Use the Google Gemini Enterprise integration to connect Gemini Enterprise, Gemini in Workspace, or both to Capsule Security.

Google uses similar names for two products that Capsule connects through different Google control planes.
| Capsule option | Also known as | Where it is administered | What Capsule collects | Customer GCP project |
|---|---|---|---|---|
| Gemini Enterprise | Agentspace; Discovery Engine | Google Cloud console | Shared and personal agents, engines, data stores, tools, sessions, prompts, responses, and citations available through Discovery Engine | Required |
| Gemini in Workspace | Gemini for Workspace | Google Workspace Admin console | Standalone Gemini app users and prompt-response conversations, using Workspace Reports and Google Vault | Not required |
Select both options if your organization uses both products. They complement each other; selecting one does not collect data from the other.
Current Workspace coverage: Capsule collects the standalone Gemini app, including conversations created at
gemini.google.com. It does not currently collect Gemini side-panel or embedded feature activity from Gmail, Docs, Drive, Meet, Sheets, Slides, Chat, Keep, Classroom, or Vids. Google Vault does not make the prompt and response content from those embedded experiences available for export.
Before opening the integration, identify:
- A Google Workspace Super Admin who can authorize domain-wide delegation (DWD). Google permits only a Super Admin to add or edit a DWD client.
- Your primary Google Workspace domain, such as
example.com. - A maintenance owner for the integration. Changes to DWD scopes, admin roles, licenses, or the delegated admin account can stop collection.
- A browser session that can complete the Google OAuth redirect. Complete the setup in the same browser without clearing site data between configuration and authorization.
Note: According to Google, changes to DWD settings can take up to 24 hours to propagate, although they typically take effect sooner. For details, see Control API access with domain-wide delegation.
You need:
- A Google Cloud project containing your Gemini Enterprise / Discovery Engine deployment.
- The project ID, not the project name or number.
- A Google account in the Workspace domain with Editor or Owner on the project. Capsule uses this account during installation to enable APIs and grant read-only roles.
- Permission for that account to list Workspace users. A Super Admin satisfies this requirement; alternatively, use an appropriately delegated Directory administrator.
The current Capsule Workspace option includes both Reports metadata and Vault content collection and therefore requires Google Vault.
Prepare one Workspace admin email. Capsule uses this address as its delegated Google identity for Reports, Directory organizational-unit lookup, Vault operations, and Vault export downloads. The account must:
- be an active Google Workspace Super Admin in the domain you enter;
- have the Google Admin Reports privilege, which permits access to usage reports and audit logs;
- have the Organizational Units > Read privilege, which permits Capsule to resolve the root organizational-unit ID through the Directory API;
- have the Google Vault service turned on;
- have a Vault license;
- have the Vault privileges Manage Matters, Manage Searches, and Manage Exports.
Super Admins normally include the Reports and Organizational Units privileges. They are listed explicitly so you can verify the delegated account if your organization uses custom or scoped administrator roles.
Treat this as a sensitive administrative account. Capsule does not collect only this admin's data; it impersonates the account to run organization-scoped API operations allowed by its roles.
The delegated Workspace admin cannot currently be changed in place. To use a different account, prepare its licenses, roles, service access, and DWD prerequisites, then reinstall the integration with the new admin email.
Every user whose Gemini app conversations you want Capsule to collect must also have Vault coverage. If your edition uses add-on licenses, assign a license to the Workspace admin and every covered user before setup.
Google currently includes Vault with these editions:
- Business Plus
- Enterprise Standard and Enterprise Plus
- Frontline Standard and Frontline Plus
- All Education editions
- Domain-verified Enterprise Essentials and Enterprise Essentials Plus
- Legacy G Suite Business
An add-on may be available for other editions. Edition names and Gemini availability alone do not guarantee Vault access; confirm compatibility through Google Sales, your reseller, or your Google billing channel.
Also confirm that:
- the Gemini app is enabled for the users you intend to monitor;
- your Gemini conversation-history settings retain the period you need;
- any Vault retention rules or holds have been reviewed and approved by your legal or compliance owner.
Capsule does not create or change retention rules or holds. A badly configured Vault retention rule can irreversibly purge data, so test retention changes on a small scope first.
Use this flow once whether you connect Enterprise, Workspace, or both. The Capsule installation card generates the exact DWD scope union for your selection.
- In Capsule, go to Integrations.
- Find Google Gemini Enterprise and select Install.
- Under Choose what to connect, select:
- Gemini Enterprise;
- Gemini in Workspace; or
- both.
- Select Continue.
- Enter your Google Workspace domain.
- If you selected Gemini Enterprise, enter the Project ID for its Google Cloud project.
- If you selected Gemini in Workspace, enter the prepared Workspace admin email.
