Google Workspace Integration
Connecting Google Workspace lets KyberGate automatically sync your students and staff, apply per-user policies, match devices to the signed-in user, and (optionally) run KyberPulse email and document safety scanning.
This guide covers the full setup: connecting your domain, authorizing domain-wide delegation, verifying it, and running your first sync. To limit the sync to specific organizational units, see Managing Users and Syncing Specific OUs.
What You Get
- Automatic roster sync — students and staff sync from Google Workspace every 6 hours
- Per-user policies — a student's policy follows them across devices
- Device-to-user matching — Chromebooks and other devices show the signed-in user
- OU-based scoping — sync and monitor only the OUs you choose
- KyberPulse scanning (optional) — scan student Gmail and Google Docs for safety signals
Before You Begin
- You need Super Admin in Google Workspace (to authorize delegation)
- You need the Admin role in KyberGate
- Have your Google Workspace domain ready (e.g.
school.edu) and a Workspace admin email to run the sync as
Step 1: Connect Your Domain
- In your dashboard, go to Settings → Workspace (or Integrations → Google Workspace)
- Enter your Domain (e.g.
school.edu) and your Admin Email - Click Connect Workspace
At this point your domain is saved, but the connection badge will show "Delegation pending" — KyberGate can't read your directory yet. That's expected. The next step authorizes it.
Why "Delegation pending"? The badge only turns green ("Connected") once KyberGate can actually read your directory. Saving a domain alone doesn't grant access — you must authorize domain-wide delegation in Google Admin (Step 2). This prevents a misleading "Connected" state where no users can actually sync.
Step 2: Authorize Domain-Wide Delegation
KyberGate uses manual domain-wide delegation (rather than a one-click OAuth) because it gives you precise control over exactly which permissions you grant.
Open the Setup tab on the Workspace page — it shows your organization's exact values with copy buttons. Then:
-
Go to Google Admin → Security → Access and data control → API Controls → Domain-Wide Delegation (Direct link:
https://admin.google.com/ac/owl/domainwidedelegation) -
Click Add new
-
Paste the Client ID:
103445766148940749130 -
Paste the OAuth scopes (comma-separated). It will look like one long line until you click Authorize, which separates them:
https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/gmail.readonly,https://www.googleapis.com/auth/drive.readonly -
Click Authorize
What each scope does
| Scope | Purpose | Required? |
|---|---|---|
admin.directory.user.readonly |
Read users for roster sync | Required |
admin.directory.orgunit.readonly |
Read your OU tree (for OU-scoped sync) | Required |
gmail.readonly |
KyberPulse email scanning | Optional |
drive.readonly |
KyberPulse document scanning | Optional |
If you don't plan to use KyberPulse email/document scanning, you can omit the last two scopes. You can always add them later.
Step 3: Verify Delegation
Back in KyberGate, on the Workspace page:
- Click Verify Delegation
- The connection badge turns green ("Connected") once KyberGate confirms it can read your directory
- If it still shows "Delegation pending," the badge will display the specific error — usually the Client ID or a scope was mistyped, or Google hasn't finished propagating (wait a couple of minutes and try again)
Step 4: Sync Your Users
- Click Sync Now (available once delegation is verified)
- KyberGate imports your users, their names, roles, and organizational units
- Users then appear under the Users tab and sync automatically every 6 hours going forward
By default, KyberGate syncs your entire organization. To sync only certain OUs (for example, students but not service accounts), see Managing Users and Syncing Specific OUs.
Filter Modes
Once users are synced, you can apply policies by user, not just by device:
- Device-based — policy follows the device
- User-based — policy follows the student across devices
- Both — device baseline plus per-user overrides (recommended)
Set this under Settings → Filtering.
KyberPulse Scanning (Optional)
If you added the gmail.readonly and drive.readonly scopes, you can enable student safety scanning on the KyberPulse Scanning tab:
- Email Scanning — scans student Gmail every 15 minutes for safety signals
- Document Scanning — scans Google Docs, Sheets, and Slides every 30 minutes
You can limit scanning to specific OUs — see Managing Users and Syncing Specific OUs.
Troubleshooting
Badge stuck on "Delegation pending"
- Recheck the Client ID and scopes in Google Admin — a single wrong character breaks it
- Confirm you authorized with a Super Admin account
- Wait 1–2 minutes for Google to propagate, then click Verify Delegation again
"Sync requires domain-wide delegation" when clicking Sync Now
- Delegation isn't verified yet. Complete Step 2 and click Verify Delegation first.
Users synced but no OUs show
- Confirm the
admin.directory.orgunit.readonlyscope was included, then click Refresh OU list on the OU Scope tab.
Devices show a generic name instead of the student
- The device shows the signed-in user once the roster is synced and the user signs in. Confirm the user exists under the Users tab.
Related Articles
- Managing Users and Syncing Specific OUs
- Clever SSO Integration
- ClassLink Integration
- Setting Up KyberPulse Notifications
Need help? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.