Google Cloud project
APIs enabled: Gmail API and Admin SDK Directory API. OAuth redirect URI: https://app.himaya.ai/api/onboarding/callback/google.
This guide walks a Google Workspace super admin through connecting Helios and enabling domain-wide delegation (DWD) — the setting that lets Helios scan and remediate every mailbox in your org, not just the admin’s.
There are two parts:
In Helios, go to Settings → Integrations and click Connect Google Workspace.
Sign in with a super admin account and approve the consent screen. Helios requests these OAuth scopes:
| Scope | Why |
|---|---|
openid, email | Identify the admin and your domain |
https://www.googleapis.com/auth/gmail.modify | Move/label mail during quarantine |
https://www.googleapis.com/auth/admin.directory.user.readonly | Discover the mailboxes in your org |
https://www.googleapis.com/auth/admin.directory.group.readonly | Resolve group membership |
You’ll be redirected back to Helios. The integration now shows Active and your mailbox count begins populating.
This is the critical step. Without it, Helios can only see the admin mailbox.
Open the Google Admin console at admin.google.com as a super admin.
Go to Security → Access and data control → API controls → Domain-wide delegation → Manage Domain Wide Delegation.
Click Add new and enter the Helios service account Client ID:
114733393163502940734In OAuth scopes, paste the following comma-separated list exactly:
https://www.googleapis.com/auth/gmail.modify,https://www.googleapis.com/auth/gmail.settings.basic,https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.user.securityClick Authorize.
| Scope | Purpose |
|---|---|
gmail.modify | Move messages out of the inbox to quarantine, apply/remove labels |
gmail.settings.basic | Read/write inbox filters (Inbox Posture checks) |
admin.directory.user.readonly | List all users to enumerate mailboxes |
admin.directory.user.security | Inspect per-user OAuth app tokens (posture) |
Helios has a built-in check. After authorizing DWD (allow a few minutes for Google to propagate):
If it reports DWD not enabled — only admin mailbox will be scanned, re-check that the Client ID and all four scopes were entered exactly, then retry.
Google Cloud project
APIs enabled: Gmail API and Admin SDK Directory API. OAuth redirect URI: https://app.himaya.ai/api/onboarding/callback/google.
Quarantine label
Quarantined mail is moved under the HELIOS_QUARANTINE label, created automatically on first use.
Deploy the Gmail Add-on
Let employees report suspicious mail in one click — see Report Add-ons.
Set up policies
Configure automated actions in Policies.