Keep this page open. It displays the environment-specific Capsule Client ID and the exact OAuth scopes to authorize.
- Sign in to the Google Workspace Admin console as a Super Admin.
- Go to Security > Access and data control > API controls > Manage Domain Wide Delegation.
- Select Add new.
- Copy the Client ID from the Capsule installation card. Use the value shown for this integration environment.
- Copy the complete comma-separated OAuth scopes value from Capsule and paste it into OAuth scopes.
- Select Authorize.
- Open the new client's details and verify that every scope is present.
If your organization uses multi-party approval for DWD changes, a second Super Admin must approve the authorization before it becomes active.
Do not add scopes for a source you did not select. If you change your selection later, update the same DWD entry with the new scope union before reinstalling.
Capsule displays the required union automatically. This table explains why each scope is requested.
| Scope | Required for | Purpose |
|---|---|---|
https://www.googleapis.com/auth/admin.directory.user.readonly | Gemini Enterprise | List Workspace users for personal-agent discovery |
https://www.googleapis.com/auth/cloud-platform | Gemini Enterprise and Gemini in Workspace | Read Discovery Engine resources; for Workspace, download Google-generated Vault export objects |
https://www.googleapis.com/auth/admin.reports.audit.readonly | Gemini in Workspace | Read Gemini activity reports for the Workspace domain |
https://www.googleapis.com/auth/admin.directory.orgunit.readonly | Gemini in Workspace | Resolve the Directory organizational-unit identifier used for Vault collection |
https://www.googleapis.com/auth/ediscovery | Gemini in Workspace | Create/reuse a Vault matter and create, inspect, and download exports |
The common scope sets are:
Gemini Enterprise only
https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/cloud-platformGemini in Workspace only
https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/ediscovery,https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/admin.directory.orgunit.readonlyBoth
https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/ediscovery,https://www.googleapis.com/auth/admin.directory.orgunit.readonlyEach scope set is independently sufficient for the corresponding Capsule selection. Capsule requests only the token profiles used by the enabled source: an Enterprise-only installation does not call Reports or Vault, and a Workspace-only installation does not call Discovery Engine or list users for personal-agent discovery. If you add another source later, update the DWD entry with the new union before reinstalling.
Use the value shown by Capsule if it differs from this reference; it reflects the current release and your selected sources.
Complete these checks before returning to Connect with Google.
In the Google Cloud console:
- Select the project containing Gemini Enterprise.
- Confirm that the OAuth installer has Editor or Owner on the project.
- Confirm that the project ID entered in Capsule is correct.
During OAuth authorization, Capsule automatically:
- enables the Discovery Engine API (
discoveryengine.googleapis.com); - enables the Admin SDK API (
admin.googleapis.com); - enables the Compute Engine API (
compute.googleapis.com); - grants Capsule's service account
Discovery Engine Viewer(roles/discoveryengine.viewer); - grants Capsule's service account
Compute Viewer(roles/compute.viewer); - validates access to the project.
These APIs and IAM grants remain in the customer project until an administrator removes them. Capsule does not modify agents, sessions, data stores, or Gemini Enterprise configuration.
- In the Google Admin console, go to Billing > Subscriptions.
- Open Google Vault.
- Assign a Vault license to the Workspace admin email if one is not included automatically.
- Assign Vault coverage to every user whose Gemini app conversations Capsule must collect.
With partial-domain licensing, new users are not necessarily licensed automatically. Include license assignment in your onboarding process.
A customer Super Admin must assign these privileges before installation. Capsule does not grant Google Workspace administrator roles; installation verifies the delegated account's existing Vault access and then uses that authority for its matter and exports.
- In the Google Admin console, go to Account > Admin roles.
- Create or open the role assigned to the Workspace admin email.
- Under Google Vault, enable:
- Manage Matters;
- Manage Searches;
- Manage Exports.
- Assign the role to the Workspace admin email.
- If the role is OU-scoped, ensure its scope covers every custodian Capsule is expected to collect.
Creating an export requires both Manage Searches and Manage Exports. Manage Matters is required because Capsule creates and reuses its own matter when one is not already configured.
- Confirm the Google Vault service is on for the Workspace admin.
- Confirm the Gemini app is on for covered users.
- Review the Gemini app conversation-history setting and its auto-delete period.
- If your governance policy requires longer preservation, configure Gemini app retention or holds in Vault through your normal legal/compliance process.
Retention affects what remains available to export; it does not change Capsule's authorization.
- Return to the Capsule installation card.
- Select Continue to reach Authorize & verify.
- Select Connect with Google.
- Sign in with an account from the Workspace domain you entered.
- For Enterprise, this account must have the required GCP project role and Directory access.
- For Workspace, use the prepared Workspace admin account unless your organization intentionally separates the OAuth installer from the delegated admin.
