Employee offboarding is one of the most time-sensitive access control workflows for IT teams. When an employee leaves, admins need to close active sessions, revoke third-party app access, invalidate backup verification codes, transfer business-critical files, preserve email continuity, and hand off calendar access without missing a step.
AssetSonar’s Google Workspace offboarding actions help IT teams run these Google Workspace actions from AssetSonar using a secure service account setup with Domain-Wide Delegation. Once connected, these actions can be used on member records and in structured offboarding workflows to reduce manual effort and close access gaps during employee exits.
This guide walks you through creating a Google Cloud service account, authorizing domain-wide delegation in Google Admin, connecting the integration in AssetSonar, and running Google Workspace offboarding actions.
1. Before you begin
Before setting up Google Workspace offboarding actions, make sure you have:
- Google Workspace Super Admin access
- Access to Google Cloud Console
- Permission to create service accounts
- Permission to configure Domain-Wide Delegation in Google Admin
- AssetSonar members with primary email addresses that match their Google Workspace users
Note: You can sync users through the Google Workspace Users Integration. To track Google Workspace as cloud software for license and user visibility, see our guide on Google Workspace Cloud Software Integration.
This setup uses a Google service account with domain-wide delegation, so it must be configured separately from your existing Google Workspace user sync or cloud software integration.
2. Understand what Google Workspace offboarding actions help secure
Google Workspace offboarding often includes both security actions and handoff actions. AssetSonar helps admins run these actions from one place.
| Offboarding risk | Google Workspace action in AssetSonar |
| The user remains signed in on devices or active sessions | Sign Out All Sessions |
| Third-party apps retain access to the user’s Google account | Revoke All OAuth Token Grants |
| Backup MFA codes remain usable after offboarding | Invalidate Backup Verification Codes |
| Important Drive files remain under the departing user’s ownership | Transfer Drive Data |
| Internal or external contacts continue emailing an unmanaged inbox | Set Email Auto-Reply |
| Calendar ownership or visibility is lost during handoff | Share Calendar Access |
These actions help IT teams standardize Google Workspace offboarding and reduce the risk of missed manual steps.
3. Create a service account in Google Cloud Console
First, create a service account in Google Cloud Console. AssetSonar uses this service account to authenticate with Google Workspace and run offboarding actions.
To create the service account:
- Log in to Google Cloud Console.

- Select the relevant project or create a new project.

- Go to IAM & Admin → Service Accounts.

- Click Create Service Account
- Enter a clear name, such as AssetSonar Offboarding Actions.
- Service Account ID will be created automatically.

- Complete the service account creation flow.
Next, enable Domain-Wide Delegation for the service account:
- Open the service account you created.
- Go to the service account details.
- Enable Domain-Wide Delegation.
- Copy the service account Client ID. You will need this in Google Admin Console

4. Authorize Domain-Wide Delegation in Google Admin Console
Next, authorize the service account in Google Admin Console so it can run the required Google Workspace actions.
To authorize Domain-Wide Delegation:
- Log in to Google Admin Console as a Super Admin.
- Go to Security → Access and data control → API Controls.

- Open Domain-wide Delegation.
- Click Add new.

- In the Client ID field, paste the service account Client ID from Google Cloud Console.
- In the OAuth scopes field, paste the required scopes.
- Click Authorize.

Use the following scope string:
https://www.googleapis.com/auth/admin.directory.user.security,https://www.googleapis.com/auth/admin.datatransfer,https://www.googleapis.com/auth/admin.datatransfer.readonly,https://www.googleapis.com/auth/gmail.settings.sharing,https://www.googleapis.com/auth/calendar
These scopes allow AssetSonar to run supported offboarding actions, including session sign-out, OAuth token revocation, backup code invalidation, Drive transfer, Gmail auto-reply, and calendar sharing.
5. Create and download the service account key
After creating the service account, generate a JSON key.
To create the key:
- Open the service account in Google Cloud Console.
- Go to Keys.

- Click Add Key → Create new key.
- Select JSON.

- Click Create.
Google downloads a JSON key file to your device.
From this file, keep the following values ready:
- client_email
- private_key
You will enter these values in AssetSonar while connecting the integration.
Warning: Store the JSON key securely. The private key should not be shared through email, chat, or unsecured documents.
6. Connect Google Workspace offboarding actions in AssetSonar
After setting up the service account and authorizing scopes in Google Admin Console, connect the integration in AssetSonar.
To connect the integration:
- Go to Settings → Integrations → User Provisioning & SSO.
- Locate Google Workspace — Offboarding Actions.
- Select Enabled.
- Click Configure.

