Google Org-wide Email / Calendar Integration
Enable Google Workspace connectivity for Rox, allowing IT administrators to authorize to securely access calendar and email data on behalf of all users within their Workspace.
Architecture

Option 1: Using Rox Workload Identity Pool (Preferred)
Option 2: Customer-Managed Identity Pool (Advanced / More Control)
Workload Identity Federation + Service Account Setup Guide
Prerequisites
Step 1: Create a Workload Identity Pool
Google Cloud Console (UI)
Equivalent gcloud command
Step 2: Add an OIDC Provider to the Pool
Google Cloud Console (UI)
Equivalent gcloud command
Step 3: Create a Service Account
Google Cloud Console (UI)
Equivalent gcloud command
Step 4: Allow the Workload Identity Pool to Impersonate the Service Account
Google Cloud Console (UI)
Equivalent gcloud command
Step 5: Ensure Token Creator Permission Is Granted
Google Cloud Console (UI)
Equivalent gcloud command (example)
Step 6: Retrieve the Service Account Unique ID (Required for Domain-Wide Delegation)
Google Cloud Console (UI)
Equivalent gcloud command
Step 7: Configure Domain-Wide Delegation in Google Workspace
Google Workspace Admin Console (UI)
Final Checklist
Common Errors & Fixes
Error
Cause
Fix
How Rox Syncs
Permission Scopes
Target
Access level
Requested permissions
What gets enabled
Security
Admin steps to follow
Steps for setup in Rox



Last updated

