Skip to content

Commit 3c735d2

Browse files
authored
fix(search): tighten Google sync and invitation recovery (#7729)
1 parent 6dba116 commit 3c735d2

13 files changed

Lines changed: 434 additions & 68 deletions

File tree

apps/docs/content/docs/search/gmail.mdx

Lines changed: 8 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ Open **Settings → Sources** and turn on **Gmail**. This allows personal connec
3636

3737
### Connect your account
3838

39-
Open **Integrations** and select **Connect** beside Gmail. Authorize the Google account matching your verified Sim email. The first connection creates the default sync configuration: the last 6 months across all labels, excluding Promotions, Social, Spam, and Trash.
39+
Join the Sim organization, then open **Integrations** and select **Connect** beside Gmail. Authorize the Google account matching your verified Sim email. The first connection creates the default sync configuration: the last 6 months across all labels, excluding Promotions, Social, Spam, and Trash. Return to Integrations to see indexing status and your searchable document count.
4040

4141
</Step>
4242
<Step>
@@ -52,6 +52,8 @@ Configurations are additive: a narrower one does not restrict an existing broade
5252
</Step>
5353
</Steps>
5454

55+
Admins can request member connections from **Manage → Accounts → Request connections**. These requests do not invite recipients to the Sim organization. See [Connect your account](/search/connect-your-account) for the shared connection and recovery steps.
56+
5557
## Set up a central service account
5658

5759
Open **Settings → Sources**, enable **Gmail**, and select **Manage → Advanced → Add sync configuration**. If personal connections are disabled for your organization, select **Add source** from the provider page instead.
@@ -100,16 +102,6 @@ Teammates join the Sim organization with their matching verified primary email.
100102
</Step>
101103
</Steps>
102104

103-
## Connect your account
104-
105-
These steps apply to **Member accounts**. A central service-account source does not require a personal Gmail connection.
106-
107-
1. Join the Sim organization and verify your Sim email address. Open **Integrations** and click **Connect** beside Gmail.
108-
2. Complete the connection in the tab that opens. Choose the Google account whose verified email matches your Sim email, and grant the requested permissions.
109-
3. Return to Integrations. The source shows its indexing status and the number of documents you can search.
110-
111-
Teammates follow these same steps after joining the organization. Once an admin allows Gmail, the first connection can create its source with default filters. Admins can edit those filters afterward or request connections from **Manage → Accounts → Request connections**. A connection request does not invite the recipient to the Sim organization.
112-
113105
## Source options
114106

115107
An admin opens **Settings → Sources** and selects **Manage** beside **Gmail** to open its configuration list. Each row shows **Member accounts** or **Service account** beside its sync status. Open a configuration's **Settings** tab to edit its filters, then select **Save**. Filters apply separately to each mailbox in the source. **Documents** shows indexed threads and **Sync history** shows recent runs.
@@ -121,11 +113,11 @@ An admin opens **Settings → Sources** and selects **Manage** beside **Gmail**
121113
| Labels | Optional comma-separated names or system IDs, such as `Engineering, INBOX`. A thread matching any listed label is included. Leave empty for all labels. Custom IDs such as `Label_7` belong to one mailbox and cannot be used for member or central setup. |
122114
| Directory administrator email | Required for central indexing. An active Workspace administrator who can read Directory users; this does not limit the crawl to the administrator's mailbox. |
123115
| Users | Central indexing only. Optional primary Workspace email addresses (up to 100); blank includes all active users in the customer. This selects which mailboxes to crawl. Each mailbox remains searchable only by its owner. |
124-
| Date Range | Last 6 months by default for Search sources. Choose the last 7, 30, or 90 days, a year, or all time. A knowledge-base connector outside Search defaults to all time. |
116+
| Date Range | Last 6 months (180 days) by default. Other options are rolling windows of 7, 30, or 90 days, 1 year (365 days), or all time. |
125117
| Exclude Promotions / Exclude Social | Both enabled by default. Choose **No** to include either category. |
126118
| Search Filter | Optional [Gmail query](https://developers.google.com/workspace/gmail/api/guides/filtering), such as `from:team@example.com subject:release`. This filters what is indexed; it is not a Sim Search query. Member-account sources with a search filter relist the mailbox on every sync instead of using Gmail's change history. |
127119

