Skip to content

Google Gemini Enterprise integration

Use the Google Gemini Enterprise integration to connect Gemini Enterprise, Gemini in Workspace, or both to Capsule Security.

Google Gemini Enterprise

Choose what to connect

Google uses similar names for two products that Capsule connects through different Google control planes.

Capsule optionAlso known asWhere it is administeredWhat Capsule collectsCustomer GCP project
Gemini EnterpriseAgentspace; Discovery EngineGoogle Cloud consoleShared and personal agents, engines, data stores, tools, sessions, prompts, responses, and citations available through Discovery EngineRequired
Gemini in WorkspaceGemini for WorkspaceGoogle Workspace Admin consoleStandalone Gemini app users and prompt-response conversations, using Workspace Reports and Google VaultNot required

Select both options if your organization uses both products. They complement each other; selecting one does not collect data from the other.

Current Workspace coverage: Capsule collects the standalone Gemini app, including conversations created at gemini.google.com. It does not currently collect Gemini side-panel or embedded feature activity from Gmail, Docs, Drive, Meet, Sheets, Slides, Chat, Keep, Classroom, or Vids. Google Vault does not make the prompt and response content from those embedded experiences available for export.

What you need

Shared requirements

Before opening the integration, identify:

  • A Google Workspace Super Admin who can authorize domain-wide delegation (DWD). Google permits only a Super Admin to add or edit a DWD client.
  • Your primary Google Workspace domain, such as example.com.
  • A maintenance owner for the integration. Changes to DWD scopes, admin roles, licenses, or the delegated admin account can stop collection.
  • A browser session that can complete the Google OAuth redirect. Complete the setup in the same browser without clearing site data between configuration and authorization.

Note: According to Google, changes to DWD settings can take up to 24 hours to propagate, although they typically take effect sooner. For details, see Control API access with domain-wide delegation.

Gemini Enterprise requirements

You need:

  • A Google Cloud project containing your Gemini Enterprise / Discovery Engine deployment.
  • The project ID, not the project name or number.
  • A Google account in the Workspace domain with Editor or Owner on the project. Capsule uses this account during installation to enable APIs and grant read-only roles.
  • Permission for that account to list Workspace users. A Super Admin satisfies this requirement; alternatively, use an appropriately delegated Directory administrator.

Gemini in Workspace requirements

The current Capsule Workspace option includes both Reports metadata and Vault content collection and therefore requires Google Vault.

Prepare one Workspace admin email. Capsule uses this address as its delegated Google identity for Reports, Directory organizational-unit lookup, Vault operations, and Vault export downloads. The account must:

  • be an active Google Workspace Super Admin in the domain you enter;
  • have the Google Admin Reports privilege, which permits access to usage reports and audit logs;
  • have the Organizational Units > Read privilege, which permits Capsule to resolve the root organizational-unit ID through the Directory API;
  • have the Google Vault service turned on;
  • have a Vault license;
  • have the Vault privileges Manage Matters, Manage Searches, and Manage Exports.

Super Admins normally include the Reports and Organizational Units privileges. They are listed explicitly so you can verify the delegated account if your organization uses custom or scoped administrator roles.

Treat this as a sensitive administrative account. Capsule does not collect only this admin's data; it impersonates the account to run organization-scoped API operations allowed by its roles.

The delegated Workspace admin cannot currently be changed in place. To use a different account, prepare its licenses, roles, service access, and DWD prerequisites, then reinstall the integration with the new admin email.

Every user whose Gemini app conversations you want Capsule to collect must also have Vault coverage. If your edition uses add-on licenses, assign a license to the Workspace admin and every covered user before setup.

Google currently includes Vault with these editions:

  • Business Plus
  • Enterprise Standard and Enterprise Plus
  • Frontline Standard and Frontline Plus
  • All Education editions
  • Domain-verified Enterprise Essentials and Enterprise Essentials Plus
  • Legacy G Suite Business

An add-on may be available for other editions. Edition names and Gemini availability alone do not guarantee Vault access; confirm compatibility through Google Sales, your reseller, or your Google billing channel.

Also confirm that:

  • the Gemini app is enabled for the users you intend to monitor;
  • your Gemini conversation-history settings retain the period you need;
  • any Vault retention rules or holds have been reviewed and approved by your legal or compliance owner.

Capsule does not create or change retention rules or holds. A badly configured Vault retention rule can irreversibly purge data, so test retention changes on a small scope first.

Set up Google permissions

Use this flow once whether you connect Enterprise, Workspace, or both. The Capsule installation card generates the exact DWD scope union for your selection.

1. Start the integration in Capsule

  1. In Capsule, go to Integrations.
  2. Find Google Gemini Enterprise and select Install.
  3. Under Choose what to connect, select:
    • Gemini Enterprise;
    • Gemini in Workspace; or
    • both.
  4. Select Continue.
  5. Enter your Google Workspace domain.
  6. If you selected Gemini Enterprise, enter the Project ID for its Google Cloud project.
  7. If you selected Gemini in Workspace, enter the prepared Workspace admin email.

