# Google permissions

<figure><img src="https://627748108-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0shDrJltbdGiCRz6ip4Z%2Fuploads%2FUsNLO0tsEeK8MZJS6pQx%2Fgoogleworkspace.png?alt=media&#x26;token=262755d9-52af-4d3e-922d-970d9153ba0b" alt=""><figcaption></figcaption></figure>

UMA requires the following permission scope to work with your Google Workspace environment:

<details>

<summary><mark style="color:blue;">https://www.googleapis.com/auth/calendar</mark></summary>

***Read and write calendars in all mailboxes***

***

We need this permission to write to your users and resource calendars.

This is required when booking or editing a booking through UMA.

</details>

<details>

<summary><mark style="color:blue;">https://www.googleapis.com/auth/admin.directory.resource.calendar</mark></summary>

**Scope for access to all calendar resources operations**

***

We need this permission to get a list of all resource calendars.

This is required when booking or editing a booking through UMA.

</details>

<details>

<summary><mark style="color:blue;">https://www.googleapis.com/auth/admin.directory.group.readonly</mark></summary>

***Read all groups***

***

We need this permission to read your Google Workspace groups for [user sync](https://support.meetuma.ai/uma-knowledgebase/integrations/calendar/microsoft-365/user-sync-legacy-search-scim).

</details>

<details>

<summary><mark style="color:blue;">https://www.googleapis.com/auth/admin.directory.group.member.readonly</mark></summary>

***Read all group memberships***

***

We need this permission to read the members of your Google Workspace groups for [user sync](https://support.meetuma.ai/uma-knowledgebase/integrations/calendar/microsoft-365/user-sync-legacy-search-scim).

</details>

<details>

<summary><mark style="color:blue;">https://www.googleapis.com/auth/admin.directory.user.readonly</mark></summary>

***Read all users full profiles***

***

Allows UMA to read the full set of profile properties, reports, and managers of other users in your organisation, on behalf of the signed-in user.

</details>

For further information on Google Workspace scopes follow the documentation here:

{% embed url="<https://developers.google.com/admin-sdk/directory/v1/guides/authorizing>" %}
