?
