Google Workspace Permissions

Prev Next

imper.ai requires access to specific Google Workspace APIs in order to retrieve identity, directory, and calendar context used for real-time verification and impersonation detection.

These permissions are requested during the Google Workspace authorization flow when connecting:

  • Google Workspace as an Identity Provider (IdP)

  • Google Meet as a Communication Channel

This article explains what permissions are requested and why they are required.


How Permissions Are Granted

Permissions are granted during the Google OAuth authorization flow.

An administrator is prompted to approve access after clicking Connect for Google Workspace in the imper.ai Integrations page.

Once approved, imper.ai uses these permissions only for verification and security analysis purposes.


Permissions Required

Directory Access

imper.ai requires read access to Google Workspace directory data in order to:

  • Identify internal vs. external users

  • Resolve user and group membership

  • Generate identity-aware verification challenges

Used for:

Identity validation and organizational context


User Profile Information

Access to basic user profile attributes allows imper.ai to:

  • Associate meeting participants with known identities

  • Detect mismatches between claimed and actual user context

Used for:

Persona analysis during verification


Calendar Access

imper.ai requests limited access to calendar metadata in order to:

  • Detect meeting context

  • Generate challenge questions related to scheduled events

  • Associate participants with expected meetings

imper.ai does not read meeting content or message bodies.

Used for:

Challenge-based verification and session correlation


Audit and Security Signals

Where applicable, imper.ai may retrieve security-related metadata to:

  • Detect unusual access patterns

  • Correlate identity anomalies

Used for:

Risk scoring and impersonation detection


How imper.ai Uses These Permissions

The permissions listed above are used exclusively to:

  • Improve verification accuracy

  • Reduce false positives

  • Detect impersonation and social engineering attempts

imper.ai does not:

  • Modify Google Workspace data

  • Act on behalf of users

  • Access email content

  • Access files or documents


Security & Privacy Considerations

  • All access is read-only

  • Permissions are scoped to verification use cases

  • Data is processed according to imper.ai security policies

  • Verification results are visible only to authorized administrators

End users are not exposed to their risk scores or internal analysis.


Revoking Permissions

If needed, administrators can revoke imper.ai access at any time from the Google Workspace Admin Console.

Revoking access will disable Google-based verification and meeting protection.