Skip to main content
Cimento uses Google Workspace for two things, each with its own setup wizard: importing your employee directory, and placing phishing simulations directly in Gmail inboxes. Both work through domain-wide delegation to a service account Cimento creates for your organization. You never create credentials or share a password.

Before you start

  • A Google Workspace Super Admin. Only a Super Admin can authorize domain-wide delegation.
  • For the directory, an administrator contact on file with Cimento who is a Google Workspace admin able to view users and groups. Cimento reads the directory as that account. Your Cimento contact can tell you which address is on file.
  • For the directory, your organization’s email domains registered with Cimento. Only people in those domains are imported.
Both setups use the same client ID, and Google keeps one list of scopes per client ID. If you set up both, the second time you’ll find the client ID already listed. Edit that entry and add the new scopes to it; don’t replace it.

Import your directory

In Cimento this is Google Workspace User Provisioning. Cimento reads users, groups and group memberships with read-only access, and never changes your directory.
Your organization connects one directory, and switching to another later needs Cimento support. As soon as you click Begin Setup, employees come from Google: you can no longer add or upload employees in Cimento, or edit their names, email addresses, status or departments.
1

Start setup in Cimento

Go to Admin → Integrations → Employee data. Under Directory provider, choose Google Workspace User Provisioning and click Begin Setup.
2

Open domain-wide delegation

Sign in to admin.google.com as a Super Admin. Go to Security › Access and data control › API controls, click Manage Domain Wide Delegation near the bottom of the page, then Add new. If Cimento’s client ID is already listed, point to it and click Edit instead.
3

Authorize Cimento

In Cimento’s Service Account step, click Copy next to Client ID and paste it into Google. Do the same with OAuth scopes; Google accepts them comma-separated. The three scopes are listed below. Click Authorize.
4

Test the connection

In Cimento’s Review step, click Test connection. Cimento lists one user from your directory, acting as your administrator contact. Google can take up to 24 hours to apply a delegation change, so if the test fails straight away, try again later. Once the test passes, Cimento imports your directory immediately and then every 24 hours.
See What Cimento imports from Google Workspace for which fields are used and what happens when someone leaves.

Deliver phishing simulations

In Cimento this is Google Workspace Email. Cimento places each simulation straight into the employee’s Gmail inbox through the Gmail API, so nothing crosses your mail gateway and there’s nothing to allowlist.
1

Start setup in Cimento

Go to Admin → Integrations → Phishing, choose Google Workspace Email and click Begin Setup. Your organization can have one email provider active at a time.
2

Open domain-wide delegation

Sign in to admin.google.com as a Super Admin. Go to Security › Access and data control › API controls, click Manage Domain Wide Delegation, then Add new. If Cimento’s client ID is already listed because you imported your directory, point to it and click Edit instead.
3

Authorize Cimento

In Cimento’s Service Account step, copy the Client ID and the OAuth scopes into Google, and click Authorize. If you’re editing an existing entry, add these scopes after the ones already there.
4

Test the connection

In Cimento’s Review step, click Test connection. Cimento reads the Gmail profile of your administrator contact using gmail.readonly. The test doesn’t use the other scopes, so before your first campaign, point to Cimento’s client ID in Google, click View details, and check that every scope is listed.
Mailbox permissions explains exactly what Cimento does with each scope, and what it never does.

Revoke access

  • To remove one setup, open Manage Domain Wide Delegation, point to Cimento’s client ID, click Edit, and delete that setup’s scopes.
  • To remove everything, point to Cimento’s client ID and click Delete. Google says apps that depend on it stop working immediately.
  • Disconnecting in Cimento doesn’t change anything in Google, so remove the delegation there too.