Skip to main content

Allow Google Workspace Connections

What You'll Accomplish

By the end of this tutorial, people on a Google Workspace domain — for example radiusclinic.com — can connect Gravity Rail's Gmail, Calendar, Drive, and Sheets integrations the same way a personal Gmail account already can.

You do this in the Google Admin console, not in Gravity Rail. You need a Google Workspace Super Admin (or the Service Settings privilege) for the domain.

What You'll Need

If you only have a Gravity Rail login and not the Google Admin console, send that page to whoever owns Google Workspace for your organization and stop here. A regular user cannot lift this block.

Why This Is Needed

Gravity Rail's Sign in with Google only asks Google who you are. Most Workspace domains allow that, so login works.

Gmail, Calendar, Drive, and Sheets ask for the mailbox, calendar, or files. Google treats those permissions as sensitive or restricted. Until Gravity Rail finishes Google's OAuth verification for each connector, Workspace treats the apps as unverified. Domains that block unverified third-party API access then show "This app is blocked" or admin_policy_enforced.

A personal @gmail.com account has no Workspace admin, so the same connector works there.

Step 1: Open API Controls

  1. Sign in to admin.google.com
  2. Go to Security → Access and data control → API controls
  3. Open admin.google.com/ac/owl if you cannot find that menu
  4. Click Manage third-party app access (some consoles say Manage App Access)

Step 2: Add the Gmail Client as Trusted

  1. Click Configure new app
  2. Choose OAuth App Name or Client ID
  3. Paste the Gmail client ID from Google Workspace Accounts
  4. Click Search and select the Gravity Rail app Google returns
  5. Leave the top organizational unit selected so the whole domain is covered
  6. Set Access to Google data to Trusted
  7. Click Continue, then Finish

Trusted is required for Gmail. Gmail uses restricted scopes; Limited will still fail.

Search by client ID, not by the name "Gravity Rail". Login and each connector are separate clients.

Step 3: Repeat for Calendar, Drive, and Sheets

Repeat Step 2 for the Google Calendar, Google Drive, and Google Sheets client IDs on the same page. Allowlisting one connector does not allow the others.

If you only need Sheets today, you can stop after the Sheets client. Add the others before someone tries to connect them.

Step 4: Confirm Unconfigured Apps Are Not a Hard Block

Still on API controls, open Settings (or Settings for unconfigured third-party apps).

  • If the domain doesn't allow users to access any third-party apps, that is fine — the four clients you just marked Trusted are now configured and should work.
  • If Gmail, Drive, or Calendar is Restricted under Manage Google Services, keep the Gravity Rail clients on Trusted. Limited apps cannot use restricted services.

Step 5: Retry the Connection in Gravity Rail

  1. In Gravity Rail, go to App Connections
  2. Open Gmail, Google Calendar, Google Drive, or Google Sheets
  3. Click Connect or Add account
  4. Sign in with the Workspace account (you@yourdomain.com)
  5. Approve the permissions

Use a private/incognito window if the previous attempt is still showing the blocked-app screen. Changes usually apply within a few minutes; Google documents up to 24 hours.

Confirm the Result

You are done when:

  • Google shows the normal consent screen instead of "This app is blocked"
  • Gravity Rail returns you to the connection and lists the Workspace email under Active
  • An assistant with that integration ability can see data from that Google account

If consent still fails, confirm you pasted the production client ID for that connector (not the login client) and that the app is Trusted, not Limited.

What's Next