128-
In the add-source form, **More options** contains optional **Metadata tags**. Sync frequency and the general knowledge-base **Max Threads** setting are hidden in Search.
120+
In the add-source form, **More options** also contains optional **Metadata tags**.
129121

130122
## What gets indexed
131123

@@ -137,13 +129,9 @@ Search schedules syncs hourly. The first sync lists every thread in scope and ca
137129

138130
**Member accounts:** later syncs use each mailbox's Gmail change history, unless the configuration has a search filter. A full relisting runs about weekly, or sooner if Gmail no longer retains the saved history.
139131

140-
**Service account:** each sync revisits the selected active mailboxes and resumes unfinished listings. It does not reuse one mailbox's history cursor across the company. Only new or changed threads need their bodies fetched. Failed mailbox reads leave the crawl incomplete; they are not treated as an empty mailbox for deletion reconciliation.
141-
142-
Updates, removals, and access refresh in the background, rather than being checked live for each search.
143-
144-
An empty mailbox or filters with no matching threads complete normally with zero documents.
132+
**Service account:** each sync revisits the selected active mailboxes and resumes unfinished listings. A failed mailbox read leaves the crawl incomplete; it does not cause existing indexed mail to be deleted from Search.
145133

146-
Threads that exceed indexing size limits are skipped and reconsidered when the thread changes.
134+
Updates, removals, and access refresh in the background. Empty mailboxes and filters with no matches complete normally with zero documents. Threads exceeding indexing size limits are skipped and reconsidered when they change.
147135

148136
## Troubleshooting
149137

@@ -155,7 +143,7 @@ Threads that exceed indexing size limits are skipped and reconsidered when the t
155143
| Reconnect | Click **Reconnect** and authorize the same account again. |
156144
| Unavailable or needs admin attention | Ask your Sim admin to check source status and the deployment's Google OAuth configuration. |
157145
| Directory or delegation error | Check both central crawl scopes, the service-account key, and the Directory administrator's user-read privileges. A normal OAuth account cannot replace the central service account. |
158-
| Gmail access fails for a selected user | Verify Gmail is enabled for that primary Workspace account and delegation is authorized. Narrow **Users** to accounts with Gmail enabled. Aliases and external accounts cannot be selected. |
146+
| Gmail access fails for a selected user | Verify delegation is authorized and [Gmail is enabled](https://knowledge.workspace.google.com/admin/gmail/control-gmail-access-for-your-organizations-users) for that primary Workspace account. Set **Users** to accounts with Gmail enabled; leaving it blank includes all active users and can stop sync on a service-access error. Aliases and external accounts cannot be selected. |
159147
| A central source indexes mail but a teammate sees no results | Confirm their verified Sim email is the mailbox's primary email and they belong to the Sim organization. Administrators do not receive other people's mailbox access. |
160148

161149
## Self-hosted operator setup

apps/docs/content/docs/search/google-calendar.mdx

Lines changed: 7 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ These are alternative setup paths. When only a central Calendar source is config
2929

3030
### Allow and connect Google Calendar
3131

32-
An admin opens **Settings → Sources** and turns on **Google Calendar**. Then each person opens **Integrations**, selects **Connect** beside Google Calendar, and authorizes their matching Google account. The first connection creates the default member-account sync configuration.
32+
An admin opens **Settings → Sources** and turns on **Google Calendar**. Each person joins the Sim organization, opens **Integrations**, selects **Connect** beside Google Calendar, and authorizes the Google account matching their verified Sim email. The first connection creates the default member-account sync configuration. Return to Integrations to see indexing status and your searchable document count.
3333

3434
</Step>
3535
<Step>
@@ -50,6 +50,8 @@ The default date range covers the previous and next 30 days. Save any changes to
5050
</Step>
5151
</Steps>
5252

