Google Drive

Search Google Docs, Sheets, Slides, and supported files in Drive. Members can connect their own accounts after an admin allows Google Drive, or an admin can configure a central service-account crawl.

Admin setup uses your organization's Settings → Sources page. Teammates connect from Integrations in the main sidebar.

Choose your setup

MethodUse it whenWhat teammates do
Member accountsEach person connects their own Drive access. No domain-wide delegation is needed; your Google Workspace app policy may require administrator approval.Connect their own Google Drive accounts.
Service accountA Google Workspace administrator can configure delegation and directory access for a central crawl.Join the Studio organization with matching verified email addresses; no personal Drive connection is needed for this source.

These are alternative setup paths. When only a central Drive source is configured, Integrations does not offer a personal Drive Connect action. Teammates use Search or Home directly. Existing member-account sources keep their connection actions.

A central crawl includes each selected employee's private My Drive files and shared-drive files they can access. Files keep their original user and group permissions; indexing a private file does not make it visible to other employees.

Connect member accounts

Allow Google Drive

An admin selects Settings → Sources → Add source → Google Drive, chooses Sync using → Member accounts, sets any filters, and selects Set up member accounts.

Connect your account

Join the Studio organization, then open Integrations and select Connect for Google Drive. Use the Google account matching your verified Studio email. Google Drive has one row even when the admin configures several folder selections; its row shows your connection and indexing status. Members do not re-enter the admin's folder filters.

Adjust filters if needed

An admin opens Settings → Sources → Google Drive, selects the connection, then opens Settings. Leave Folders empty to include supported files each member can access, or narrow the source to folders. Account for browsing helps select folders; manual Folder IDs work without it. Browsing does not connect that account to Search.

Keep Sync documents with → Connected members unless a dedicated account should fetch content. Members still connect to establish access. If the dedicated account is a delegated service account, Crawl as selects the Google Workspace user whose files it fetches. Save the source settings when finished.

Admins can request member connections from Settings → Sources → People → Request connections (filter by the integration first). These requests do not grant organization membership. See Connect your account for the shared connection and recovery steps.

Set up a central service account

Open Settings → Sources → Add source and select Google Drive. This opens Connect Google Drive service account. To add another connection later, open Google Drive from the Sources list and select Connect service account.

This requires a Google Workspace domain and a Workspace super administrator to authorize domain-wide delegation. Consumer Gmail accounts cannot use this path.

Prepare the service account

In Google Cloud Console, select your project and enable Google Drive API and Admin SDK API under APIs & Services → Library. Then open IAM & Admin → Service Accounts → Create service account, enter a name, and finish creation. Google Cloud project roles do not grant access to Workspace files; they are not required for this crawl.

Open the service account's Keys tab and choose Add key → Create new key → JSON, then select Create to download the key. Store it securely; you will add it to Studio next. See Google's key creation guide.

Authorize domain-wide delegation

In the service account's Details, expand Advanced settings and copy its numeric Client ID. Sign in to the Workspace Admin Console as a super administrator. Open Security → Access and data control → API controls → Manage Domain Wide Delegation → Add new.

Paste that Client ID into Client ID, then enter these exact scopes as a comma-separated list under OAuth scopes:

https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.group.readonly,https://www.googleapis.com/auth/admin.directory.domain.readonly

Select Authorize, then View details to confirm all four scopes were saved. If you reuse a Gmail or Calendar service account, retain those services' required scopes and add any missing Drive scopes. If your organization requires multi-party approval, another super administrator must approve the request. Delegation changes can take up to 24 hours to propagate. See Google's Admin Console delegation guide.

These are Search's central crawl scopes. The general Google service account guide includes broader scopes for workflow actions; do not copy those into this Search setup.

The Directory administrator email must belong to an active Workspace administrator with permission to read users, groups, group memberships, and domains. A super administrator has these privileges; a custom administrator role can supply them instead. This identity enumerates the directory. Studio obtains separate read-only Drive tokens for the selected users.

Group permissions require groups and memberships that this administrator can read in this Google Workspace customer. External groups and unresolvable nested groups are not supported. Google Drive target-audience shares are not mapped; use explicit user, supported group, or domain permissions instead.

Add the credential in Studio

Under Service account, choose Add service account, or select an existing service account. Paste the JSON key into Add Google service account, give it a name, and select Add service account. Studio returns you to the source form with that credential selected.

Choose the directory administrator and users

After selecting the service account, Directory administrator email appears. Enter the Workspace administrator described above. Under More options, leave Users blank for everyone, or enter up to 100 primary Workspace email addresses separated by commas. Suspended, archived, and guest accounts are excluded.

Leave Folders empty to include supported files each selected user can access. To narrow the source, select folders visible to the Directory administrator or enter Folder IDs manually. The same folder filter applies to each selected user and does not grant access. Choose Connect & Sync. Studio validates the administrator and any selected users, and probes Drive access for an active user, before accepting the connection.

The crawl includes shared-drive files even if a selected user has never opened them. A selected user must be able to download each file and Studio must verify its permissions before showing it in Search; this also applies to shortcut targets. If a reader can download a file but cannot list its permissions, include its owner or another user who can read those permissions.

