← All integrations
Identity · integration
Google Workspace
2-Step Verification, super-admin hygiene, stale accounts and deprovisioning for Google Workspace.
ISO 27001SOC 2PCI DSSDPDPARBISEBI CSCRFIRDAI
What ProofLayer proves
Read-only evidence, evaluated against versioned rules.
- All users are 2SV-enrolled and admins have 2SV enforced
- Super-admins are limited, idle accounts are suspended, and departed people are deprovisioned
Configure in ProofLayer
Live in minutes.
- Connections → New connection → pick this provider and name the account.
- Upload a service-account key (write-only) and the administrator email it should impersonate.
- Click Test connection — ProofLayer verifies read access from the control plane and reports a clear reason if anything is off.
- Set the scan schedule; every run appends to the evidence chain for this account.
- Choose the framework mapping(s) and, optionally, a push target (CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack).
Grant access from your side
Read-only, least-privilege, revocable.
You create the access in your own console and paste a credential ProofLayer stores sealed — it never writes to your systems.
- Create a service account with a JSON key and enable the Admin SDK API.
- In the Admin console, grant domain-wide delegation to the service account’s client ID with the read-only directory scopes.
- Name a read-only administrator for the service account to act as.
In-account agent option. Run the agent with the service-account key on your infrastructure; the key never leaves it. The collector posts evidence outbound-only, so ProofLayer holds no credential into your environment.