Manage users
Create Google User
Create Google User
@Reset Google MFA/Password with the password scope and generatePassword: true once they can receive the credential over Slack DM, or send them through Google’s own recovery flow.Tool name: @Create Google UserInputs:emailUsername(required) - username portion of the new primary email, or the full addressfirstName,lastName(required)domain- domain for the primary email. Defaults to the primary domain on your Google Workspace integration; set it to provision on a secondary verified domainsecondaryEmail,recoveryEmail,recoveryPhoneorgUnitPath- for example/Engineering. Defaults to/department,jobTitle,managerEmail
@Check Google Email Availability first so the agent does not attempt to create an account on an address already in use.Suspend Google User
Suspend Google User
@Suspend Google UserRestore Google User
Restore Google User
@Restore Google UserReset Google MFA/Password
Reset Google MFA/Password
@Reset Google MFA/PasswordInputs:userEmail- the target userscope-mfa,password, orbothgeneratePassword- defaults totruefor password resets. Set it tofalsewhen the user cannot receive a Slack DM, so Google’s own recovery flow takes over insteadsignUserOut- optional. Signs the user out of every active session
generatePassword set to false.Manage email addresses
Check Google Email Availability
Check Google Email Availability
@Create Google User or @Create Email Alias so it can offer a different address instead of failing on a conflict.Tool name: @Check Google Email AvailabilityOutput:isAvailable-truewhen the address is freereason- explains the conflict when unavailable
Create Email Alias
Create Email Alias
@Create Email AliasPair it with @Check Google Email Availability so the agent does not try to add an alias that is already claimed as a primary email or alias somewhere else.Manage groups
Delete Google Group
Delete Google Group
@Delete Google GroupIdentify the group by its name or email.@Create Google Group, @List Google Groups, @Get Google Group Info, @Check Google Group Membership, @Add Google Group Member, @Remove Google Group Member, @Update Google Group). They share the behavior of the matching workflow actions.Offboard users
Transfer Google User Files
Transfer Google User Files
@Transfer Google User FilesInputs:sourceUserEmail,destinationUserEmail(required)driveTransferScope-ALL(default),PRIVATE,SHARED, orNONEtransferCalendarEvents- defaulttruereleaseCalendarResources- release rooms and equipment on future events. Only applies when calendar transfer is enabled.
admin.datatransfer scope on domain-wide delegation. See the setup guide.Setup
Connect Google Workspace
Enable data transfer (optional)
admin.datatransfer scope on domain-wide delegation before writing rules that use @Transfer Google User Files.Attach the tools to an agent
Write a rule
Example rules
When someone locks themselves out of Google, use @Check Google Email Availability to confirm the address exists, then offer @Reset Google MFA/Password. Reset MFA only when they mention a new device, password only when they forgot it, and both after a suspected compromise. In generatePassword mode, deliver the temporary password through a Slack DM.
When a manager reports someone is leaving, ask for the source and destination user, then run @Transfer Google User Files with driveTransferScope ALL and transferCalendarEvents true. After the transfer ID comes back, run @Suspend Google User on the source account and confirm both steps in the reply.
Best practices
- Check before you create. Pair
@Check Google Email Availabilitywith@Create Google Userand@Create Email Aliasso the agent picks up conflicts before it tries to write. - Transfer, then suspend. Run
@Transfer Google User Filesbefore@Suspend Google Userduring offboarding. Suspended users cannot start a transfer. - Deliver temporary passwords privately. When you use
@Reset Google MFA/PasswordingeneratePasswordmode, have the rule send the password through a private Slack DM instead of putting it in the ticket. - Gate the destructive tools. Put
@Delete Google Group,@Suspend Google User, and any write ingeneratePasswordmode behind Requires approval in rules an agent can reach on its own.