Keep this page open. It displays the environment-specific Capsule Client ID and the exact OAuth scopes to authorize.

2. Authorize domain-wide delegation

  1. Sign in to the Google Workspace Admin console as a Super Admin.
  2. Go to Security > Access and data control > API controls > Manage Domain Wide Delegation.
  3. Select Add new.
  4. Copy the Client ID from the Capsule installation card. Use the value shown for this integration environment.
  5. Copy the complete comma-separated OAuth scopes value from Capsule and paste it into OAuth scopes.
  6. Select Authorize.
  7. Open the new client's details and verify that every scope is present.

If your organization uses multi-party approval for DWD changes, a second Super Admin must approve the authorization before it becomes active.

Do not add scopes for a source you did not select. If you change your selection later, update the same DWD entry with the new scope union before reinstalling.

Scope reference

Capsule displays the required union automatically. This table explains why each scope is requested.

ScopeRequired forPurpose
https://www.googleapis.com/auth/admin.directory.user.readonlyGemini EnterpriseList Workspace users for personal-agent discovery
https://www.googleapis.com/auth/cloud-platformGemini Enterprise and Gemini in WorkspaceRead Discovery Engine resources; for Workspace, download Google-generated Vault export objects
https://www.googleapis.com/auth/admin.reports.audit.readonlyGemini in WorkspaceRead Gemini activity reports for the Workspace domain
https://www.googleapis.com/auth/admin.directory.orgunit.readonlyGemini in WorkspaceResolve the Directory organizational-unit identifier used for Vault collection
https://www.googleapis.com/auth/ediscoveryGemini in WorkspaceCreate/reuse a Vault matter and create, inspect, and download exports

The common scope sets are:

Gemini Enterprise only

https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/cloud-platform

Gemini in Workspace only

https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/ediscovery,https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/admin.directory.orgunit.readonly

Both

https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/ediscovery,https://www.googleapis.com/auth/admin.directory.orgunit.readonly

Each scope set is independently sufficient for the corresponding Capsule selection. Capsule requests only the token profiles used by the enabled source: an Enterprise-only installation does not call Reports or Vault, and a Workspace-only installation does not call Discovery Engine or list users for personal-agent discovery. If you add another source later, update the DWD entry with the new union before reinstalling.

Use the value shown by Capsule if it differs from this reference; it reflects the current release and your selected sources.

Prepare each selected source

Complete these checks before returning to Connect with Google.

Gemini Enterprise

In the Google Cloud console:

  1. Select the project containing Gemini Enterprise.
  2. Confirm that the OAuth installer has Editor or Owner on the project.
  3. Confirm that the project ID entered in Capsule is correct.

During OAuth authorization, Capsule automatically:

  • enables the Discovery Engine API (discoveryengine.googleapis.com);
  • enables the Admin SDK API (admin.googleapis.com);
  • enables the Compute Engine API (compute.googleapis.com);
  • grants Capsule's service account Discovery Engine Viewer (roles/discoveryengine.viewer);
  • grants Capsule's service account Compute Viewer (roles/compute.viewer);
  • validates access to the project.

These APIs and IAM grants remain in the customer project until an administrator removes them. Capsule does not modify agents, sessions, data stores, or Gemini Enterprise configuration.

Gemini in Workspace

Assign the Vault license

  1. In the Google Admin console, go to Billing > Subscriptions.
  2. Open Google Vault.
  3. Assign a Vault license to the Workspace admin email if one is not included automatically.
  4. Assign Vault coverage to every user whose Gemini app conversations Capsule must collect.

With partial-domain licensing, new users are not necessarily licensed automatically. Include license assignment in your onboarding process.

Assign the Vault privileges

A customer Super Admin must assign these privileges before installation. Capsule does not grant Google Workspace administrator roles; installation verifies the delegated account's existing Vault access and then uses that authority for its matter and exports.

  1. In the Google Admin console, go to Account > Admin roles.
  2. Create or open the role assigned to the Workspace admin email.
  3. Under Google Vault, enable:
    • Manage Matters;
    • Manage Searches;
    • Manage Exports.
  4. Assign the role to the Workspace admin email.
  5. If the role is OU-scoped, ensure its scope covers every custodian Capsule is expected to collect.

Creating an export requires both Manage Searches and Manage Exports. Manage Matters is required because Capsule creates and reuses its own matter when one is not already configured.

Confirm services and history

  1. Confirm the Google Vault service is on for the Workspace admin.
  2. Confirm the Gemini app is on for covered users.
  3. Review the Gemini app conversation-history setting and its auto-delete period.
  4. If your governance policy requires longer preservation, configure Gemini app retention or holds in Vault through your normal legal/compliance process.

Retention affects what remains available to export; it does not change Capsule's authorization.

