Sublime Cloud - Google Workspace

📘

Google Workspace Super Administrator Required

To add a Google Workspace message source, you need to be a super administrator for your Google Workspace organization or get the help of a super administrator.

You can add a Google Workspace message source when setting up your Sublime organization or by going to Admin > Message Sources > New message source in the Sublime dashboard and selecting Google Workspace.

Overview

If you're using Sublime Cloud, simply select "Google Workspace" and follow the prompts to authorize access on behalf of your organization. The Sublime App for the Google Workspace Marketplace is private so you can't find it by searching the app directory. Follow this link to the Sublime Cloud Platform Listing.

Installing the app from the Google Workspace Marketplace

When you open the Sublime Cloud Platform listing, Google walks you through installing the app for your domain:

  1. Click Admin install.
  2. Review the requested permissions and click Continue.
  3. Choose who the app installs for:
    • Everyone at your organization, the recommended option for a Google Workspace message source. This grants Sublime the access it needs for every mailbox in your domain.
    • Certain groups or organizational units, which limits the install to the OUs or groups you select.
  4. Click Finish.
  5. Confirm the install landed. In the Google Workspace Admin console, go to Apps > Marketplace apps > Sublime Cloud Platform and check that the status is active and the install scope covers every OU holding mailboxes you want Sublime to protect.
⚠️

Install for everyone, not a subset of OUs

If you scope the install to specific organizational units or groups instead of Everyone at your organization, only mailboxes in those OUs are authorized. Sublime can't sync or protect mailboxes outside the granted scope, and those mailboxes typically surface as unauthorized during onboarding or sync (see Common setup errors below). Install for Everyone at your organization unless you have a specific reason to stage the rollout by OU, and if you do stage it, expand the install to cover every OU you want Sublime to protect.

Required Google Workspace permissions

Installing the app grants Sublime full mailbox access (https://mail.google.com/, which covers reading, composing, sending, and permanently deleting mail) and calendar write access (calendar.events), which Sublime uses to remediate malicious messages and calendar invites. It also grants read-only access to your users, groups, organizational units, domains, and admin audit reports, plus access to your Workspace alerts (apps.alerts) so Sublime can process reported phishing.

You don't configure these individually. Google grants them when a super administrator completes the install above.

Common setup errors

If a Google Workspace message source doesn't finish setting up, or an authorized mailbox stops syncing later, the cause is almost always one of the following.

"Requested client not authorized"

This means Google is rejecting Sublime's request to access a mailbox because domain-wide delegation for the Sublime app isn't configured correctly, for that mailbox.

Common causes:

  • The Marketplace install was scoped to specific organizational units or groups (see above), and the affected mailbox falls outside that scope.
  • The Sublime app was uninstalled, or its Marketplace license was suspended or revoked, after the message source was originally set up.
  • A mailbox was moved into an OU that wasn't included in the original install scope.

To resolve it, confirm in the Google Workspace Admin console (Apps > Marketplace apps > Sublime Cloud Platform) that the app's status is active and that it's installed for every OU containing mailboxes you want Sublime to protect.

"Invalid email or token"

This appears during the admin authorization step of setup, when the super administrator signs in to grant Sublime access. It means the sign-in identity token Google returned couldn't be validated, most often because the sign-in session expired, the browser used a cached or mismatched account, or the authorization link was reused after it had already completed.

To resolve it, start the message source setup again from the Sublime dashboard and complete the Google sign-in prompt in a fresh browser session, signed in as the intended super administrator.

Related