Home Admin & Settings Google Workspace Integration

Google Workspace Integration

Last updated on Jul 10, 2026

Google Workspace Integration

Connecting Google Workspace lets KyberGate automatically sync your students and staff, apply per-user policies, match devices to the signed-in user, and (optionally) run KyberPulse email and document safety scanning.

This guide covers the full setup: connecting your domain, authorizing domain-wide delegation, verifying it, and running your first sync. To limit the sync to specific organizational units, see Managing Users and Syncing Specific OUs.

What You Get

  • Automatic roster sync — students and staff sync from Google Workspace every 6 hours
  • Per-user policies — a student's policy follows them across devices
  • Device-to-user matching — Chromebooks and other devices show the signed-in user
  • OU-based scoping — sync and monitor only the OUs you choose
  • KyberPulse scanning (optional) — scan student Gmail and Google Docs for safety signals

Before You Begin

  • You need Super Admin in Google Workspace (to authorize delegation)
  • You need the Admin role in KyberGate
  • Have your Google Workspace domain ready (e.g. school.edu) and a Workspace admin email to run the sync as

Step 1: Connect Your Domain

  1. In your dashboard, go to Settings → Workspace (or Integrations → Google Workspace)
  2. Enter your Domain (e.g. school.edu) and your Admin Email
  3. Click Connect Workspace

At this point your domain is saved, but the connection badge will show "Delegation pending" — KyberGate can't read your directory yet. That's expected. The next step authorizes it.

Why "Delegation pending"? The badge only turns green ("Connected") once KyberGate can actually read your directory. Saving a domain alone doesn't grant access — you must authorize domain-wide delegation in Google Admin (Step 2). This prevents a misleading "Connected" state where no users can actually sync.

Step 2: Authorize Domain-Wide Delegation

KyberGate uses manual domain-wide delegation (rather than a one-click OAuth) because it gives you precise control over exactly which permissions you grant.

Open the Setup tab on the Workspace page — it shows your organization's exact values with copy buttons. Then:

  1. Go to Google Admin → Security → Access and data control → API Controls → Domain-Wide Delegation (Direct link: https://admin.google.com/ac/owl/domainwidedelegation)

  2. Click Add new

  3. Paste the Client ID:

    103445766148940749130
    
  4. Paste the OAuth scopes (comma-separated). It will look like one long line until you click Authorize, which separates them:

    https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/gmail.readonly,https://www.googleapis.com/auth/drive.readonly
    
  5. Click Authorize

What each scope does

Scope Purpose Required?
admin.directory.user.readonly Read users for roster sync Required
admin.directory.orgunit.readonly Read your OU tree (for OU-scoped sync) Required
gmail.readonly KyberPulse email scanning Optional
drive.readonly KyberPulse document scanning Optional

If you don't plan to use KyberPulse email/document scanning, you can omit the last two scopes. You can always add them later.

Step 3: Verify Delegation

Back in KyberGate, on the Workspace page:

  1. Click Verify Delegation
  2. The connection badge turns green ("Connected") once KyberGate confirms it can read your directory
  3. If it still shows "Delegation pending," the badge will display the specific error — usually the Client ID or a scope was mistyped, or Google hasn't finished propagating (wait a couple of minutes and try again)

Step 4: Sync Your Users

  1. Click Sync Now (available once delegation is verified)
  2. KyberGate imports your users, their names, roles, and organizational units
  3. Users then appear under the Users tab and sync automatically every 6 hours going forward

By default, KyberGate syncs your entire organization. To sync only certain OUs (for example, students but not service accounts), see Managing Users and Syncing Specific OUs.

Filter Modes

Once users are synced, you can apply policies by user, not just by device:

  • Device-based — policy follows the device
  • User-based — policy follows the student across devices
  • Both — device baseline plus per-user overrides (recommended)

Set this under Settings → Filtering.

KyberPulse Scanning (Optional)

If you added the gmail.readonly and drive.readonly scopes, you can enable student safety scanning on the KyberPulse Scanning tab:

  • Email Scanning — scans student Gmail every 15 minutes for safety signals
  • Document Scanning — scans Google Docs, Sheets, and Slides every 30 minutes

You can limit scanning to specific OUs — see Managing Users and Syncing Specific OUs.

Troubleshooting

Badge stuck on "Delegation pending"

  • Recheck the Client ID and scopes in Google Admin — a single wrong character breaks it
  • Confirm you authorized with a Super Admin account
  • Wait 1–2 minutes for Google to propagate, then click Verify Delegation again

"Sync requires domain-wide delegation" when clicking Sync Now

  • Delegation isn't verified yet. Complete Step 2 and click Verify Delegation first.

Users synced but no OUs show

  • Confirm the admin.directory.orgunit.readonly scope was included, then click Refresh OU list on the OU Scope tab.

Devices show a generic name instead of the student

  • The device shows the signed-in user once the roster is synced and the user signs in. Confirm the user exists under the Users tab.

Related Articles

  • Managing Users and Syncing Specific OUs
  • Clever SSO Integration
  • ClassLink Integration
  • Setting Up KyberPulse Notifications

Need help? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.