# Administrator Tools

Connect your Google Workspace as an administrator, import your directory, create Salfio accounts, and connect your team's Gmail — without each person signing in individually.

**Administrator Tools** is where organization admins perform privileged, organization-wide actions. It lives under **Settings → Organization → Administrator Tools** and is visible only to admins — members don't see the menu entry, and the underlying operations are refused for them regardless.

Its first tool imports your team from **Google Workspace** at the organization level: connect and verify once as an admin, import your directory, create Salfio accounts for the people you select, and connect their Gmail — no individual sign-ins required. You can leave at any point and resume where you left off.

## Who can use it

Only organization **admins** and **owners**. Your role comes from your organization membership — if you don't see Administrator Tools under Settings, ask an admin of your organization to make these changes, or to grant you the admin role.

## Connect Google Workspace

Start the import from the **Import users and activity from Google Workspace** card. Step 1 connects and authorizes your Workspace:

1.  **Sign in with Google** using a Google Workspace **super administrator** account. This identifies you as the administrator and connects your domain — it grants no access to anyone's mailbox or to your directory by itself, and only asks for your basic profile.
2.  **Authorize Salfio** for your organization, one of two ways:
    - **Install from the Google Workspace Marketplace** (when available): install Salfio for everyone in your domain and approve the required permissions once.
    - **Authorize manually** with domain-wide delegation: the **Authorize in Google Admin Console** button opens Google's Admin Console with Salfio's client ID and required scopes pre-filled — review them and click **Authorize**. If the form doesn't pre-fill, the **Add it manually** section shows the client ID and scopes to paste, under *Security → Access and data control → API controls → Manage Domain Wide Delegation → Add new*.
3.  **Verify access.** Salfio confirms the authorization by reading your directory as you. New installations and permission changes can take a few minutes to take effect on Google's side — if verification fails at first, wait a moment and try again from the same screen. If the message says **Couldn't reach Google**, the problem is on Salfio's side rather than in your Workspace settings: there is nothing to change in Google, so try again in a few minutes.

Once verified, your domain is bound to your organization: Salfio will refuse to touch any mailbox outside it.

## What the authorization allows

The authorization is domain-wide by construction: Google grants read access to mailboxes and calendars in your organization. Salfio limits mailbox and calendar connections to the users you explicitly select in the import wizard and never requests write access — it can read, and only read, what you choose to connect.

The permissions requested are:

| Scope | Used for |
|----|----|
| `gmail.readonly` | Reading the mailboxes you select in the Connect Gmail step. |
| `admin.directory.user.readonly` | Listing your Workspace directory so you can choose who to import. |
| `calendar.events.readonly` | Reading the primary calendars of the users you select for calendar tracking — upcoming events only: title, time, meeting link, and attendees. Event descriptions and attachments are never read. |

The calendar permission is **optional**: an authorization that grants only the email and directory permissions verifies fine and email import works normally. The connection card shows when the calendar permission is missing, with instructions to add it — update the delegation entry with the current scope list, then re-verify.

## Import your directory

Once access is verified, step 2 lists everyone in your Workspace directory. Suspended and archived accounts aren't shown. Each member is marked:

| Status | Meaning |
|----|----|
| **Already in Salfio** | This person already has a Salfio account and is linked to their directory entry. |
| **New** | No Salfio account in this organization yet — selected for import by default. |
| **Created** | Their account was created by this import. |

If someone already has a Salfio account, their row reads *Already has a Salfio account* under the **New** badge: creating them adds that existing account to your organization rather than making a second one.

Use the search box to narrow the list; **select all** applies to your current search, never silently to the whole directory.

**Create users** makes a Salfio account for each selected member, directly in your organization — **no invitation emails are sent**, and each account is linked to its directory entry right away, so you can move straight on to step 3. They sign in with their Google account like anyone else. If everyone already has an account, use **Skip: everyone already has an account** to move on.

## Connect Gmail & Calendar

Step 3 lists every Salfio user from your directory with their mailbox. Users who already connected their own Gmail are marked **Connected by user** and left untouched — a person's own connection always takes precedence, and there is never more than one integration per mailbox.

The same table carries a **Calendar** column: check it to track that person's primary calendar for meeting notifications, prep briefs, and My Week — org-wide, with no individual sign-ins. Calendar selection is independent of the mailbox column and **off by default**: connecting email for everyone while tracking calendars only for account managers is a supported shape. The column requires the calendar permission — if your authorization predates it, the connection card shows how to add it and re-verify.

