Google Workspace Agent
Google Workspace in Switchboard. Review AI skills, playbooks, access limits and setup requirements before connecting your MSP systems.
How the Google Workspace integration works
Google Workspace is where your clients' identities live. Connect their domains and a session answers across all of them at once: who has an account, who's an admin, who never turned on 2-Step Verification, what licenses you're paying for, which phones and Chromebooks are enrolled, and what changed in the Admin console last week. Each domain is connected separately by its own super admin, and what a session may do there is exactly what that admin granted. Switchboard connects through an MSPStuff-hosted MCP server, so there's nothing to install and no API keys to hand your techs.
Hosted and external AI connections provide read-only access. Guidance, shared playbooks and automations we release for everyone are included with Dedicated. Bespoke automation builds are scoped separately. Any change a platform could make is held back — refused by our server before anything reaches the platform — until a person switches it on, and nothing is switched on today. Vendor consent does not switch any change on.
| Sample administrator | 2-step verification |
|---|---|
| alex@example.com | Missing |
| sam@example.com | Missing |
| jo@example.com | Enabled |
Read-only today. Any change the integration could make in Google Workspace is held back — refused by our server before anything reaches Google Workspace — until a person switches it on, and nothing is switched on today. A client's grant does not switch anything on; the per-domain grants the client's own super admin approves are a second fence beneath that refusal. Held back behind lifecycle-manage: a session could create, rename, suspend, unsuspend, sign out and move users, reset passwords, issue 2SV backup codes, create groups and org units, and add or remove group members. Behind licensing-manage it could assign, remove, and reassign license SKUs — and because Google ships no read-only licensing scope, that same grant is what makes license data readable at all. Behind device-manage it could approve or block mobile devices and disable, re-enable, or relocate ChromeOS devices. The destructive tier — deleting or restoring a user, remote-wiping a phone or its Workspace account, deprovisioning a Chromebook — is not in the recommended default, and even once switched on every call would be refused until the exact primary email or device id is echoed back.
What it can do
- UsersSearch and read the people in a domain — admin and suspended state, org unit, group memberships, and 2-Step Verification status, plus a domain-wide 2SV enrollment report. The lifecycle actions behind an onboard or an offboard sit here too.5skills
It reads and manages directory identity only — no mailbox, no Drive file, no message and no document is readable or writable from here. Temp passwords and backup codes are returned once and cannot be retrieved again afterwards.
Writes: With lifecycle-manage granted: creates accounts with a one-time temp password, edits name fields, suspends and unsuspends sign-in, resets passwords, signs a user out of every session, moves them between org units, and issues fresh 2SV backup codes. With lifecycle-destructive granted: permanently deletes an account, or restores one that was deleted.
- Find people in a client's domain by name or by the front of their email address.
- Open one person's record in full — admin rights, suspended state, 2SV enrollment and enforcement, org unit, and when they last signed in.
- Every group a person belongs to directly — memberships inherited through nested groups aren't expanded.
- Whether one person has 2-Step Verification switched on, and whether policy is forcing it on them.
- How much of a domain has 2-Step Verification, counted from the user directory rather than Reports — past 500 active users the figures come back marked as lower bounds instead of exact totals.
- GroupsDistribution lists and security groups: what exists, who's in each one, and one group's detail on its own.3skills
Membership is read and written one member at a time, directly — nested group membership isn't flattened, and group settings such as posting permissions or moderation aren't exposed.
Writes: With lifecycle-manage granted: creates a group at an address you choose, and adds or removes individual members at member, manager, or owner level.
- Every group in a client's domain, with its address, description, and how many members sit directly in it.
- One group's detail on its own — address, name, description, direct member count, and whether the domain created it.
- Who's directly inside a group, each with their role and membership status.
- Org unitsThe tree a domain's policy hangs off — read it, and add to it.1skills
It can read the tree and add to it, but cannot rename, move, or delete an existing org unit, and it does not read or set the policies attached to one.
Writes: With lifecycle-manage granted: creates a new org unit under a parent path you name.
- The whole org-unit tree for a domain, each unit with its path and parent — the structure every Workspace policy is applied against.
- LicensingSeat assignment across the Workspace editions, and what any individual holds. Google publishes no read-only licensing scope, so seeing license data at all takes the same grant as changing it — that's a Google constraint, not a choice made here.2skills
It probes a fixed list of current-generation Workspace editions plus Google Vault — legacy G Suite, Education, Cloud Identity, Gemini, and device SKUs are outside it. It cannot buy, cancel, or change the size of a subscription; assignment is only ever a move between seats you already own.
Writes: With licensing-manage granted: assigns a SKU to an existing user, removes one, and reassigns a user from one SKU to another within the same product.
- How many seats are assigned on each known Workspace edition, found by probing them one by one — a SKU past 500 assignments is reported as a lower bound, not an exact count.
- Which editions one person actually holds, checked against that same known-SKU list.
