Skip to main content
Google Workspace provides agent tools for identity, group, and mailbox operations. Reference them in using @ mentions so your agent can create accounts, adjust access, reset credentials, and hand off data without a handoff. Every tool listed here mirrors the Google Workspace workflow action of the same name, so the behavior and permissions match what your workflows already do.

Manage users

Create Google User

Creates a new Google Workspace user with a randomly generated password. The password is not returned. Give the user access by running @Reset Google MFA/Password with the password scope and generatePassword: true once they can receive the credential over Slack DM, or send them through Google’s own recovery flow.Tool name: @Create Google UserInputs:
  • emailUsername (required) - username portion of the new primary email, or the full address
  • firstName, lastName (required)
  • domain - domain for the primary email. Defaults to the primary domain on your Google Workspace integration; set it to provision on a secondary verified domain
  • secondaryEmail, recoveryEmail, recoveryPhone
  • orgUnitPath - for example /Engineering. Defaults to /
  • department, jobTitle, managerEmail
Call @Check Google Email Availability first so the agent does not attempt to create an account on an address already in use.
Suspends a Google Workspace user so they can no longer sign in to any Google service. Use it for offboarding, security incident response, or extended-leave lockouts.Tool name: @Suspend Google User
Unsuspends a previously suspended user, restoring access to every Google service. Use it when someone returns from leave or after a security review clears the account.Tool name: @Restore Google User
Resets multi-factor authentication, the password, or both, in one call. A password reset always requires the user to choose a new password at next sign-in. By default the tool also generates a temporary password and delivers it to the user in a private Slack DM, so it never appears in the ticket.Tool name: @Reset Google MFA/PasswordInputs:
  • userEmail - the target user
  • scope - mfa, password, or both
  • generatePassword - defaults to true for password resets. Set it to false when the user cannot receive a Slack DM, so Google’s own recovery flow takes over instead
  • signUserOut - optional. Signs the user out of every active session
If the temporary password cannot be delivered privately, the tool tells the agent to rerun with generatePassword set to false.
Any signed-in member can trigger these tools, including for another person. To limit who can reset someone else, set Requires approval on the tool in the rule, or scope the rule to the people who should use it.

Manage email addresses

Checks whether an email address is already in use as a primary email or alias in Google Workspace. Have the agent call this before @Create Google User or @Create Email Alias so it can offer a different address instead of failing on a conflict.Tool name: @Check Google Email AvailabilityOutput:
  • isAvailable - true when the address is free
  • reason - explains the conflict when unavailable
Adds an email alias to an existing user so mail sent to the alias delivers to the same inbox. Use it for role-based addresses (support@, sales@) or brand-specific addresses that route to one person.Tool name: @Create Email AliasPair it with @Check Google Email Availability so the agent does not try to add an alias that is already claimed as a primary email or alias somewhere else.

Manage groups

Deletes a Google Group. Every member loses the membership immediately, so this is a destructive change the agent confirms before running.Tool name: @Delete Google GroupIdentify the group by its name or email.
Group creation, listing, membership checks, and member add/remove are also available as agent tools (@Create Google Group, @List Google Groups, @Get Google Group Info, @Check Google Group Membership, @Add Google Group Member, @Remove Google Group Member, @Update Google Group). They share the behavior of the matching workflow actions.

Offboard users

Kicks off an asynchronous transfer of a user’s Google Drive and Calendar data to another user. Google processes the transfer in the background and Ravenna returns a transfer ID for tracking. Use it before suspending or deleting an account so nothing is lost.Tool name: @Transfer Google User FilesInputs:
  • sourceUserEmail, destinationUserEmail (required)
  • driveTransferScope - ALL (default), PRIVATE, SHARED, or NONE
  • transferCalendarEvents - default true
  • releaseCalendarResources - release rooms and equipment on future events. Only applies when calendar transfer is enabled.
At least one of Drive or Calendar must be transferred.
This tool needs the Enable User Data Transfer setting on your Google Workspace integration, plus the admin.datatransfer scope on domain-wide delegation. See the setup guide.
A tool with no execution policy set runs without asking. When Copilot drafts a rule, it suggests Requires confirmation for write tools and Requires approval for delete tools, and you can change either per rule. See tool execution policies.

Setup

1

Connect Google Workspace

Follow the Google Workspace setup guide and confirm the integration is active.
2

Enable data transfer (optional)

Turn on Enable User Data Transfer and grant the admin.datatransfer scope on domain-wide delegation before writing rules that use @Transfer Google User Files.
3

Attach the tools to an agent

Open the agent’s settings and add the Google Workspace tools you want it to use under Tools. An admin has to attach each tool before an agent or rule can call it.
4

Write a rule

Reference the tools with @ mentions in a , then test it on a real request.

Example rules

When someone locks themselves out of Google, use @Check Google Email Availability to confirm the address exists, then offer @Reset Google MFA/Password. Reset MFA only when they mention a new device, password only when they forgot it, and both after a suspected compromise. In generatePassword mode, deliver the temporary password through a Slack DM.

When a manager reports someone is leaving, ask for the source and destination user, then run @Transfer Google User Files with driveTransferScope ALL and transferCalendarEvents true. After the transfer ID comes back, run @Suspend Google User on the source account and confirm both steps in the reply.


Best practices

  • Check before you create. Pair @Check Google Email Availability with @Create Google User and @Create Email Alias so the agent picks up conflicts before it tries to write.
  • Transfer, then suspend. Run @Transfer Google User Files before @Suspend Google User during offboarding. Suspended users cannot start a transfer.
  • Deliver temporary passwords privately. When you use @Reset Google MFA/Password in generatePassword mode, have the rule send the password through a private Slack DM instead of putting it in the ticket.
  • Gate the destructive tools. Put @Delete Google Group, @Suspend Google User, and any write in generatePassword mode behind Requires approval in rules an agent can reach on its own.
Last modified on September 28, 2026