Before you start
Have these ready:- Permission to manage Knowledge and integrations in June.
- A Google Cloud project where you can enable APIs, create a service account, and create its JSON key. Ask your Google Cloud administrator for help if any of these actions are unavailable.
- A Google Workspace super administrator to authorize domain-wide delegation and assign administrator roles.
- An active Google Workspace user to use as the delegated admin, with access to the shared drives you want to connect. We recommend a dedicated user for June Knowledge.
Where to grant permissions
The optional fields in Google Cloud control access to Cloud resources and the service account itself. Workspace delegation, administrator roles, and shared-drive access are configured separately in the steps below. See Google’s service-account creation guide.
Configure Google access
1
Enable the Google APIs
Open the Google Cloud console and select the project you will use for June Knowledge.Go to APIs & Services → Library. Search for each API below, open its page, and choose Enable:
- Google Drive API
- Google Drive Activity API
- Admin SDK API
2
Create a service account
- In Google Cloud, open IAM & Admin → Service Accounts → Create service account.
- Enter a name such as
June Knowledge. Keep the generated service-account ID. The description is optional. - Leave Permissions (optional) empty. Do not select a project role such as Owner or Editor.
- Leave Principals with access (optional) empty.
- Choose Create and close. If your console shows Create and continue, proceed through the two optional sections without adding anything, then choose Done.
client_id in the JSON key you create next. Keep it for the delegation step.3
Download a JSON key
- On the service account, open Keys.
- Choose Add key → Create new key.
- Select JSON, then choose Create.
4
Authorize domain-wide delegation
Domain-wide delegation lets the service account act on behalf of Workspace users within the authorized scopes.Choose Authorize, then open View details for the new entry and confirm that all six scopes appear. These scopes belong in Google Admin; they are not roles to select in the service-account creation screen.If your organization requires multi-party approval, another super administrator must approve the change. Delegation changes can take up to 24 hours to apply, although they usually apply sooner. See Google’s domain-wide delegation guide.
- Sign in to the Google Admin console as a super administrator.
- In the left navigation, expand Security → Access and data control, then click API controls.
- On the API controls page, find Domain-wide delegation and click Manage Domain Wide Delegation. This is a control inside the page, not a separate item in the left navigation. If you have the Admin search dropdown open, close it to navigate using the sidebar.
- Choose Add new.
- In Client ID, paste the service account’s numeric client ID. Use the number, not its email address or your Cloud project ID.
- In OAuth scopes, paste the complete comma-separated line below.
5
Give the delegated user its Workspace admin roles
The delegated admin is a Google Workspace user, such as
june-knowledge@example.com. June uses this user’s access to read Drive content and directory information.In Google Admin, sign in as a super administrator and:- Open Directory → Users.
- Choose an existing dedicated user, or use Add new user to create one.
- Open that user’s Admin roles and privileges.
- Assign Groups Reader, User Management Admin, and Storage Admin, then save.
iam.gserviceaccount.com is a different identity. The delegated user does not need the Super Admin role for this connection.Record the user’s primary email address for June’s Delegated admin email field, and keep the account active. These are Google Workspace admin roles; they will not appear in Google Cloud’s project-role picker.See Google’s administrator-role guide for each role’s permissions.6
Give the delegated user access to your shared drives
For each shared drive you intend to include, have a drive manager open Google Drive → Shared drives → the drive → Manage members and add the delegated user’s email.Viewer provides read access. The user must also be allowed to download the intended files and access any limited-access folders you want to include. Sign in as the delegated user and confirm it can open the drive and read and download the intended content.Workspace admin roles alone do not grant access to every file. This setup uses the delegated user’s drive membership. See Google’s shared-drive membership guide.
7
Connect in June
Open Settings → Integrations → Knowledge → Google Drive and provide:
- Delegated admin email: the Workspace user’s primary email, such as
june-knowledge@example.com. - Service-account JSON key: the file downloaded from Google Cloud.
Add a Knowledge source
Open Intelligence → Knowledge Base → Add source, then choose Google Drive. Search shared drives by name or paste a shared-drive URL. Expand drives and folders to inspect their files using the same picker as other Knowledge providers. Select whole shared drives, name the source, and review the inventory before adding it. Their current and future content is included on sync. Folder/file selection, shortcuts, personal drives, and “Shared with me” are not supported in this release. Google permissions determine which documents can contribute to an employee’s answers. There is no separate employee-audience selector. Knowledge inventory titles and links retain the workspace’s existing visibility rules; inventory visibility does not grant access to document content. The employee’s email in June must exactly match their Google email. Email aliases are not supported. June only uses documents the employee has permission to access. Documents are omitted from answers when access cannot be verified.Manage the connection
- Choose Update credentials to upload a replacement JSON key. Leave the upload empty to retain the saved key. A failed replacement preserves the existing credentials.
- Choose Test Connection to verify access. Sync sources after updating or reconnecting.
- Choose Disconnect to stop using Google Drive content in answers. Saved source configuration remains available.
- Delete the connection’s Knowledge sources and wait for their deletion to finish before deleting the connection. Original Google files are preserved.
- Selected shared drives are fixed once source setup starts. To change them, delete the source and add it again after deletion finishes.