53+
Admins can request member connections from **Manage → Accounts → Request connections**. These requests do not grant organization membership. Connecting Gmail or Drive does not replace the Calendar connection. See [Connect your account](/search/connect-your-account) for the shared connection and recovery steps.
54+
5355
<Callout type="info">
5456
`primary` means the connected or impersonated person's main calendar. A calendar selected from the list is a specific calendar ID, even when it is your main calendar. That same ID applies to every selected user, and only users with access to it can search its events.
5557
</Callout>
@@ -102,16 +104,6 @@ Sim verifies Directory access and selected users, then probes one selected user'
102104
</Step>
103105
</Steps>
104106

105-
## Connect your account
106-
107-
These steps apply to **Member accounts**. When only a central Calendar source is configured, teammates use Search or Home directly and are not offered a personal Calendar connection for that source.
108-
109-
1. Join the Sim organization and verify your Sim email. Open **Integrations** and click **Connect** beside Google Calendar.
110-
2. In the connection tab, choose the Google account whose verified email matches your Sim email. Grant the requested permissions.
111-
3. Return to Integrations to see indexing status and your searchable document count.
112-
113-
Teammates repeat only these connection steps after joining the organization. They do not need to configure the source. An admin can send connection requests from **Settings → Sources**: select **Manage** beside **Google Calendar**, then **Accounts → Request connections**. These requests do not grant organization membership. Connecting Gmail or Google Drive does not replace the Calendar connection.
114-
115107
## Source options
116108

117109
An admin opens **Settings → Sources** and selects **Manage** beside **Google Calendar** to open its configuration list. Each row shows **Member accounts** or **Service account** beside its sync status. Open a configuration's **Settings** tab to edit its filters, then select **Save**. **Documents** shows indexed events and **Sync history** shows recent runs.
@@ -127,13 +119,13 @@ An admin opens **Settings → Sources** and selects **Manage** beside **Google C
127119
| Search Query | Optional text filter applied by Google to event titles, descriptions, locations, and organizer or attendee names and emails. Leave empty to include all matching events in the date range. |
128120
| Include Attendees | **Yes** by default. **No** omits organizer and attendee identity fields and keeps the attendee count. It does not redact names written into titles or descriptions. |
129121

130-
In the add-source form, **More options** contains optional **Metadata tags**. Search hides sync frequency and the general knowledge-base **Max Events** setting.
122+
In the add-source form, **More options** also contains optional **Metadata tags**.
131123

132124
## What gets indexed
133125

134-
Sim indexes event titles, descriptions, times, locations, and the selected attendee information. All-day events and individual occurrences of recurring meetings are supported. An invitation you declined stays searchable and is marked `Response: declined`. Results link back to Google Calendar.
126+
Sim indexes event titles, descriptions, times, locations, and the selected attendee information. All-day events and individual occurrences of recurring meetings are supported. Declined invitations returned by Google stay searchable and are marked `Response: declined`; hidden invitations are not requested. Results link back to Google Calendar.
135127

136-
Cancelled events, attachment contents, meeting recordings, and transcripts are not indexed. Status entries such as working location, out of office, focus time, and birthdays, and automatically generated reservation events from Gmail are not indexed. A shared calendar where you can see only free or busy times contributes nothing, since those blocks have no title or description. Events outside the selected date window are excluded. Private event details that Google withholds are not available in Search; see [Google's calendar sharing rules](https://developers.google.com/workspace/calendar/api/concepts/sharing).
128+
Cancelled events, attachment contents, meeting recordings, and transcripts are not indexed. Status entries such as working location, out of office, focus time, and birthdays, and automatically generated reservation events from Gmail are not indexed. Events Google returns only as free/busy blocks, without searchable details, are not indexed. Events outside the selected date window are excluded. Private event details that Google withholds are not available in Search; see [Google's calendar sharing rules](https://developers.google.com/workspace/calendar/api/concepts/sharing).
137129

138130
Search schedules syncs hourly. Event edits, cancellations, access changes, inactive or removed users, and events moving outside the date window are reconciled during completed background syncs. Central crawls page through each selected user and resume unfinished work before removing documents no longer listed. Authorization, quota, and provider failures stop the sync rather than treating unread calendars as empty. The first sync may take longer, and results appear as indexing progresses; Search is not a live Calendar read.
139131