- DevicesMobile and ChromeOS hardware enrolled in a domain: model, OS, owner, serial, and last sync — plus the management actions that follow a lost phone or a returned Chromebook.4skills
It manages devices already enrolled — it cannot enroll one, push an app or a policy to one, or locate one. There is no manual sync action for mobile devices in Google's API at all, so none is offered here.
Writes: With device-manage granted: approves or blocks a mobile device, and disables, re-enables, or moves a ChromeOS device between org units. With device-destructive granted: factory-wipes a mobile device, wipes just the Workspace account off it, or deprovisions a Chromebook — permanent actions, each refused until the exact device id is echoed back.
- Every phone and tablet enrolled in a domain, with model, OS, type, owner, status, and when it last synced.
- One phone or tablet in full, down to its IMEI and serial number.
- Every enrolled Chromebook, with model, OS version, assigned user, location, serial, and last sync.
- A single Chromebook opened out — including its platform version and the org unit it currently sits in.
- Audit & securityThe record of what happened in a domain: sign-ins, Admin console changes, Drive access and sharing, usage counters, and Alert Center notices.5skills
Read-only, and it reports events rather than acting on them — it cannot dismiss or resolve an alert, and it cannot revoke a session or block an IP from here.
- Who signed in lately across a domain, with the actor and the source IP on every event.
- What administrators actually did in the Admin console — the change record behind a configuration surprise.
- File access and sharing activity across Drive, domain-wide — where an external-sharing question gets answered.
- Domain-level counters for a single day — seats, disabled accounts, license totals, mail sent, Drive items created — pulled from three days back by default, because the last day or two is usually still incomplete.
- What Alert Center has raised for a domain recently — the security notices that otherwise sit unread in a console nobody opens.
- Admin roles4skills
- List admin roles defined in the client's Workspace domain (built-in and custom).
- Get one admin role by id, including its granted privileges.
- List role assignments.
- Get one admin role assignment by id.
- Alerts more3skills
- Get alert.
- Get metadata for one alert (status, assignee, severity) without the full alert payload.
- List feedback (e.g. NOT_HARMFUL/USEFUL dispositions) logged against one alert.
- Chrome policy2skills
- List chrome policy schemas.
- Resolve the effective Chrome policy values applied to one org unit (read/query only — does not change any policy).
- Groups settings1skills
- Get one group's access/sharing settings: who can join, who can view membership/post, and whether external (outside-domain) members are allowed.
- OAuth tokens4skills
- List OAuth apps a user has granted access to (third-party and Google-native), with granted scopes.
- Get one OAuth grant for a user by client id, including its granted scopes.
- List a user's application-specific passwords (ASPs) — a security posture signal, since an ASP bypasses 2SV prompts for the app it was issued to.
- Get one of a user's application-specific passwords by code id.
- Reports more16skills
- Recent OAuth token grant/authorization events — which apps received access and to what, domain-wide.
- Recent account security events: password changes, 2SV enrollment changes, recovery-info changes, suspensions.
- Recent SAML single sign-on events.
- Recent Calendar events (event creation/sharing) across the domain.
- Get groups events.
- Recent enterprise Groups (Groups for Business) audit events.
- Recent Google Meet activity events across the domain.
- Recent Google Chat activity events across the domain.
- Get mobile activity events.
- Recent DLP/content-compliance rule trigger events.
- Recent context-aware access policy evaluation events.
- Get chrome activity events.
- Recent Google Cloud Platform admin activity, when Cloud Identity/GCP is linked to this Workspace customer.
- Get vault activity events.
- Recent Looker Studio (Data Studio) asset events.
- Recent Google Keep activity events.
- Vault4skills
- List Google Vault eDiscovery matters visible to the connected service account.
- Get one Vault matter by id, including its state (OPEN/CLOSED/DELETED).
- List legal holds within one Vault matter.
- Get one legal hold by id within a Vault matter — its scope (accounts/org unit), query, and corpus held.
How it has been taught to work it
Playbooks are the vetted techniques a session loads for this platform — what to check, in what order, and what a number means before it is reported.
- Google Vault eDiscovery matters & legal holds (not yet live)A client asks about legal holds, eDiscovery matters, or litigation-hold status in Google Vault. Read this before attempting any of these four tools — none of them work today.Vetted Sep 2, 2026
- Google Workspace 2SV & access review — MFA coverage, admins, suspended accounts, alertsHow secure is a client's Google Workspace, 2-step verification coverage, admin access, suspended-but-licensed accounts, security alerts, access review.Vetted Sep 2, 2026
- Google Workspace domain model (identity & productivity, per client tenant)Always when Google Workspace is attached. Its domain model — users/OUs/groups/licences/devices/2SV/audit — the per-client binding, the licensing-scope quirk, and the read-vs-write boundary.Vetted Sep 2, 2026Always on
- Querying Google Workspace — client resolution, the licensing-scope quirk, and audit windowsAlways when Google Workspace is attached. The read surface, resolving the client, how results come back, the license-scope quirk, and the audit-report windows.Vetted Sep 2, 2026Always on
