The connected Google account does not have permission to read the Google Workspace directory. Reconnect using a Google Workspace administrator account with directory read access.
Google Workspace Integration
Connecting Google Workspace lets you sync users from your Google directory into CalmCompliance. Map organisation units (OUs) to sites and permissions, then run an import so new staff appear with the right access.
How to connect and use Google Workspace
Connect Google Workspace from site settings, map organisation units, then start an import.
Go to Settings > Integrations.
Find the Google Workspace card and click Connect.
Sign in with a Google Workspace administrator account that can read the directory, and approve the requested access.
After connecting, click Configure to open the integration settings.
Open the Org Unit Mapping tab and map each Google organisation unit to your site and permissions (Member, Manager, or Admin per module).
Optionally open the Exclusions tab to exclude email patterns (for example system accounts or shared mailboxes).
Click Start Import to sync users from Google into CalmCompliance.
Users are created or updated from the mapping. Run Start Import again anytime to refresh the sync.
Right after you connect, the Connection tab shows Verifying Connection while CalmCompliance checks that the account can read users and organisational units. When the check succeeds, the status becomes Connected and Healthy.
Check connection status
Open Settings > Integrations, then Configure on the Google Workspace card, and review the Connection tab.
Verifying Connection — Google Workspace is connected. CalmCompliance is checking that the account can read users and organisational units.
Connected and Healthy — Google Workspace permissions were verified successfully.
Connection Needs Attention — Sync is blocked by a permissions or connection problem. The page shows the specific error and tells you to disconnect and reconnect after you fix Google Workspace permissions.
Connected — The integration is linked, but a successful permission check has not been recorded yet.
If Google Workspace is only temporarily unavailable, CalmCompliance retries the sync automatically. That situation is separate from Connection Needs Attention, which means you need to fix permissions or reconnect.
Fix connection problems
When the Connection tab shows Connection Needs Attention, read the error message, correct the Google Workspace side, then Disconnect and reconnect the integration.
Connected account cannot read the directory
Google Workspace policy is blocking CalmCompliance
Google Workspace policy is blocking CalmCompliance. In the Google Admin console, go to Security, API controls, and App access control, allow the OAuth app, then reconnect the integration.
Required directory permissions were not approved
The Google connection is missing required directory permissions. Reconnect Google Workspace and approve all requested access.
Connection is no longer valid
The Google Workspace connection is no longer valid. Reconnect the integration to resume user sync.
Status stays on Verifying Connection
A newly connected integration starts in Verifying Connection until a sync run succeeds or fails. Stay on the Connection tab and wait for the status to update. If it moves to Connection Needs Attention, use the error message and the fixes above.
Owner notifications for connection issues
When a new Google Workspace connection problem starts that blocks sync, organisation owners receive a Google Workspace Connection Issue notification in their inbox and by email.
The notification explains that CalmCompliance could not sync Google Workspace users for the affected site and includes the error message. Use Review Integration to open the integration settings, fix the cause, then disconnect and reconnect.
Owners are notified when a new problem begins. Repeated failures of the same issue do not send another notification.
Before you start
You need the Admin role for your site to connect and configure Google Workspace. If your organisation uses a Trust site with child sites, configure Google Workspace at the parent (Trust) site—child sites inherit the sync.
On a child site, configuration is only available at the Trust site. Switch to the Trust site, or use Go to Trust Site Configuration from the integrations page.
Common questions
What data is synced?
User names, email addresses, and organisation unit membership. The sync creates or updates users and assigns them to groups and sites according to your mapping.
Can I exclude certain users?
Yes. Use the Exclusions tab to add email patterns (for example *noreply* or *bot*). You can also use auto-detect to suggest system accounts to exclude.
Where do I see the import history?
Open the Import Log tab to view audit events for discovery, import runs, user creation, and any errors.
What if I am on a child site?
Google Workspace is configured at the parent site. Switch to the Trust site to connect and configure, or use Go to Trust Site Configuration from the integrations page.
Why did I get a Google Workspace Connection Issue notification?
Organisation owners receive this when CalmCompliance cannot sync Google Workspace users because of a connection problem that needs fixing, such as missing admin access, blocked app policy, missing permissions, or an invalid connection. Open Review Integration, read the error on the Connection tab, fix the Google Workspace side, then disconnect and reconnect.