Google Workspace audit logs
Review unusual sign-ins, administrator changes and third-party OAuth activity. This is separate from the Google Cloud connector.What Flare reads
- Reports API activities from login, admin and token applications.
- The customer profile needed to verify your customer ID and display domain.
- Supported event metadata such as timestamp, actor, action, resource and network information.
Before connecting
Use a Google Workspace administrator with permission to view the required audit reports and customer profile. Locate the customer ID (for example,C01234567) in Google Admin console → Account → Account settings → Profile. A domain name or email address is not the customer ID.
Flare requests these read-only OAuth scopes:
https://www.googleapis.com/auth/admin.reports.audit.readonlyhttps://www.googleapis.com/auth/admin.directory.customer.readonly
Connect and analyze
- Open Connectors and select Google Workspace.
- Enter the customer ID, choose Connect Google Workspace, and sign in as the intended administrator.
- Review and approve the requested read-only access. Flare verifies that the signed-in account belongs to the entered customer and can read all three report applications.
- Confirm the displayed customer identity, then choose Run an analysis.
- Name the run, select a time window and inspect both findings and the Google Workspace audit coverage panel.