Appearance
For the helpdesk use case, imper.ai requires the following Google Workspace API scopes to build identity verification questions and to reset passwords during remediation. These scopes are authorized through Domain-Wide Delegation by a Google Workspace Super Admin.
This article explains which scopes are required and why they are needed.
Scopes Requested by imper.ai
…/auth/admin.directory.user
Used for:
- Reading user profiles and resetting a user's password during helpdesk remediation
…/auth/admin.directory.group.readonly
Used for:
- Reading groups to provide organizational context for verification
…/auth/admin.directory.device.mobile.readonly
Used for:
- Reading mobile device information used during verification
…/auth/calendar.readonly
Used for:
- Reading calendar settings and events to generate verification questions
…/auth/calendar.events.readonly
Used for:
- Reading calendar events to generate verification questions
…/auth/gmail.readonly
Used for:
- Reading email metadata to generate verification questions
…/auth/userinfo.email
Used for:
- Viewing the user's email address to identify and link their Google account
…/auth/userinfo.profile
Used for:
- Accessing basic profile information for user identification
openid
Used for:
- Authenticating the user