
Google Workspace
Every client domain — people, licenses, devices, and the admin record — in one conversation.
Google Workspace is where your clients' identities live. Connect their domains and a session answers across all of them at once: who has an account, who's an admin, who never turned on 2-Step Verification, what licenses you're paying for, which phones and Chromebooks are enrolled, and what changed in the Admin console last week. Each domain is connected separately by its own super admin, and what a session may do there is exactly what that admin granted.
The story
What changes once it’s connected.
The Admin console is fine for one domain. It's the twentieth that hurts — twenty logins, twenty user lists, twenty places to check whether the people who left in June still have mailboxes. Connect your clients' Workspace domains here and the question gets asked once: which admins across the whole book are missing 2-Step Verification, who hasn't signed in since spring, how many Business Standard seats are assigned against how many you're billing for.
The coverage tracks how Workspace is actually administered. Users with their admin, suspended, org-unit, and 2SV state, plus a domain-wide enrollment report; groups and their direct members; the org-unit tree that every policy hangs off; per-SKU license assignment counts and what a given person holds; mobile and ChromeOS devices with model, owner, and last sync; and the audit side — login events, Admin console activity, Drive access and sharing, usage counters, and whatever Alert Center has flagged.
Access is granted in tiers, per domain, by the client's own super admin during the connect wizard — nothing is automatic and nothing is estate-wide by default. Reads are the base tier. User, group, org-unit, license, and device management are separate opt-in grants. The genuinely irreversible actions — deleting a user, factory-wiping a phone, deprovisioning a Chromebook — sit in a destructive tier that isn't part of the recommended default, and every one of them refuses to run until you echo the exact email or device id back. If a domain never granted a pack, the underlying scope simply isn't there to use.
Things you can ask
Ask it like you’d ask a teammate.
Skills included
Every skill, in the open.
48 skills across 7 areas
Read by default; every write is a separate per-domain grant the client's own super admin approves. With lifecycle-manage a session can create, rename, suspend, unsuspend, sign out and move users, reset passwords, issue 2SV backup codes, create groups and org units, and add or remove group members. With licensing-manage it can assign, remove, and reassign license SKUs — and because Google ships no read-only licensing scope, that same grant is what makes license data readable at all. With device-manage it can approve or block mobile devices and disable, re-enable, or relocate ChromeOS devices. The destructive tier — deleting or restoring a user, remote-wiping a phone or its Workspace account, deprovisioning a Chromebook — is never in the recommended default and every call is refused until the exact primary email or device id is echoed back.
Clients & connection3Which client domains are connected, what each one's super admin actually granted, and who this session is authenticated as. The first thing to ask when an answer looks thinner than you expected.⊘ Read-only, and scoped to this session — where a session is restricted to particular client connections, only those appear here, not the whole roster. It cannot connect a domain, request a pack, or revoke a grant; that happens in the connect wizard, on the client's side.›
whoamiWhich org this session is running as, what scopes its token carries, and how many client domains are in reach of it right now.list_clientsEvery connected client domain in one list, each showing which capability packs its super admin granted and whether those grants last probed healthy.get_client_healthOne domain's connection in detail — pack by pack, the grant status, when it was authorised, and whether the most recent health probe came back clean.
Users15Search and read the people in a domain — admin and suspended state, org unit, group memberships, and 2-Step Verification status, plus a domain-wide 2SV enrollment report. The lifecycle actions behind an onboard or an offboard sit here too.⊘ It reads and manages directory identity only — no mailbox, no Drive file, no message and no document is readable or writable from here. Temp passwords and backup codes are returned once and cannot be retrieved again afterwards.✎ Writes: With lifecycle-manage granted: creates accounts with a one-time temp password, edits name fields, suspends and unsuspends sign-in, resets passwords, signs a user out of every session, moves them between org units, and issues fresh 2SV backup codes. With lifecycle-destructive granted: permanently deletes an account, or restores one that was deleted.›
search_usersFind people in a client's domain by name or by the front of their email address.get_userOpen one person's record in full — admin rights, suspended state, 2SV enrollment and enforcement, org unit, and when they last signed in.list_user_groupsEvery group a person belongs to directly — memberships inherited through nested groups aren't expanded.get_user_2sv_statusWhether one person has 2-Step Verification switched on, and whether policy is forcing it on them.get_2sv_enrollment_reportHow much of a domain has 2-Step Verification, counted from the user directory rather than Reports — past 500 active users the figures come back marked as lower bounds instead of exact totals.create_userStand up a new account with a generated password the person must change at first sign-in — shown once, never recoverable, so hand it over out of band.update_userCorrect the name on an existing account — first, last, or both.suspend_userBlock someone's sign-in without deleting anything — the first move of an offboard.unsuspend_userPut a suspended account back into service.reset_passwordIssue a fresh one-time password with a forced change at next sign-in — like the create case, it's displayed once and can't be looked up later.sign_out_userDrop someone out of every active web and device session — the password itself is left alone.move_user_orgunitRelocate a person into a different org unit, which is how Workspace policy follows them.get_2sv_backup_codesMint a new set of 2-Step Verification backup codes for someone — doing so voids any codes they were already holding.delete_userRemove an account outright — destructive, and refused until the person's exact primary email is typed back as confirmation.undelete_userBring a deleted account back, matched by primary email across up to 500 deleted users and restored into the root org unit — also gated on an exact-email confirmation.
