Skip to content

Connect Google Workspace

This guide walks a Google Workspace super admin through connecting Helios and enabling domain-wide delegation (DWD) — the setting that lets Helios scan and remediate every mailbox in your org, not just the admin’s.

There are two parts:

  1. Connect — the admin signs in via OAuth in Settings → Integrations. This authorizes Helios and discovers your users.
  2. Delegate — you authorize the Helios service account for domain-wide delegation with a specific set of scopes, so Helios can act on behalf of each user’s mailbox.
  1. In Helios, go to Settings → Integrations and click Connect Google Workspace.

  2. Sign in with a super admin account and approve the consent screen. Helios requests these OAuth scopes:

    ScopeWhy
    openid, emailIdentify the admin and your domain
    https://www.googleapis.com/auth/gmail.modifyMove/label mail during quarantine
    https://www.googleapis.com/auth/admin.directory.user.readonlyDiscover the mailboxes in your org
    https://www.googleapis.com/auth/admin.directory.group.readonlyResolve group membership
  3. You’ll be redirected back to Helios. The integration now shows Active and your mailbox count begins populating.

This is the critical step. Without it, Helios can only see the admin mailbox.

  1. Open the Google Admin console at admin.google.com as a super admin.

  2. Go to Security → Access and data control → API controls → Domain-wide delegationManage Domain Wide Delegation.

  3. Click Add new and enter the Helios service account Client ID:

    114733393163502940734
  4. In OAuth scopes, paste the following comma-separated list exactly:

    https://www.googleapis.com/auth/gmail.modify,https://www.googleapis.com/auth/gmail.settings.basic,https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.user.security
  5. Click Authorize.

ScopePurpose
gmail.modifyMove messages out of the inbox to quarantine, apply/remove labels
gmail.settings.basicRead/write inbox filters (Inbox Posture checks)
admin.directory.user.readonlyList all users to enumerate mailboxes
admin.directory.user.securityInspect per-user OAuth app tokens (posture)

Helios has a built-in check. After authorizing DWD (allow a few minutes for Google to propagate):

  1. Go to Settings → Integrations → Google Workspace.
  2. Click Test domain-wide delegation.
  3. A green DWD active result means Helios successfully listed your directory and impersonated a non-admin mailbox.

If it reports DWD not enabled — only admin mailbox will be scanned, re-check that the Client ID and all four scopes were entered exactly, then retry.

Google Cloud project

APIs enabled: Gmail API and Admin SDK Directory API. OAuth redirect URI: https://app.himaya.ai/api/onboarding/callback/google.

Quarantine label

Quarantined mail is moved under the HELIOS_QUARANTINE label, created automatically on first use.

Deploy the Gmail Add-on

Let employees report suspicious mail in one click — see Report Add-ons.

Set up policies

Configure automated actions in Policies.