Home Admin & Settings Managing Users and Syncing Specific OUs

Managing Users and Syncing Specific OUs

Last updated on Jul 10, 2026

Managing Users and Syncing Specific OUs

Once Google Workspace is connected, KyberGate can sync your users automatically. By default it syncs your entire organization — but most schools want to sync only certain organizational units (OUs), for example students and staff but not service accounts, shared mailboxes, or test accounts.

This guide covers managing users and scoping both user sync and KyberPulse monitoring to specific OUs.

Prerequisite: Google Workspace must be connected and delegation verified. See Google Workspace Integration. OU scoping also requires the admin.directory.orgunit.readonly scope (included in the standard setup).

How Users Get Into KyberGate

There are three ways users appear in KyberGate:

  1. Google Workspace sync (recommended) — automatic, every 6 hours
  2. Clever / ClassLink — via SSO roster sync
  3. Manual — add users individually under the Users tab

Once a user exists in KyberGate and signs into a device, KyberGate matches the device to that user and applies the user's policy.

Viewing Synced Users

On the Settings → Workspace page, the Users tab lists everyone synced, with their name, email, OU, and role (student / staff / teacher). Use the search box to find a specific user by name, email, or OU.

Roles are inferred from the OU path — e.g. a user under /Students is tagged as a student, and one under /Staff or /Teachers as staff. You can adjust role mapping under Role Mapping on the Overview tab.

Syncing Only Specific OUs

This is the key setting for keeping your user list clean.

  1. Go to Settings → Workspace and open the OU Scope tab
  2. You'll see a list of your Google Workspace OUs, each with two checkboxes:
    • Sync users — import users from this OU into KyberGate
    • Monitor (Pulse) — include this OU in KyberPulse safety scanning
  3. Check Sync users for only the OUs you want (e.g. /Students, /Staff)
  4. Click Save OU Scope

The next sync will import only users in the selected OUs. Existing users outside those OUs are left as-is; new users outside them won't be added.

Leave everything unchecked to include all OUs. An empty selection means "sync the entire organization." Checking specific OUs narrows it to just those.

How OU matching works (prefix-based)

OU selection is prefix-based. Selecting /Students includes every sub-OU beneath it — /Students/Grade 3, /Students/Grade 4, and so on. You don't need to check each grade individually; check the parent and all children are included.

If you don't see an OU you expect, click Refresh OU list to pull the latest tree from Google. (This requires verified delegation.)

Scoping KyberPulse Monitoring to Specific OUs

You often want to sync more users than you monitor. For example, sync all students and staff, but only run KyberPulse safety scanning on students.

On the same OU Scope tab, use the Monitor (Pulse) column:

  1. Check Monitor (Pulse) for only the OUs you want scanned (e.g. /Students)
  2. Leave staff or test OUs unchecked
  3. Click Save OU Scope

KyberPulse email and document scanning will then only cover users in the selected OUs. As with sync, an empty selection means "monitor all student OUs."

Example: Check Sync users on /Students and /Staff, but only check Monitor (Pulse) on /Students. Result: staff and students are both in KyberGate for filtering and reporting, but only students' Gmail/Docs are scanned by KyberPulse.

Running a Sync

  • Click Sync Now on the Workspace page to sync immediately
  • KyberGate also syncs automatically every 6 hours
  • After a scoped sync, the result shows how many users were imported and how many were skipped by your OU filter

Adding or Removing Users Manually

  • Add: Users tab → add a user with email, name, and role
  • Remove: withdrawn users are deactivated automatically on the next sync if they're removed from Google Workspace

Troubleshooting

OU list is empty

  • Confirm delegation is verified and the admin.directory.orgunit.readonly scope is authorized
  • Click Refresh OU list

I synced the whole org by accident (service accounts, etc.)

  • Set the correct OUs under OU Scope → Sync users and Save. Users outside the selected OUs won't be re-added on the next sync. To remove already-imported users, deactivate or delete them on the Users tab.

A student's policy isn't following them across devices

  • Confirm the user is synced (Users tab) and that your filter mode is User-based or Both (Settings → Filtering)

KyberPulse is scanning the wrong group

  • Check the Monitor (Pulse) column on the OU Scope tab — only the checked OUs are scanned (or all student OUs if none are checked)

Related Articles

  • Google Workspace Integration
  • Setting Up KyberPulse Notifications
  • Clever SSO Integration
  • ClassLink Integration

Need help? Open the live chat in your dashboard (bottom-right) — it goes to a real person on our team.