- In the Configure Google Workspace Offboarding popup, enter the following details:
- Client Email
- Private Key
- Super Admin Email

- Click Connect.
- Click Update to save the integration settings.
Use the client_email and private_key values from the JSON key file downloaded from Google Cloud Console.
The Super Admin Email should be the email address of a Google Workspace Super Admin in your domain. AssetSonar uses this account as the impersonation target for admin-level Google Workspace actions.
7. Validate the connection
When you save the integration, AssetSonar validates the credentials and required access. If validation succeeds, the integration is marked as connected.
If validation fails, review the error message and check that:
- The Client Email and Private Key were copied correctly.
- The correct service account Client ID was added in Google Admin Console.
- All required OAuth scopes were added.
- The Super Admin Email belongs to a valid Super Admin in the Google Workspace domain.
8. Run Google Workspace offboarding actions from a member record
Once the integration is connected, you can run Google Workspace offboarding actions from the relevant member record.
To run an action:
- Go to Members & Access → Members.
- Open the member being offboarded.
- Click More.
- Select the relevant Google Workspace offboarding action.
- Enter any required information.
- Confirm the action.
AssetSonar uses the member’s primary email address to identify the matching Google Workspace user.
Warning: Make sure the member’s email address in AssetSonar matches their Google Workspace email address. If the member does not have a primary email address, AssetSonar cannot run Google Workspace actions for that member.
9. Enter required inputs for handoff actions
Some Google Workspace offboarding actions can run directly from the member record, while others require additional information before they can run.
For example:
- Transfer Drive Data requires a recipient email address.
- Set Email Auto-Reply may require a subject, message, forwarding option, or forwarding email.
- Share Calendar Access requires the email address of the user receiving calendar access.
Enter the required details in the action popup before confirming the action.
Note: Invalidate Backup Verification Codes invalidates backup codes only. Primary MFA methods such as authenticator apps, hardware security keys, and passkeys may need to be handled through your organization’s broader Google Workspace account suspension or deactivation process, where applicable.
10. Run Google Workspace actions in a security-first order
When running multiple Google Workspace actions during offboarding, use the security-first order below:
- Sign Out All Sessions
- Revoke All OAuth Token Grants
- Invalidate Backup Verification Codes
- Set Email Auto-Reply
- Share Calendar Access
- Transfer Drive Data
The first three actions help close active access paths. Run them before data handoff actions such as auto-replies, calendar sharing, and Drive transfer.
Note: Drive transfer may take longer than the other actions because Google processes the transfer asynchronously.
11. Review action history
AssetSonar records Google Workspace action history on the member detail page.
Use the history to review:
- Which action was run
- When the action was run
- Who initiated the action
- Whether the action succeeded or failed
- Any relevant error or status details
This gives admins an audit trail for offboarding actions taken on a member’s Google Workspace account.
12. Use Google Workspace actions in offboarding workflows
Google Workspace offboarding actions can be used with other AssetSonar offboarding and automation workflows. This allows IT teams to combine Google Workspace actions with related offboarding tasks such as hardware retrieval, software license reclamation, approvals, and handoffs.
For example, an offboarding workflow can include security actions such as signing the user out of Google Workspace and revoking OAuth app access, followed by handoff actions such as transferring Drive files or sharing calendar access.
To build structured employee exit workflows, read our guide on [How-To] Create Offboarding Workflows in AssetSonar.
To learn how to automate broader IT workflows, see [How-To] Automate IT Workflows in AssetSonar.
Ready to secure Google Workspace offboarding?
With Google Workspace offboarding actions in AssetSonar, IT teams can run key account security and handoff actions from one place. You can terminate sessions, revoke third-party app access, invalidate backup verification codes, transfer Drive data, set email continuity, and share calendar access as part of a structured offboarding process.
Need help setting up Google Workspace Offboarding Actions? Reach out to us at support@ezo.io — we’re happy to assist.
![[How-To] Initiate and Track Employee Offboarding Requests in AssetSonar](https://cdn.ezo.io/wp-content/uploads/2026/08/31095430/Offboarding-ITSM-Banner.png)
![[How-To] Automate IT Asset Lifecycle in AssetSonar: From Procurement to Retirement](https://cdn.ezo.io/wp-content/uploads/2026/07/28072313/AssetSonar-Automated-Asset-Lifecycle-Banner-1200x600-1.png)
![[How-To] Create Offboarding Workflows in AssetSonar](https://cdn.ezo.io/wp-content/uploads/2026/08/31065059/Offboarding-Banner.png)