Administrator Tools
Connect your Google Workspace as an administrator, import your directory, create Salfio accounts, and connect your team's Gmail — without each person signing in individually.
Administrator Tools is where organization admins perform privileged, organization-wide actions. It lives under Settings → Organization → Administrator Tools and is visible only to admins — members don't see the menu entry, and the underlying operations are refused for them regardless.
Its first tool imports your team from Google Workspace at the organization level: connect and verify once as an admin, import your directory, create Salfio accounts for the people you select, and connect their Gmail — no individual sign-ins required. You can leave at any point and resume where you left off.
Who can use it
Section titled “Who can use it”Only organization admins and owners. Your role comes from your organization membership — if you don't see Administrator Tools under Settings, ask an admin of your organization to make these changes, or to grant you the admin role.
Connect Google Workspace
Section titled “Connect Google Workspace”Start the import from the Import users and activity from Google Workspace card. Step 1 connects and authorizes your Workspace:
- Sign in with Google using a Google Workspace super administrator account. This identifies you as the administrator and connects your domain — it grants no access to anyone's mailbox or to your directory by itself, and only asks for your basic profile.
- Authorize Salfio for your organization, one of two ways:
- Install from the Google Workspace Marketplace (when available): install Salfio for everyone in your domain and approve the required permissions once.
- Authorize manually with domain-wide delegation: the Authorize in Google Admin Console button opens Google's Admin Console with Salfio's client ID and required scopes pre-filled — review them and click Authorize. If the form doesn't pre-fill, the Add it manually section shows the client ID and scopes to paste, under Security → Access and data control → API controls → Manage Domain Wide Delegation → Add new.
- Verify access. Salfio confirms the authorization by reading your directory as you. New installations and permission changes can take a few minutes to take effect on Google's side — if verification fails at first, wait a moment and try again from the same screen. If the message says Couldn't reach Google, the problem is on Salfio's side rather than in your Workspace settings: there is nothing to change in Google, so try again in a few minutes.
Once verified, your domain is bound to your organization: Salfio will refuse to touch any mailbox outside it.
What the authorization allows
Section titled “What the authorization allows”The authorization is domain-wide by construction: Google grants read access to mailboxes and calendars in your organization. Salfio limits mailbox and calendar connections to the users you explicitly select in the import wizard and never requests write access — it can read, and only read, what you choose to connect.
The permissions requested are:
| Scope | Used for |
|---|---|
gmail.readonly |
Reading the mailboxes you select in the Connect Gmail step. |
admin.directory.user.readonly |
Listing your Workspace directory so you can choose who to import. |
calendar.events.readonly |
Reading the primary calendars of the users you select for calendar tracking — upcoming events only: title, time, meeting link, and attendees. Event descriptions and attachments are never read. |
The calendar permission is optional: an authorization that grants only the email and directory permissions verifies fine and email import works normally. The connection card shows when the calendar permission is missing, with instructions to add it — update the delegation entry with the current scope list, then re-verify.
Import your directory
Section titled “Import your directory”Once access is verified, step 2 lists everyone in your Workspace directory. Suspended and archived accounts aren't shown. Each member is marked:
| Status | Meaning |
|---|---|
| Already in Salfio | This person already has a Salfio account and is linked to their directory entry. |
| New | No Salfio account in this organization yet — selected for import by default. |
| Created | Their account was created by this import. |
If someone already has a Salfio account, their row reads Already has a Salfio account under the New badge: creating them adds that existing account to your organization rather than making a second one.
Use the search box to narrow the list; select all applies to your current search, never silently to the whole directory.
Create users makes a Salfio account for each selected member, directly in your organization — no invitation emails are sent, and each account is linked to its directory entry right away, so you can move straight on to step 3. They sign in with their Google account like anyone else. If everyone already has an account, use Skip: everyone already has an account to move on.
Connect Gmail & Calendar
Section titled “Connect Gmail & Calendar”Step 3 lists every Salfio user from your directory with their mailbox. Users who already connected their own Gmail are marked Connected by user and left untouched — a person's own connection always takes precedence, and there is never more than one integration per mailbox.
The same table carries a Calendar column: check it to track that person's primary calendar for meeting notifications, prep briefs, and My Week — org-wide, with no individual sign-ins. Calendar selection is independent of the mailbox column and off by default: connecting email for everyone while tracking calendars only for account managers is a supported shape. The column requires the calendar permission — if your authorization predates it, the connection card shows how to add it and re-verify.
A person's own calendar connection always wins: selecting someone whose calendar is already connected (via the Salfio notetaker or their own Google sign-in) records the selection without touching their connection, and the workspace takes over only if they later disconnect. Tracked users see their calendar as Managed by your workspace admin under Settings → Account → Calendar, with no disconnect — only an admin can stop the tracking.
Choose an Email history window (30, 90, or 180 days, or full history) — it bounds how far back each mailbox's first import reaches. Only email exchanged with your client domains is imported; personal and internal mail stays out of Salfio. That filter is what makes the import safe, so it is enforced rather than assumed: until at least one client with a domain exists, these mailboxes will not import anything — add a client with a domain first.
Review before you continue shows exactly what will be created; nothing happens until you confirm. Each integration is owned by the person whose mailbox it reads — it appears in their Settings → Integrations as if they had connected it themselves — and first imports are queued and staged, so large imports may take a few hours in the background.
Managing enrolled mailboxes
Section titled “Managing enrolled mailboxes”Once mailboxes are connected, the Administrator Tools page shows a health card for your Google Workspace connection:
- Manage mailboxes lists every connected mailbox with its status and last sync. Remove stops one mailbox's syncing; everything already imported is kept, and the row stays listed as Removed. A Paused status means syncing is temporarily stopped for the whole connection (for example, while authorization is revoked) and resumes on re-verify. Needs attention means that one mailbox has a problem of its own, with the reason shown beside it. The usual cause is that its owner was suspended or deleted in Google Workspace — the rest of the connection is unaffected.
- Manage calendars lists every calendar selected for tracking with its status — including Connected by user for a selection that currently syncs through the person's own connection. Remove stops the tracking: that calendar's upcoming meetings are cancelled, past meetings are kept, and you can select it again later.
- Import more users re-runs the import for people who joined your Workspace later — and is also where you select more calendars.
- Sync now, on an individual integration, can be used by the mailbox's own user or by an administrator. Other members of your organization cannot trigger a resync of a mailbox connected through Administrator Tools.
- Disconnect Google Workspace ends every enrollment created through Administrator Tools and removes Salfio's organization-level access. Reconnecting later does not bring those mailboxes back — you run the wizard again and re-select them. Everything already imported is kept, and users who connected their own Gmail are not affected.
If you revoke Salfio's authorization in Google, syncing pauses for all enrolled mailboxes as a single event and the page shows Access revoked — restore the authorization in Google, then Re-verify access to resume where things left off.
Starting over
Section titled “Starting over”Start over on the import card removes the current Google Workspace connection so the wizard begins fresh. Nothing already imported is deleted. Signing out on the connect step does the same thing.