Google Workspace
Google Workspace
Hal reads Google Workspace activity through the Reports API and the Alert Center, over a service-account authorization you grant in your Admin Console. Its scopes are read-only except the Alert Center’s, the only one Google offers, which can also change alerts; Hal only reads with it. He never writes to the workspace.
What’s collected:
- Login and account activity, including login type and source IP
- Admin console actions and changes
- Drive and other application audit events
- Google’s own security alerts from the Alert Center, with their severity
Polled every few minutes, retained 365 days.
Connect it: in the portal chat, either way: Hal-assisted onboarding walks you through granting his own service account’s delegation, or you create a service account in your own Google Cloud project as the manual page describes and paste its key on Settings → Google Workspace.
See what Hal surfaces on your own clients.
No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.
- 01You ask us your questions. No deck, no demo dataset.
- 02You sign a short evaluation agreement, and we stand up your own instance.
- 03You connect one tenant from your own admin console. Hal watches it for 14 days.
- 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.