Required Permissions

Note
When the connector is configured using client credentials, the refresh token holds the scopes and permissions.

The necessary permissions to manage Google Workspace connector are : 

  • Roles assigned to an Impersonated user on the Google managed system.

  • Permissions assigned to Service Account Scopes.

Important
The impersonated user should be the IAM User and not the Service Account.

To perform necessary connector operations, refer to the following for minimum Service Account Scopes and Roles for Impersonate User:

Additional Permissions for SailPoint Non-Human Identity (NHI) Discovery

The following GCP configuration is required when you enable SailPoint Non-Human Identity (NHI) Discovery on the Google Workspace SaaS connector. Grant only the roles and APIs that correspond to the features you plan to use. For supported features, refer to Supported Features.

Important
SailPoint NHI Discovery requires Service Account authentication grant type only.

SailPoint recommends assigning the Viewer and Organization Viewer roles to the SailPoint service account at the organization level. The following table lists additional GCP IAM roles you can assign for least-privilege access by features:

Features

GCP IAM roles

Continuous secret discovery

Secret Manager Viewer, Secret Manager Secret Accessor, API Keys Viewer, Cloud Functions Viewer

IAM monitoring

Cloud Asset Viewer, View Service Accounts, IAM Recommender Viewer, Activity Analysis Viewer, Organization Role Viewer, Folder Viewer

Compliance validation

Logs Viewer, Logs View Accessor, Private Logs Viewer, Security Reviewer