Connect Google Workspace
This page walks you through the one-time setup — click by click. Afterwards Mango Inventory maintains your user list by itself: whoever is in the chosen Google groups joins automatically; whoever leaves them is deactivated. You need no IT knowledge for this, only a Google account with administrator rights. Plan for 10 minutes.
What the sync does in general is on the overview page Directory sync.
Prerequisites
Section titled “Prerequisites”- Premium plan in Mango Inventory — single sign-on and directory sync are part of it. Details on the pricing page.
- Owner role in Mango Inventory — only owners see the Settings → Single sign-on page.
- A Google Workspace administrator account of your organization. That is the account used to manage your users in the Google Admin console. Unlike with Microsoft, everything happens in one go — so you have to be signed in with that account yourself, or do the setup together with your IT.
- Google Workspace is the service behind your Gmail, Drive and Calendar accounts on your organization’s address. Your groups are the same ones you see under “Groups” in the Google Admin console.
Setting it up
Section titled “Setting it up”Google’s pages (steps 3 to 5) appear in the language set for your Google account — the pictures below show the German view. The wording you see may differ, the order of the screens does not.
-
Open the setup page in Mango Inventory. Sign in at
app.mangoinventory.comand go to Settings → Single sign-on. At the top of the “Connect your directory” card there is a row of provider tabs — click “Google Workspace”.
-
Click “Connect Google Workspace”. Mango Inventory forwards you to Google — the rest happens on Google’s pages.
-
Choose the administrator account. Under “Choose an account” Google shows your signed-in accounts. Take your organization’s Workspace administrator account, not your private Google account. If it isn’t listed: “Use another account” and sign in with it.

-
Get past the “not verified” notice. During the pilot phase, Google shows an in-between page saying the app has not been verified yet. Click “Advanced” at the bottom of it, then “Go to Mango Inventory (unsafe)”. The notice only means that Google’s review of our app is still running — not that something is wrong. If that page doesn’t appear for you, that is fine too: Google doesn’t show it to every account. Carry on with step 5 in that case.
-
Approve the read access. Google lists three permissions, all of them read-only: “View group subscriptions on your domain”, “View groups on your domain” and “See info about users on your domain”. The checkboxes start empty: tick “Select all” — without all three ticks the sync cannot work. Mango Inventory cannot create, change or delete anything in your directory, and has no access to Gmail, Drive or Calendar. Confirm with “Continue”.

-
Back in Mango Inventory: pick the groups. Google sends you back automatically; a short “Google Workspace connected.” message appears at the top. Under “Sync settings”, open “Groups to sync” and select the groups whose people should use Mango Inventory. Check “Synced users join as” below it: that is the role everyone joining from now on receives (default: Member).

-
Look at the preview — then sync. Click “Preview changes”. The preview lists who would join, be updated or deactivated; nothing is changed yet. If the list looks right, click “Sync now” at the bottom.
Done — what happens now
Section titled “Done — what happens now”- The synced people appear in the user list right away, marked “Not signed in yet” at first. With their first sign-in via “Continue with Google” they become full users — no invitation email, no new password.
- Every night Mango Inventory reconciles the chosen groups automatically. In between you can do it by hand any time: ”⋯” at the top right of the “Directory sync” card → “Sync now”.
- Whoever is removed from every chosen group is deactivated at the next run: no more sign-in, but the history stays fully intact. Nothing is ever deleted. If the person returns to the group, their access comes back. Owners are never deactivated by the directory.
- You can end the access from either side at any time: in Mango Inventory via ”⋯” → “Disconnect”, or in your Google account under the connections to third-party apps.
- People outside your directory you keep inviting by hand — see SSO & users.
If something doesn’t work
Section titled “If something doesn’t work”- The card shows “Needs reconnecting”. Google’s access has expired or was revoked. Click “Reconnect” and sign in once more — your groups and the join role are kept. During the pilot phase this happens roughly every week; your Google administration can fix it permanently with one setting — we show how during setup.
- The card shows “Not finished”. The sign-in with Google was broken off (window closed, wrong account). Click “Finish connecting with Google” and walk steps 3 to 5 again.
- You picked the wrong account. Sign out of that account at Google or open a private window, then start again in Mango Inventory via “Reconnect”.
- The group list stays empty. Then the chosen account has no read access to the groups. Use an account with administrator rights in Google Workspace.
- More than 500 people cannot be synced by one connection. Pick narrower groups in that case, or get in touch with us.