Skip to main content

Create a Google Workspace account with restricted directory access

By default, synchronisation with Google Workspace uses an administrator account that has access to your entire directory. You can create a dedicated account with read-only access to a specific organisational unit.

By default, synchronisation with Google Workspace uses an administrator account that can see your entire directory. If your internal policy doesn't allow that, or if you only want to synchronise part of your employees, you can create a dedicated account whose access is limited to read-only on a specific organizational unit.

👍 Good to know: this account needs no write permissions at all. It reads the users and groups of the unit you designate, and nothing else: the rest of your domain is not exposed.

1️⃣ Create or choose the account

👉 Step 1: In the Google Admin console, go to Directory > Users.

👉 Step 2: Create a new dedicated user — for example [email protected] — or select an existing integration account.

👉 Step 3: Open its details page.

2️⃣ Create a custom admin role

👉 Step 1: On the user's page, scroll down to Admin roles and privileges, then open role management.

👉 Step 2: Create a custom role.

👉 Step 3: Give it a clear name, for example Riot Directory Reader, and optionally a description such as "Read users and groups of a restricted unit for the Riot integration".

👉 Step 4: Under admin privileges, enable only the read access to users.

👉 Step 5: Save the role.

3️⃣ Assign the role to a specific organizational unit

👉 Step 1: Go back to the user's page, to Admin roles and privileges, and tick the role you have just created.

👉 Step 2: To the right of the entry covering all organizational units, click the edit icon.

👉 Step 3: Choose the organizational unit the role should apply to — for example /Employees/France.

👉 Step 4: Save.

⚠️ Important: this is the step that actually restricts the scope. A read-only role assigned across all units would give access to the whole directory — the limitation comes from the choice of unit, not from the role.

4️⃣ Connect the integration in Riot

👉 Step 1: Sign in to hub.tryriot.com.

👉 Step 2: Go to Settings > Integrations > Directory.

👉 Step 3: Select Google Workspace.

👉 Step 4: When authenticating, sign in with the account you have just configured, not with your usual administrator account.

Riot then relies on that account's permissions: only the users and groups of the authorised unit are synchronised.

👍 Good to know: if an organizational unit you expect doesn't appear in the sync configuration, the cause is often related to the permissions of the account used. See Why can't I find my organizational unit (OU) in the sync configuration?

Key takeaways

  • A custom role with read access to users only is enough: no write permission is needed.

  • It is the choice of organizational unit that restricts the scope, not the role itself.

  • When connecting the integration, authenticate with this dedicated account.

  • Only the users and groups of the authorised unit are synchronised.

Did this answer your question?