M ManySignal
MS
GW
Integration

Google Workspace Integration

Detect account compromise and data theft across your Google environment.

What this integration does

Google Workspace meets agentic SOC

Google Workspace is a common target for phishing, OAuth token abuse, and insider data exfiltration through Drive sharing and export. ManySignal ingests Workspace Admin SDK audit events across Gmail, Drive, Admin, Login, and OAuth audit logs, building behavioural models and detecting threats from initial account compromise through data exfiltration.

Admin SDK audit log ingestion across all Workspace apps

Login event behavioural baselining per user

Drive mass download and external sharing detection

Data collected

  • Login audit log events (success, failure, 2SV events)
  • Drive audit log (file access, sharing, download events)
  • Admin audit log (user management, role changes)
  • Gmail audit log (forwarding, delegation, filter events)
  • Token audit log (OAuth app authorisations)

Actions supported

  • Suspend Google Workspace user
  • Sign out all active sessions for a user
  • Revoke OAuth application access for a user
  • Force password reset on next sign-in
  • Remove external sharing from Drive resources

Getting started

Set up in minutes

  1. 1

    Create a GCP service account

  2. 2

    Grant Admin SDK API access

  3. 3

    Configure ManySignal

  4. 4

    Enable the Workspace detection pack

Google Workspace Integration: frequently asked questions

Which Google Workspace editions are supported?

The Admin SDK Reports API is available on Business Standard and above. Business Starter and legacy editions may have limited audit log retention and event types.

Can ManySignal detect Google Drive ransomware simulation?

Yes. ManySignal detects bulk file rename patterns that match known ransomware extensions and large-volume file deletion events, which are common indicators of ransomware or destructive insider activity.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.