Invite teammates through Settings → Members → Invite, using their Google Workspace email addresses. They accept, sign in with those matching verified emails, and open Search or Home. They do not connect personal Google accounts for this central source.

Source options

An admin opens Settings → Sources → Google Drive to open its configuration list. Each row shows Member accounts or Service account beside its sync status. Open a connection's Settings tab to edit its filters, then select Save. Documents shows indexed files and Sync history shows recent runs.

Sync using identifies the configuration's fixed connection method. To replace a central credential, choose another Service account and select Change service account.

Use Sync now to request an update, Pause syncing to stop scheduled syncs, and Resume syncing to restart them. Remove connection deletes the configuration and its indexed documents from Studio; it does not delete Drive files. These actions belong to the admin connection page. Members use Connect, Reconnect, or Disconnect on their Integrations row.

OptionBehavior
Folders / Folder IDsOptional. Includes files in each selected folder and its accessible subfolders. A folder selection does not grant access.
File TypeAll supported files by default, or only Google Docs, Sheets, Slides, or text formats. Plain text files only also includes CSV, HTML, Markdown, JSON, and XML.
Directory administrator emailRequired for central indexing. Supplies Directory access for user enumeration and permission groups; it does not limit the crawl to this administrator's files.
UsersCentral indexing only. Optional primary email addresses (up to 100); blank includes all active users in this Workspace customer. This selects which users' Drives to crawl, not who may search the resulting files.
Crawl asIn Member accounts, optionally supplies the impersonated user when a dedicated service account fetches content. It has no effect on ordinary OAuth accounts.
Openly shared filesApplies only to central crawls; it has no effect in Member accounts. Keep out of search by default. You can include discoverable domain shares or discoverable public shares. Link-only sharing does not grant Search access; named user and group permissions still apply.
Metadata tagsOptional owner, file type, modification date, and starred metadata. In the add-source form, these, Users, and File Type are under More options.

Studio exports Docs and Slides as text and Sheets as XLSX spreadsheets. Supported uploaded files use the knowledge-base document pipeline, including PDF and Office formats. Unsupported files and oversized exports cannot be indexed; Google limits Workspace exports to 10 MB. See Drive export formats and download limits.

Search schedules syncs hourly. Central crawls revisit the selected users' files and permissions, including unchanged files, so permission changes and a new employee's older files are included. Unfinished crawls resume before deletion reconciliation. Content, deletions, and permissions refresh in the background; results are not a live read from Drive. People on the Sources settings page shows personal account connections; it does not list the central service-account credential.

Troubleshooting

ProblemNext step
Directory access failedCheck all four delegated scopes and the Directory administrator email user's administrator privileges. A normal Google OAuth credential cannot supply this central Search path.
Missing files in a central crawlCheck Users, folder and file-type filters, and whether selected active Workspace users can download the file and read its permissions. Opening a file alone does not prove either. Check Sync history for errors. Files reachable only by excluded or inactive accounts are not crawled; files with unverified permissions stay hidden.
User not found or inactiveUse a primary email in the same Google Workspace customer. Aliases, external or guest accounts, suspended users, and archived users cannot be selected for crawling.
A teammate sees no resultsConfirm they have joined the Studio organization and their verified Studio email matches the Drive permission or group membership. For member accounts, finish their personal Drive connection too.
A public or shared-link file is missingCheck Openly shared files. Link-only sharing does not grant Search access. A named user or group permission can still make the file searchable.
Reconnect or credential errorReauthorize the member account, or replace the service-account credential and verify delegation, as applicable.

Self-hosted OAuth configuration

The deployment operator configures Google OAuth for member accounts and Account for browsing. This is separate from the central service account above.

  1. In Google Cloud Console, select your project and enable Google Drive API under APIs & Services → Library.
  2. Open Google Auth platform → Branding and configure the app name and contact details. Under Audience, choose Internal for your Google Workspace organization only, or External for other users, adding test users while testing. Review Data Access → Add or remove scopes using the current Studio scopes below. See Google's consent guidance.
  3. Open Google Auth platform → Clients → Create client, choose Web application, and add this URI under Authorized redirect URIs. Add it to the existing Google client if your instance already uses one.
https://<your-studio-domain>/api/auth/oauth2/callback/google-drive

This Google Cloud example uses one client for all three services. Replace https://studio.example.com with your Studio origin and add only the callbacks for services you enable.

Save the client ID and secret as GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET. Set NEXT_PUBLIC_APP_URL to the same Studio origin used in the callback, then restart Studio. See Integrations & OAuth. If you change an existing deployment's OAuth client or scopes, an organization admin selects Settings → Sources → More → Update sign-in settings, then affected teammates reconnect.

The current Studio Drive OAuth connection uses these scopes:

openid
https://www.googleapis.com/auth/userinfo.email
https://www.googleapis.com/auth/userinfo.profile
https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/drive.file

Google's drive.readonly scope covers Search's file reads. Studio's existing OAuth connection also supports workflow actions and requires the broader scopes above; do not substitute read-only scopes for member OAuth. The central service account uses the four separate read-only Drive and Directory scopes listed earlier. Adding company-wide indexing requires the Directory user-read scope in the service account's domain-wide delegation; it does not change the member OAuth app scopes. See Google's Drive scope descriptions.