Collects account security, external sharing activity, and administrator evidence from Google Workspace.
AvailableRead-only collection
What vCISO.ai observes
Two step verification report
External sharing activity
User account inventory
Admin audit log
Authorization and permissions
Google Workspace delegated OAuth
Admin Directory user read-only
Admin role-management read-only
Admin Reports audit read-only
Setup path
Setup remains administrator-controlled inside the authenticated workspace.
Authorize with a Google Workspace administrator
Grant the listed read-only scopes
Complete the first directory and reports collection
Review the checks and proposed evidence
Collection limitations
A limited or failed read stays visible and never becomes a passing result.
Collection covers only the directory and Reports API slices implemented by the connector
Pagination and reporting windows follow supported collection limits
Incomplete collection never becomes a passing result
Disconnect and deletion behavior
An administrator can disconnect the integration. Stored tokens are removed locally, Google revocation is attempted, and connector-derived evidence is expired.
Existing historical records remain available as review history
Connector-derived evidence is marked expired when the source is disconnected
Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Google Workspace does not automatically verify a control, complete a framework, or produce an audit conclusion.
Start with the roadmap
Put Google Workspace into a prioritized readiness plan.
Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.