A person's own calendar connection always wins: selecting someone whose calendar is already connected (via the Salfio notetaker or their own Google sign-in) records the selection without touching their connection, and the workspace takes over only if they later disconnect. Tracked users see their calendar as **Managed by your workspace admin** under Settings → Account → Calendar, with no disconnect — only an admin can stop the tracking.

Choose an **Email history** window (30, 90, or 180 days, or full history) — it bounds how far back each mailbox's first import reaches. **Only email exchanged with your client domains is imported**; personal and internal mail stays out of Salfio. That filter is what makes the import safe, so it is enforced rather than assumed: until at least one client with a domain exists, these mailboxes will not import anything — add a client with a domain first.

**Review before you continue** shows exactly what will be created; nothing happens until you confirm. Each integration is **owned by the person whose mailbox it reads** — it appears in *their* Settings → Integrations as if they had connected it themselves — and first imports are queued and staged, so large imports may take a few hours in the background.

## Managing enrolled mailboxes

Once mailboxes are connected, the Administrator Tools page shows a health card for your Google Workspace connection:

- **Manage mailboxes** lists every connected mailbox with its status and last sync. **Remove** stops one mailbox's syncing; everything already imported is kept, and the row stays listed as **Removed**. A **Paused** status means syncing is temporarily stopped for the whole connection (for example, while authorization is revoked) and resumes on re-verify. **Needs attention** means that one mailbox has a problem of its own, with the reason shown beside it. The usual cause is that its owner was suspended or deleted in Google Workspace — the rest of the connection is unaffected.
- **Manage calendars** lists every calendar selected for tracking with its status — including **Connected by user** for a selection that currently syncs through the person's own connection. **Remove** stops the tracking: that calendar's upcoming meetings are cancelled, past meetings are kept, and you can select it again later.
- **Import more users** re-runs the import for people who joined your Workspace later — and is also where you select more calendars.
- **Sync now**, on an individual integration, can be used by the mailbox's own user or by an administrator. Other members of your organization cannot trigger a resync of a mailbox connected through Administrator Tools.
- **Disconnect Google Workspace** ends every enrollment created through Administrator Tools and removes Salfio's organization-level access. Reconnecting later does not bring those mailboxes back — you run the wizard again and re-select them. Everything already imported is kept, and users who connected their own Gmail are not affected.

If you revoke Salfio's authorization in Google, syncing pauses for all enrolled mailboxes as a single event and the page shows **Access revoked** — restore the authorization in Google, then **Re-verify access** to resume where things left off.

## Starting over

**Start over** on the import card removes the current Google Workspace connection so the wizard begins fresh. Nothing already imported is deleted. Signing out on the connect step does the same thing.

## Related pages

- [Agent Tools](./mcp-external-servers.md)
- [Assign a Slack channel to a client over the API](./guides-assign-slack-channel.md)
- [Authenticated health check](./api-reference-gethealth.md)
- [Authentication](./api-authentication.md)
- [Cards](./cards.md)
- [Changelog](./changelog.md)
- [Changelog](../changelog.md)
- [Connect a workspace](./getting-started-connect-workspace.md)
- [Connect an integration](./getting-started-connect-integration.md)
- [Connect from Claude Desktop](./mcp-connect-claude-desktop.md)

# Agent Instructions

This portal answers questions programmatically. To receive a synthesized,
source-cited answer instead of crawling page by page, append the `?ask=`
query parameter to any page URL on this site:

    /guides/quickstart?ask=how+do+I+authenticate

Optional parameters:

- `&goal=<what-you-are-trying-to-do>` steers the answer toward your
  objective (e.g. `&goal=write+a+python+client`).
- `&version=<label>` scopes the answer to a mounted version when the
  portal publishes more than one.

The response is `text/markdown`: the answer followed by a `# Sources` list
of the portal pages it was grounded in. Status codes are the contract:

- `200` — the answer; `402` — the portal owner’s plan or answer credits are
  exhausted (surface this to your operator; do NOT retry); `429` — you are
  rate-limited; back off for the `Retry-After` seconds; `503` — the answer
  lane is temporarily unavailable; fall back to crawling the `.md` pages.

For the full corpus map read `llms.txt` at the site root; for the tool
surface (search + page fetch as MCP tools) see `/mcp`.
