Skip to main content

Provision and sync accounts with Google Workspace

Google account provisioning creates Google Workspace accounts for your employees from Humaans and suspends them when they leave. As details in user profiles change, employee Google accounts stay up to date.

Accounts can be created as soon as you add someone, or in the run-up to their employment start date, with sign-in details sent to their personal email.

You choose which Humaans fields map to which Google fields, and which organisational unit each person is placed in.

Before you begin

To set up the integration, you need:

  • A Humaans Growth or Enterprise plan.

  • The Owner or Admin role in Humaans. To learn more, visit Managing permissions and roles.

  • A Google Workspace administrator who can manage users and organisational units in your Google Workspace account.

  • Work emails in Humaans that use a domain registered to your Humaans account.

Connect Google Workspace

A Google Workspace administrator connects the integration once for your organisation by following these steps:

  1. Click Integrations in the main menu.

  2. Locate Google Account Provisioning, then click Configure.

  3. In the Connection tab, click Sign in with Google.

  4. Sign in to Google as a Google Workspace administrator.

  5. Review the requested permissions, then allow them. Humaans asks to view and manage the:
    Provisioning of users on your domain
    Organisation units on your domain

  6. Humaans returns to the Integrations page and shows the connection as active.

The account you sign in with authorises Humaans to create and update user profiles on its behalf, so it's important to keep it active. If that administrator leaves your organisation, reconnect the integration with another administrator.

Choose when accounts are created

To configure your provisioning rules, open the Provisioning tab:

  1. Toggle on Provision new Google Workspace accounts.

  2. Under When to provision, select one of these options:

    As soon as the employee is created: Humaans creates the Google account when you add the person.
    Employment start date: Humaans creates the account relative to the start date.

  3. Select the offset: on the day, one day before, one week before, two weeks before, or one month before.

  4. Under When to send invite with password, select one of these options:
    As soon as the account is provisioned
    Employment start date, with the same offsets
    Never - invite will be sent manually

  5. Click Save.

When Humaans creates an account, it sets the person's first name, last name, work email as the primary email, and a temporary password.

Note: People are provisioned once they become active members in Humaans. This doesn't include new hires.

What a person needs before an account can be created

To avoid account provisioning being skipped, the following must be true:

  • The person is an active member in Humaans.

  • Their work email uses a domain registered to your Humaans account.

  • They have a personal email on their profile (Not required when invites are set to Never - invite will be sent manually.)

  • They became an active member after you connected the integration. To provision people who were already in Humaans, read Sync existing employees.

What the new account holder receives

The invite goes to the person's personal email, with the subject "You have a new Google account for [your company name]." The invite provides their work email as their username, a temporary password, and a link to sign in. On clicking the link, Google prompts the recipient to set their own password.

If you select Never - invite will be sent manually, Humaans creates the account and sends nothing. Share the sign-in details, or reset the password, from the Google Admin console.

Choose which fields sync

In the Data mapping tab, choose which data maps from a person's Humaans profile to their Google account. First name, last name, and work email always sync and can't be toggled off, because they identify the account.

For first name, use the dropdown to select the source: First name, or Preferred name, which falls back to first name when the person doesn't have one.

Every other mapping is optional and can be toggled on or off. Here's a list of the fields available for mapping:

Humaans profile

Google Workspace

Personal email

Personal email

Work phone

Work phone

Personal phone

Personal phone

Profile photo

Profile photo

Address*

Address

Employee ID

Employee ID

Job title

Job title

Department

Department

Contract type

Type of employee

Place of work

Organization location

Place of work city

Work address city

Place of work country

Work address country

Manager email

Manager email

*Address maps a person's home address in Humaans to their home address in Google. Their work address comes from the place of work data point.

Google stores job title, department, contract type, and place of work under the user's organisation details, and the city and country under the user's work address. Google's user resource reference lists each field.

Map place of work and the work address

Place of work and the work address are separate mappings, so enable the ones you need:

  • Place of work sets Organization location to the name of the person's location in Humaans, such as London HQ. For someone who works remotely, Humaans sends the city and country from their remote work details, such as Kaunas, Lithuania, or Remote when neither are set.

  • Place of work city sets the city on the work address.

  • Place of work country sets the country on the work address.

Enabling Place of work on its own doesn't populate the work address. To fill the work address, enable both Place of work city and Place of work country.

The work address is built from the city and country. The street address of an office isn't part of these mappings. Humaans also sends a formatted summary of the work address, such as Kaunas, Lithuania, which Google displays alongside the structured city and country values.