@@ -148,6 +140,7 @@ Search schedules syncs hourly. Event edits, cancellations, access changes, inact
148140
| Reconnect | Click **Reconnect** and complete Google authorization again. Allow pop-ups if the connection tab does not open. |
149141
| Unavailable or needs admin attention | Ask your Sim admin to check source status and the deployment's Google OAuth configuration. |
150142
| Service-account authorization or Directory error | Confirm both delegated scopes, enabled APIs, and the Directory administrator's user-read privilege. Check whether delegation still awaits approval or propagation. |
143+
| Calendar is disabled for a selected user | An active Workspace user may have Calendar turned off. [Enable Calendar](https://knowledge.workspace.google.com/admin/users/access/turn-calendar-on-or-off-for-users) for them, or set **Users** to accounts with Calendar enabled. Leaving **Users** blank includes all active users and can stop sync on a service-access error. |
151144
| User not found or inactive | Use an active primary email in the same Workspace customer. Aliases, external or guest accounts, suspended users, and archived users cannot be selected. |
152145
| A central source has no results for a teammate | Confirm their primary Workspace email matches their verified Sim email, they belong to the Sim organization, and they are included in **Users**. Check calendar IDs and **Sync history**. |
153146

apps/docs/content/docs/search/google-drive.mdx

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ Admin setup uses your organization's **Settings → Sources** page. Teammates co
2121
These are alternative setup paths. When only a central Drive source is configured, Integrations does not offer a personal Drive **Connect** action. Teammates use Search or Home directly. Existing member-account sources keep their connection actions.
2222

2323
<Callout type="info">
24-
A central crawl reads each selected employee's Drive through domain-wide delegation, including private My Drive files and shared-drive files they can access. Leave **Users** blank to include all active users in your Google Workspace customer, including secondary domains. Files keep their original user and group permissions; indexing a private file does not make it visible to other employees.
24+
A central crawl includes each selected employee's private My Drive files and shared-drive files they can access. Files keep their original user and group permissions; indexing a private file does not make it visible to other employees.
2525
</Callout>
2626

2727
## Connect member accounts
@@ -38,7 +38,7 @@ An organization admin opens **Settings → Sources** and turns on **Google Drive
3838

3939
### Connect your account
4040

41-
Open **Integrations** in the main sidebar and select **Connect** beside Google Drive. Use the Google account matching your verified Sim email. The first personal connection can create a source with default filters. Teammates follow the same [connection steps](/search/connect-your-account).
41+
Join the Sim organization, then open **Integrations** and select **Connect** beside Google Drive. Use the Google account matching your verified Sim email. The first personal connection can create a source with default filters. Return to Integrations to see indexing status and your searchable document count.
4242

4343
</Step>
4444
<Step>
@@ -52,6 +52,8 @@ Keep **Sync documents with → Connected members** unless a dedicated account sh
5252
</Step>
5353
</Steps>
5454

55+
Admins can request member connections from **Manage → Accounts → Request connections**. These requests do not grant organization membership. See [Connect your account](/search/connect-your-account) for the shared connection and recovery steps.
56+
5557
## Set up a central service account
5658

5759
Open **Settings → Sources** and turn on **Google Drive**. Select **Manage → Advanced → Add sync configuration** to open the central service-account form directly. If personal connections are disabled for your organization, select **Add source** from the provider page instead. Teammates do not need a personal Drive connection for this source.
@@ -80,8 +82,6 @@ Open the service account's **Keys** tab and choose **Add key → Create new key
8082

8183
In the service account's **Details**, expand **Advanced settings** and copy its numeric **Client ID**. Sign in to the [Workspace Admin Console](https://admin.google.com/ac/owl/domainwidedelegation) as a super administrator. Open **Security → Access and data control → API controls → Manage Domain Wide Delegation → Add new**.
8284

83-
<Image className="mx-auto h-auto w-full max-w-md" src="/static/search/google-domain-delegation.png" alt="Google Workspace Admin Console Add a new client ID dialog with Client ID and OAuth scopes fields" width={768} height={929} />
84-
8585
Paste that Client ID into **Client ID**, then enter these exact scopes as a comma-separated list under **OAuth scopes**:
8686

8787
```text
-123 KB
Binary file not shown.

0 commit comments

Comments
 (0)