AI security & operations for MSPs

Google Workspace

Google Workspace

Hal reads Google Workspace activity through the Reports API and the Alert Center, over a service-account authorization you grant in your Admin Console. Its scopes are read-only except the Alert Center’s, the only one Google offers, which can also change alerts; Hal only reads with it. He never writes to the workspace.

What’s collected:

  • Login and account activity, including login type and source IP
  • Admin console actions and changes
  • Drive and other application audit events
  • Google’s own security alerts from the Alert Center, with their severity

Polled every few minutes, retained 365 days.

Connect it: in the portal chat, either way: Hal-assisted onboarding walks you through granting his own service account’s delegation, or you create a service account in your own Google Cloud project as the manual page describes and paste its key on Settings → Google Workspace.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.