Connect and verify

  1. Return to the Capsule installation card.
  2. Select Continue to reach Authorize & verify.
  3. Select Connect with Google.
  4. Sign in with an account from the Workspace domain you entered.
    • For Enterprise, this account must have the required GCP project role and Directory access.
    • For Workspace, use the prepared Workspace admin account unless your organization intentionally separates the OAuth installer from the delegated admin.
    • When both are selected, the sign-in account must satisfy the Enterprise installer requirements; the Workspace admin field identifies the delegated Workspace/Vault account.
  5. Review and approve Google's OAuth consent.
  6. Wait for Capsule to return to the installation result.

Capsule validates the selected sources during installation. An authorized source with no current data is valid. Immediately after setup, the result can show Provisioned - verifying access while the first collection runs.

Verify the first sync in Capsule:

  • For Gemini Enterprise, check Inventory for shared and personal agents and Observability for sessions.
  • For Gemini in Workspace, check Inventory for per-user agents named Gemini for Workspace - <user email>.
  • After Vault exports are processed, check Observability for Gemini app sessions and prompt-response messages.

Initial Workspace content collection can take longer than a normal API sync because Google prepares Vault exports asynchronously.

Customer-visible behavior

Gemini Enterprise

Capsule reads the configured GCP project, discovers agents and related resources across supported locations, lists Workspace users, and reads available sessions and turns. The customer-project IAM roles granted to Capsule are viewer roles.

Capsule does not modify agents, sessions, data stores, or Gemini Enterprise configuration. The enabled APIs and Capsule service-account IAM grants remain visible in the customer project until an administrator removes them.

Workspace Reports

Capsule calls the Gemini-specific Admin SDK Reports feed with the Workspace admin identity. Google retains this feed from June 20, 2025 onward, with a rolling maximum of 180 days.

In the current release, Capsule uses Reports to identify standalone Gemini-app users and create their Capsule agent records. Reports provides activity metadata only; it never contains prompt or response text. Capsule does not currently create visible utilization activities from these events, and it ignores embedded Gmail/Docs/Meet/etc. events.

Reports access is read-only. It does not create or modify objects in the customer's Google Workspace account.

Google Vault

Capsule uses Google Vault to obtain standalone Gemini-app prompt and response content. The following objects are visible to authorized customer Vault administrators:

  1. Capsule creates or reuses an open matter named Capsule Gemini Content [<identifier>] in the customer's Vault.
  2. It resolves the customer's root organizational-unit ID through the Directory API and creates organization-scoped XML exports for one-day UTC windows, starting with a 90-day backfill.

Capsule reuses the matter and does not automatically close or delete it. Google makes completed export objects available for 15 days and then deletes them. Capsule does not change or delete users' Gemini conversations, retention rules, or holds.

Google allows no more than 20 simultaneous Vault exports across the organization, shared by Capsule and all other Vault users. Existing customer eDiscovery work can therefore delay Capsule exports.

Data coverage and limitations

DataGemini EnterpriseGemini in Workspace
Shared and custom Enterprise agentsYesNo
Discovery Engine sessions and turnsYesNo
Standalone Gemini app user discoveryNoYes, through Reports
Standalone Gemini app prompts and responsesNoYes, when available through Vault
Content detections on collected messagesYesYes, for Vault-exported content
Embedded Gemini use in Gmail, Docs, Meet, and other Workspace appsNoNot in the current Capsule release

Additional constraints:

  • Reports history is limited to 180 days; Capsule's current Vault initial backfill is 90 days.
  • Vault returns only data that remains available under Google's conversation-history, deletion, licensing, retention, and hold behavior.
  • Vault adds up to 12 hours of surrounding conversation context to matching data, so export windows can overlap.
  • A Vault license does not recover content that Google already purged.

Security and offboarding

The Workspace DWD scopes, especially ediscovery, provide access to sensitive organization content. Review the DWD client, scopes, delegated admin, and Vault role regularly.

When you permanently disconnect the integration, review and remove customer-side access as appropriate:

  1. Remove or edit Capsule's DWD client in the Google Admin console.
  2. Remove the Capsule service account's viewer roles from any connected Enterprise GCP project.
  3. Review the Capsule Gemini Content [...] matter and its exports with your legal/compliance owner before closing or deleting anything.
  4. Revoke Vault privileges or licenses from a dedicated delegated admin only after confirming that no other workflow needs them.

Removing DWD access stops future scheduled authorization. It does not automatically undo APIs, IAM grants, matters, exports, retention settings, or data already collected in Capsule.

Google references

Support

Contact support@capsule.security if setup or collection remains blocked. Include:

  • the Capsule integration name and environment;
  • the selected source or sources;
  • the Google Workspace domain and, for Enterprise, the GCP project ID;
  • the exact error message and timestamp;
  • whether DWD scopes, admin roles, or licenses changed in the previous 24 hours.