Groups6Distribution lists and security groups: what exists, who's in each one, and one group's detail on its own.⊘ Membership is read and written one member at a time, directly — nested group membership isn't flattened, and group settings such as posting permissions or moderation aren't exposed.✎ Writes: With lifecycle-manage granted: creates a group at an address you choose, and adds or removes individual members at member, manager, or owner level.›
list_groupsEvery group in a client's domain, with its address, description, and how many members sit directly in it.get_groupOne group's detail on its own — address, name, description, direct member count, and whether the domain created it.list_group_membersWho's directly inside a group, each with their role and membership status.create_groupStand up a new group at an address you pick, with a display name and an optional description.add_group_memberPut someone into a group as a member, a manager, or an owner.remove_group_memberTake someone back out of a group.
Org units2The tree a domain's policy hangs off — read it, and add to it.⊘ It can read the tree and add to it, but cannot rename, move, or delete an existing org unit, and it does not read or set the policies attached to one.✎ Writes: With lifecycle-manage granted: creates a new org unit under a parent path you name.›
list_orgunitsThe whole org-unit tree for a domain, each unit with its path and parent — the structure every Workspace policy is applied against.create_orgunitAdd a new org unit beneath a parent path you name.
Licensing5Seat assignment across the Workspace editions, and what any individual holds. Google publishes no read-only licensing scope, so seeing license data at all takes the same grant as changing it — that's a Google constraint, not a choice made here.⊘ It probes a fixed list of current-generation Workspace editions plus Google Vault — legacy G Suite, Education, Cloud Identity, Gemini, and device SKUs are outside it. It cannot buy, cancel, or change the size of a subscription; assignment is only ever a move between seats you already own.✎ Writes: With licensing-manage granted: assigns a SKU to an existing user, removes one, and reassigns a user from one SKU to another within the same product.›
list_skusHow many seats are assigned on each known Workspace edition, found by probing them one by one — a SKU past 500 assignments is reported as a lower bound, not an exact count.get_user_licensesWhich editions one person actually holds, checked against that same known-SKU list.assign_licenseGive an existing user a seat on a specific product and SKU.remove_licenseTake a seat back off a user, freeing it for someone else.move_licenseShift a user from one SKU to another inside the same product — an upgrade or a downgrade done in place.
Devices12Mobile and ChromeOS hardware enrolled in a domain: model, OS, owner, serial, and last sync — plus the management actions that follow a lost phone or a returned Chromebook.⊘ It manages devices already enrolled — it cannot enroll one, push an app or a policy to one, or locate one. There is no manual sync action for mobile devices in Google's API at all, so none is offered here.✎ Writes: With device-manage granted: approves or blocks a mobile device, and disables, re-enables, or moves a ChromeOS device between org units. With device-destructive granted: factory-wipes a mobile device, wipes just the Workspace account off it, or deprovisions a Chromebook — permanent actions, each refused until the exact device id is echoed back.›
list_mobile_devicesEvery phone and tablet enrolled in a domain, with model, OS, type, owner, status, and when it last synced.get_mobile_deviceOne phone or tablet in full, down to its IMEI and serial number.list_chromeos_devicesEvery enrolled Chromebook, with model, OS version, assigned user, location, serial, and last sync.get_chromeos_deviceA single Chromebook opened out — including its platform version and the org unit it currently sits in.approve_mobile_deviceLet a pending phone or tablet through into management.block_mobile_deviceCut a phone or tablet off from domain access.disable_chromeos_deviceLock sign-in on a Chromebook — reversible, and the device stays enrolled.reenable_chromeos_deviceBring a disabled Chromebook back into service.move_chromeos_deviceShift a Chromebook into a different org unit, which is how the policy applied to it changes.wipe_mobile_deviceFactory-wipe a phone or tablet, taking every byte on it with it — destructive, and refused until the device's exact resource id is echoed back.account_wipe_mobile_deviceStrip only the Workspace account and its data off a device and leave the owner's own contents intact — lighter than a factory wipe, still destructive, still confirmation-gated.deprovision_chromeos_deviceRetire a Chromebook out of management for good, which may release a perpetual-license seat — permanent, and gated on echoing the exact device id.
Audit & security5The record of what happened in a domain: sign-ins, Admin console changes, Drive access and sharing, usage counters, and Alert Center notices.⊘ Read-only, and it reports events rather than acting on them — it cannot dismiss or resolve an alert, and it cannot revoke a session or block an IP from here.›
get_login_eventsWho signed in lately across a domain, with the actor and the source IP on every event.get_admin_eventsWhat administrators actually did in the Admin console — the change record behind a configuration surprise.get_drive_eventsFile access and sharing activity across Drive, domain-wide — where an external-sharing question gets answered.get_usage_reportsDomain-level counters for a single day — seats, disabled accounts, license totals, mail sent, Drive items created — pulled from three days back by default, because the last day or two is usually still incomplete.list_alertsWhat Alert Center has raised for a domain recently — the security notices that otherwise sit unread in a console nobody opens.
Connecting
Wire it in, in an afternoon.
How to connect
- 01Start the guided connect wizard here and choose which capability packs that client's domain should grant — reads on their own, or reads plus the manage and destructive tiers.
- 02The client's own Workspace super admin authorises MSPStuff's dedicated service account for exactly those packs, via domain-wide delegation scoped to nothing else.
- 03Confirm the domain back in the wizard and it's answerable from that point. Every additional client domain connects the same way, independently.
Patch your stack in.
Start the Switchboard free trial against your own environment — read-only, traced answers, live in an afternoon. The apps are on the shelf when you want them.