Skip to main content
Solved

Our integration of WORKSPACE_PRIVILEGES requires Super Admin privileges, which conflicts with our organization's security policy

  • November 14, 2025
  • 1 reply
  • 26 views

Forum|alt.badge.img+1

Hi team,

We are currently setting up the ingestion of WORKSPACE_PRIVILEGES logs from Google Workspace. According to the documentation, this requires assigning the Super Admin role to the service account.

Due to internal company security constraints, we are unable to grant Super Admin privileges to a service account. Are there any alternative configurations, workarounds, or more granular permission sets that would allow us to ingest this log type without full Super Admin access?

Thanks for your help.

Best answer by cmmartin_google

There is no workaround due to Workspace only permitting the API access if you have Super User privilege; however, as a Context source as far as I know it is not used by anything out of the box, and so it can be safely omitted as a context log source for collection. 

1 reply

cmmartin_google
Staff
Forum|alt.badge.img+11

There is no workaround due to Workspace only permitting the API access if you have Super User privilege; however, as a Context source as far as I know it is not used by anything out of the box, and so it can be safely omitted as a context log source for collection.