Before you start
- A Google Workspace Super Admin. Only a Super Admin can authorize domain-wide delegation.
- For the directory, an administrator contact on file with Cimento who is a Google Workspace admin able to view users and groups. Cimento reads the directory as that account. Your Cimento contact can tell you which address is on file.
- For the directory, your organization’s email domains registered with Cimento. Only people in those domains are imported.
Import your directory
In Cimento this is Google Workspace User Provisioning. Cimento reads users, groups and group memberships with read-only access, and never changes your directory.Your organization connects one directory, and switching to another later needs Cimento support. As soon as you click Begin Setup, employees come from Google: you can no longer add or upload employees in Cimento, or edit their names, email addresses, status or departments.
1
Start setup in Cimento
Go to Admin → Integrations → Employee data. Under Directory provider, choose Google Workspace User Provisioning and click Begin Setup.
2
Open domain-wide delegation
Sign in to admin.google.com as a Super Admin. Go to Security › Access and data control › API controls, click Manage Domain Wide Delegation near the bottom of the page, then Add new. If Cimento’s client ID is already listed, point to it and click Edit instead.
3
Authorize Cimento
In Cimento’s Service Account step, click Copy next to Client ID and paste it into Google. Do the same with OAuth scopes; Google accepts them comma-separated. The three scopes are listed below. Click Authorize.
4
Test the connection
In Cimento’s Review step, click Test connection. Cimento lists one user from your directory, acting as your administrator contact. Google can take up to 24 hours to apply a delegation change, so if the test fails straight away, try again later. Once the test passes, Cimento imports your directory immediately and then every 24 hours.
See What Cimento imports from Google Workspace for which fields are used and what happens when someone leaves.
Deliver phishing simulations
In Cimento this is Google Workspace Email. Cimento places each simulation straight into the employee’s Gmail inbox through the Gmail API, so nothing crosses your mail gateway and there’s nothing to allowlist.1
Start setup in Cimento
Go to Admin → Integrations → Phishing, choose Google Workspace Email and click Begin Setup. Your organization can have one email provider active at a time.
2
Open domain-wide delegation
Sign in to admin.google.com as a Super Admin. Go to Security › Access and data control › API controls, click Manage Domain Wide Delegation, then Add new. If Cimento’s client ID is already listed because you imported your directory, point to it and click Edit instead.
3
Authorize Cimento
In Cimento’s Service Account step, copy the Client ID and the OAuth scopes into Google, and click Authorize. If you’re editing an existing entry, add these scopes after the ones already there.
4
Test the connection
In Cimento’s Review step, click Test connection. Cimento reads the Gmail profile of your administrator contact using
gmail.readonly. The test doesn’t use the other scopes, so before your first campaign, point to Cimento’s client ID in Google, click View details, and check that every scope is listed.
Mailbox permissions explains exactly what Cimento does with each scope, and what it never does.
Revoke access
- To remove one setup, open Manage Domain Wide Delegation, point to Cimento’s client ID, click Edit, and delete that setup’s scopes.
- To remove everything, point to Cimento’s client ID and click Delete. Google says apps that depend on it stop working immediately.
- Disconnecting in Cimento doesn’t change anything in Google, so remove the delegation there too.