GW
LivePro

Google Workspace

ProductivityBuilt by cAND/or OAuth 2.0 Setup: ~10 minutes Includes Client Management

Connect Helix to Google Workspace for Google Calendar sync and Gmail integration. Appointment scheduling syncs with Google Calendar. Tech availability imports from personal calendar.

Your Organization

Connect Helix to your own Google Workspace account. Applies to all users in your MSP — calendar sync, notifications, and staff tools.

Required Credentials

1 field
Google AccountClick to Connect

Click Connect with Google in the App Marketplace. A Google Workspace admin account is required to grant calendar permissions for your organization.

Data Flow

2 capabilities
Helix initiates
Vendor notifies Helix
Both directions
// Helix → VendorHelix initiates

Gmail Notifications

Helix → Vendor

Optional: route Helix email notifications through Gmail

ProtocolREST API call via Gmail API
TriggerSame triggers as Resend transactional email. Gmail routing is an alternative to Resend for lower-volume scenarios.
AuthOAuth 2.0 (user-level)
You configureNo configuration needed in Gmail.
Helix doesConfigure in App Marketplace → Google Workspace → Email Routing. Resend is recommended for high-volume transactional email.
// BidirectionalBoth sides communicate

Google Calendar Sync

Bidirectional

Helix appointments sync to Google Calendar. Personal calendar blocks import as unavailable time.

ProtocolOAuth 2.0 API (both directions)
TriggerAppointment created or updated in Helix syncs immediately to Google Calendar. Personal calendar blocks sync on a 15-minute schedule.
AuthOAuth 2.0 (user-level, per technician)
You configureEach technician connects their own Google account in Helix Settings → My Profile → Calendar.
Helix doesHelix creates Google Calendar events for appointments. Personal blocks appear as unavailable in the dispatch board without exposing personal details.

Client Management

MSP Feature

Connect your clients' Google Workspace tenants to manage them directly from their Helix client record — without opening the vendor's admin console. Each client gets their own separate connection.

Required Credentials

3 fields
Service Account Key (JSON)
RequiredSecret

Full JSON key file downloaded from Google Cloud Console for the service account that has domain-wide delegation enabled. In the client Google Workspace Admin: Security → API Controls → Domain-wide Delegation → Add the service account client ID with the required API scopes.

Format:{"type":"service_account","project_id":"..."}
Must be the full JSON key file content. The service account must have domain-wide delegation enabled with scopes: admin.directory.user, admin.directory.group, admin.directory.userschema
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_managementsuspended_account_alerts
Client Domain
Required

The primary domain of the client Google Workspace account. Used to scope all API calls to the correct organization.

Format:clientcompany.com
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_managementsuspended_account_alerts
Super Admin Email
Required

Email address of a Google Workspace super admin in the client organization. The service account impersonates this account to execute admin operations via domain-wide delegation.

Format:admin@clientcompany.com
Enables →
user_provisioninguser_deprovisioningpassword_resetlicense_managementsuspended_account_alerts

Data Flow

5 capabilities
Helix initiates
Vendor notifies Helix
Both directions
// Helix → VendorHelix initiates

User Provisioning

Helix → Vendor

Create users, assign Google Workspace licenses, and add to groups in the client domain from Helix onboarding workflows

ProtocolREST API call via Google Admin SDK (Directory API)
TriggerOnboarding ticket reaches provisioning milestone, or tech initiates from client record → Google Workspace tab
AuthService account with domain-wide delegation
You configureIn the client Google Workspace Admin: Security → API Controls → Domain-wide Delegation → Add the Helix service account client ID. Required scopes: admin.directory.user, admin.directory.group.
Helix doesProvisioning templates are configurable per client in the client record. Helix creates the user with the specified OU, license, and group memberships in a single workflow step.

User Deprovisioning

Helix → Vendor

Suspend accounts, revoke tokens, transfer Drive ownership, and remove group memberships for departing users

ProtocolREST API call via Google Admin SDK
TriggerOffboarding ticket reaches deprovisioning milestone, or tech initiates from client record → Google Workspace tab → [User] → Deprovision
AuthService account with domain-wide delegation
You configureNo additional configuration beyond provisioning setup.
Helix doesHelix suspends the account, revokes all OAuth tokens, optionally transfers Drive files to a designated owner, and removes the user from all groups. Each step is logged as a ticket note.

Password Reset

Helix → Vendor

Reset a client user password directly from a Helix ticket without opening the Google Admin Console

ProtocolREST API call via Google Admin SDK
TriggerTech clicks Reset Password on a ticket or from client record → Google Workspace tab → [User] → Reset Password
AuthService account with domain-wide delegation
You configureNo additional configuration beyond provisioning setup.
Helix doesHelix resets the password and optionally flags the account to require a password change at next sign-in. The reset is logged as a ticket note with timestamp and performing tech.
// Vendor → HelixVendor notifies Helix

Suspended Account and Security Alerts

Vendor → Helix

Detect suspended accounts, login anomalies, and inactive users — surface them as Coach alerts on the client record

ProtocolScheduled API Poll — event-driven Coach alerts
TriggerHelix polls the client domain daily: accounts suspended more than 30 days, users inactive for 90+ days, admin activity anomalies from the Reports API
AuthService account with domain-wide delegation (Reports API scope required)
You configureAdd the Reports API scope (reports.audit.readonly) to the domain-wide delegation configuration.
Helix doesCoach alerts appear on the client record. Stale suspended accounts are flagged for license reclamation. Prolonged inactivity alerts prompt a client check-in workflow.
// BidirectionalBoth sides communicate

License Management

Bidirectional

View assigned Google Workspace license SKUs, audit unused seats, and reassign licenses

ProtocolREST API (both directions) via License Manager API
TriggerLicense tab in client record loads current assignments on demand
AuthService account with domain-wide delegation
You configureAdd the License Manager API scope to the domain-wide delegation configuration.
Helix doesHelix reads the client domain license inventory. Unused seats and SKU mismatches surface as Coach alerts.

Ready to connect?

Log into Helix and open App Marketplace to configure this integration.

Open Helix