To set up the locations these fields draw on, visit Adding office locations.

Keep data in sync

By enabling Keep data in sync, changes made to people in Humaans will be reflected in their Google account. If this setting isn't enabled, mapped fields are used only when an account is first provisioned.

Syncing is one-way: changes made in Humaans update Google, but not the other way around.

Toggling on a new mapping will trigger a sync for people who have existing Google accounts, so no further action is needed to fill that field.

Sync existing employees

Accounts are provisioned and synced from the time you set up the integration, so people who were already in Humaans aren't included. To apply your settings to them, click Sync all users at the bottom of the Data mapping page.

Save any changes to your settings first, and enable Keep data in sync, otherwise existing people are skipped.

What does sync all users do?:

  • Creates accounts for active people who don't have one.

  • Links a person to their existing Google account when one already uses their work email, rather than creating a duplicate.

  • Updates mapped fields for everyone already linked.

  • Suspends offboarded people, if deprovisioning is enabled.

Organise accounts into organisational units

Under Organisational unit in the Data mapping tab, place people into organisational units in Google based on their Humaans data.

  1. Click Add mapping.

  2. For Level 1, select Department, Place of work, or Contract type.

  3. To nest units, click Add level, then select an attribute for that level.

  4. Click Save.

Humaans builds the path from the person's own values, so a Level 1 of Place of work with a Level 2 of Department places someone in /London HQ/Engineering. Each attribute can be used once, giving up to three levels. Humaans creates any organisational units that don't exist yet.

People who work remotely are placed under Remote when Place of work is one of the levels. If a person is missing a value for one of the levels, such as a job role without a department, Humaans leaves their organisational unit unchanged and records this in the Logs tab.

To remove a level, click the delete icon at the end of its row.

Deactivate accounts when people leave

In the Deprovisioning tab, toggle on Deprovision Google Workspace accounts, then click Save.

  • People who are offboarded in Humaans are suspended at the end of their last working day.

  • People who are deleted from Humaans are suspended immediately.

The deprovisioning method is Suspend. Humaans runs a final sync before suspending an account, so the profile reflects the person's latest details.

Suspending doesn't delete the Google account or release its licence. You need to delete the account, transfer its data, and reassign the licence in the Google Admin console manually.

Reprovisioning isn't automatic. Once an account is deprovisioned, Humaans doesn't create or update that person's Google account again, including if they're rehired. Restore the account in the Google Admin console instead.

Review activity and errors

The Logs tab records provisioning, syncing, deprovisioning, and invite activity, including details of the person, the time, and whether the action succeeded, was skipped, or failed. Failures include the reason reported by Google.

Check the logs to confirm accounts were created, or to investigate a sync that didn't complete.

Reconnect the integration

If the connection expires, or the connecting administrator's Google access changes, the Connection tab shows:

"An authentication issue has occurred. Please reconnect to continue syncing Google Workspace with Humaans."

Provisioning and syncing stop until the integration is reconnected. To reconnect:

  1. Click Integrations in the main menu.

  2. Locate Google Account Provisioning, then click Configure.

  3. In the Connection tab, click Sign in with Google.

  4. Sign in as a Google Workspace administrator, then allow the permissions.

  5. If the administrator who connected the integration has been offboarded, reconnect it with another administrator.

Troubleshooting

Below are some common issues that pop up and steps on how to resolve them.

Type of employee is filled but the work address is empty

Ensure both Place of work city and Place of work country are enabled in the Data mapping tab. Place of work on its own only updates Organization location.

A new hire didn't get an account

Open the Logs tab and look for a skipped entry for that person, then confirm:

  • They're an active member in Humaans, not a new hire.

  • Their work email uses a domain registered to your Humaans account.

  • They have a personal email, if invites are enabled.

  • They became active after the integration was connected. If they didn't, click Sync all users.

The log shows "Insufficient Google Workspace licences"

Your Google Workspace subscription has no seats available. Add licences in the Google Admin console, then click Sync all users.

The log shows an account is associated with another Humaans user

A Google account already uses that work email and is linked to a different person in Humaans. Correct the work email in Humaans, or the account in Google Workspace, then sync again.

Changes in Humaans aren't reaching Google

Check that Keep data in sync is enabled, that the field is mapped in the Data mapping tab, and that the person's Google account isn't suspended. Humaans skips accounts that are suspended or have been deprovisioned.

Did this answer your question?