Integrations
Google Workspace Sign-In
When you add people to SecureSlate from your Google Workspace directory, they sign in with Continue with Google using their work account. No invitation email, no separate password, and no second set of credentials to manage.
Their SecureSlate account is created the first time they sign in, with the role you assigned. If they never sign in, no account is ever created.
This builds on the Google Workspace integration. Connect that first.
Why this matters
A separate SecureSlate password is a second way into your compliance data, one that sits outside the controls you already run in Google Workspace.
When someone signs in with Google, your 2-Step Verification, session policies, and device rules apply to SecureSlate too. When you suspend them in Google Workspace, that door closes with every other one.
Who this applies to
| Person | How they sign in |
|---|---|
| Added from the Google Workspace directory | Google only |
| Invited by email from the Employees page | Password, as before |
| Owners and Auditors | Password, always. See Keeping a way in |
Adding someone from the directory does not change how existing people sign in. If you invited someone by email months ago and they later appear in your Workspace directory, SecureSlate records the match for reporting but leaves their password sign-in alone.
Adding people
- Go to Integrations → Google Workspace → Configure.
- Open the Directory tab. This lists the people in your Google Workspace directory.
- Select the people you want, and choose a role for each: Admin or Member.
- Select Add.
You can add up to 100 people at a time.
They appear in your employee list straight away, marked as not yet signed in. Nothing is emailed to them: tell them to go to SecureSlate and choose Continue with Google.
If someone can't be added
Some people are skipped, and SecureSlate tells you which and why:
| Message | What to do |
|---|---|
| They already have a SecureSlate sign-in | Add them from the Employees page instead |
| They are already an Owner or Auditor in SecureSlate | Nothing. These roles keep password sign-in by design |
| They are already in your employee directory | Nothing. They are already there |
| Their Google Workspace account is suspended | Restore the account in Google Workspace first |
| Their email domain isn't verified in Google Workspace | Verify the domain in Google, then try again |
| Their email is already linked to another organization | Contact support. An address belongs to one organization |
| They were removed from SecureSlate earlier | Nothing. This is deliberate |
Access levels
Each person in the Google Workspace configure screen has an access level you can change at any time.
| Level | What it means |
|---|---|
| Full access | In the employee list and can sign in. |
| Roster only | In the employee list for compliance, but cannot sign in. |
| Not in scope | Hidden from the employee list and every picker, and cannot sign in. |
Roster only is the one worth knowing about. Contractors, service accounts and people on leave often belong in your personnel records, and auditors expect to see them, without needing to open SecureSlate. This keeps them in your evidence without giving them a way in.
Turning access off takes effect immediately. It ends sessions the person already has open, so they do not keep working until a session expires.
Some rows cannot be changed, and SecureSlate says why: an Owner always keeps access, you cannot change your own, and an Admin can only change access for Members.
What people see
Someone signing in for the first time chooses Continue with Google and lands in SecureSlate. There is no setup step.
If they try another way in, such as a password, an email sign-in link, or a different provider, they are told:
Your organization uses Google sign-in for SecureSlate. Use "Continue with Google" with your work account.
If you have turned their access off:
Your access to this workspace has been turned off. Contact your administrator.
Anyone who asks for a password reset or an email sign-in link is pointed back to Google rather than being sent a link that would not work.
Keeping a way in
Owners and Auditors are never converted to Google sign-in. They keep password access, and the directory screen will not offer to change it.
This is deliberate. If Google Workspace is unreachable, whether an outage, an expired domain, or a misconfigured policy, an Owner can still sign in with a password and restore access for everyone else. Removing that would mean a Google problem becomes a total lockout of your compliance program.
Before an Owner leaves the company, transfer ownership to someone else first.
Removing access
| You want to | Do this | Result |
|---|---|---|
| Stop someone signing in, keep their records | Set them to Roster only | Sessions end immediately; they stay in your evidence |
| Remove them entirely | Employees → Remove | Employee record and sign-in are both removed |
| Suspend them in Google Workspace | Nothing in SecureSlate | They can no longer sign in, because Google refuses them |
Removing someone from the Employees page also releases their email address, so they can be added again later, including to a different organization.
Disconnecting the integration
Disconnecting Google Workspace does not remove anyone, and does not hand anyone back a password.
Google sign-in keeps working, because it does not depend on the integration being connected. The integration reads your directory, it does not stand between your people and the login page. Disconnecting and reconnecting is safe, and is sometimes needed when the authorization expires.
If your company actually stops using Google Workspace, contact support before removing the connection, so access can be moved over deliberately rather than discovered at the login page.
Limitations
- Adding people is a manual step. SecureSlate does not create records for everyone in your directory automatically. You choose who belongs in your compliance program.
- Removals are not instant. Suspending someone in Google Workspace stops them signing in immediately, but their SecureSlate record stays until you remove it or your next review.
- One email, one organization. An address that already belongs to another SecureSlate organization cannot be added to a second.
- Existing accounts keep their sign-in. Someone who already has a SecureSlate account is not switched to Google sign-in by adding them from the directory.
Troubleshooting
Someone says "Your organization uses Google sign-in"
They are trying a password, a sign-in link, or another provider. Ask them to use Continue with Google with their work account, not a personal Gmail address.
Someone was added but never appears as signed in
Nothing is emailed when you add someone. Tell them to open SecureSlate and choose Continue with Google. Until they do, the record stays as not yet signed in, which is expected.
"This account is already linked to a different sign-in"
The employee record is already attached to someone else's sign-in, usually a duplicate record created earlier. Remove the duplicate from the Employees page, then add them again.
An Admin cannot change someone's access
Admins can only change access for Members. Ask an Owner to change an Admin or an Auditor.
Someone lost access after being suspended in Google Workspace
That is the intended behaviour. Restore them in Google Workspace and they can sign in again. No change is needed in SecureSlate.