- When both are selected, the sign-in account must satisfy the Enterprise installer requirements; the Workspace admin field identifies the delegated Workspace/Vault account.
- Review and approve Google's OAuth consent.
- Wait for Capsule to return to the installation result.
Capsule validates the selected sources during installation. An authorized source with no current data is valid. Immediately after setup, the result can show Provisioned - verifying access while the first collection runs.
Verify the first sync in Capsule:
- For Gemini Enterprise, check Inventory for shared and personal agents and Observability for sessions.
- For Gemini in Workspace, check Inventory for per-user agents named
Gemini for Workspace - <user email>. - After Vault exports are processed, check Observability for Gemini app sessions and prompt-response messages.
Initial Workspace content collection can take longer than a normal API sync because Google prepares Vault exports asynchronously.
Capsule reads the configured GCP project, discovers agents and related resources across supported locations, lists Workspace users, and reads available sessions and turns. The customer-project IAM roles granted to Capsule are viewer roles.
Capsule does not modify agents, sessions, data stores, or Gemini Enterprise configuration. The enabled APIs and Capsule service-account IAM grants remain visible in the customer project until an administrator removes them.
Capsule calls the Gemini-specific Admin SDK Reports feed with the Workspace admin identity. Google retains this feed from June 20, 2025 onward, with a rolling maximum of 180 days.
In the current release, Capsule uses Reports to identify standalone Gemini-app users and create their Capsule agent records. Reports provides activity metadata only; it never contains prompt or response text. Capsule does not currently create visible utilization activities from these events, and it ignores embedded Gmail/Docs/Meet/etc. events.
Reports access is read-only. It does not create or modify objects in the customer's Google Workspace account.
Capsule uses Google Vault to obtain standalone Gemini-app prompt and response content. The following objects are visible to authorized customer Vault administrators:
- Capsule creates or reuses an open matter named
Capsule Gemini Content [<identifier>]in the customer's Vault. - It resolves the customer's root organizational-unit ID through the Directory API and creates organization-scoped XML exports for one-day UTC windows, starting with a 90-day backfill.
Capsule reuses the matter and does not automatically close or delete it. Google makes completed export objects available for 15 days and then deletes them. Capsule does not change or delete users' Gemini conversations, retention rules, or holds.
Google allows no more than 20 simultaneous Vault exports across the organization, shared by Capsule and all other Vault users. Existing customer eDiscovery work can therefore delay Capsule exports.
| Data | Gemini Enterprise | Gemini in Workspace |
|---|---|---|
| Shared and custom Enterprise agents | Yes | No |
| Discovery Engine sessions and turns | Yes | No |
| Standalone Gemini app user discovery | No | Yes, through Reports |
| Standalone Gemini app prompts and responses | No | Yes, when available through Vault |
| Content detections on collected messages | Yes | Yes, for Vault-exported content |
| Embedded Gemini use in Gmail, Docs, Meet, and other Workspace apps | No | Not in the current Capsule release |
Additional constraints:
- Reports history is limited to 180 days; Capsule's current Vault initial backfill is 90 days.
- Vault returns only data that remains available under Google's conversation-history, deletion, licensing, retention, and hold behavior.
- Vault adds up to 12 hours of surrounding conversation context to matching data, so export windows can overlap.
- A Vault license does not recover content that Google already purged.
The Workspace DWD scopes, especially ediscovery, provide access to sensitive organization content. Review the DWD client, scopes, delegated admin, and Vault role regularly.
When you permanently disconnect the integration, review and remove customer-side access as appropriate:
- Remove or edit Capsule's DWD client in the Google Admin console.
- Remove the Capsule service account's viewer roles from any connected Enterprise GCP project.
- Review the
Capsule Gemini Content [...]matter and its exports with your legal/compliance owner before closing or deleting anything. - Revoke Vault privileges or licenses from a dedicated delegated admin only after confirming that no other workflow needs them.
Removing DWD access stops future scheduled authorization. It does not automatically undo APIs, IAM grants, matters, exports, retention settings, or data already collected in Capsule.
- Control API access with domain-wide delegation
- Gemini in Workspace Apps activity events
- Reports API scopes
- Google Workspace administrator privilege definitions
- Vault licensing
- Assign Vault licenses
- Set up Vault privileges
- Search and export Gemini app conversations
- Vault-supported Gemini app data
- Retain Gemini app messages with Vault
- Vault export contents
- Vault export limits and lifetime
Contact support@capsule.security if setup or collection remains blocked. Include:
- the Capsule integration name and environment;
- the selected source or sources;
- the Google Workspace domain and, for Enterprise, the GCP project ID;
- the exact error message and timestamp;
- whether DWD scopes, admin roles, or licenses changed in the previous 24 hours.