Skip to main content

Google Workspace Email Signature Permissions and Admin Roles

What WiseStamp accesses on your Google Workspace domain, the OAuth scopes behind Auto-Inject and directory sync, plus WiseStamp roles and sign-in methods.

WiseStamp for IT › Google Workspace › Step 8 of 12 — Permissions Reference



Part 1 — Google permissions WiseStamp uses

WiseStamp accesses your Google Workspace through a Marketplace app (domain-wide) and, for individual setups, Google Connect (per-user OAuth).

Mechanism

Where granted

What it’s used for

Google Workspace Marketplace app

Installed domain-wide by a super admin ("Everyone at your organization")

Import employees, sync employee details from the directory, auto add/remove based on directory status, and inject signatures into Gmail (Auto-Inject)

Google Connect

Per-user OAuth consent

Write one signature into one user’s Gmail signature settings

Chrome Extension

Per-user sign-in (email + OTP)

Insert/select signatures in Gmail and Outlook web from the browser

WiseStamp states its Google integration mechanisms adhere to the Google API Services User Data Policy, including the Limited Use requirements, and that it does not access, store, or read email content.

What the super admin sees on the consent screen

When the super administrator installs the Marketplace app, Google shows a consent screen listing the permissions WiseStamp requests. These are used only to sync employees and deploy their signatures:

  • See, edit, create, or change your email settings and filters in Gmail (install and update employee signatures).

  • Manage your sensitive mail settings, including who can manage your mail.

  • Manage the email settings of users on your domain (apply signatures across the organization, not just one account).

  • See info about users on your domain (import the employee directory).

  • See your primary Google Account email address (identify the account completing the integration).

  • See your personal info, including any personal info you have made publicly available (populate signature fields such as name).

Google OAuth scopes:

Scope

Reference

WiseStamp reason

To retrieve users/aliases from the Google Workspace directory

To set an individual inbox’s signature HTML

Requested during installation but no longer in use in the product — previously used in a now-deprecated product behavior

For security reviewers

  • The Marketplace app is installed domain-wide; to limit which users are actually managed, use selective sync by OU/department (Scope Employee Sync) rather than expecting a narrower grant.

  • WiseStamp’s stated compliance posture includes SOC 2 Type II, ISO 27001, GDPR, and HIPAA, with TLS in-transit encryption. (See the Data Security material in the knowledge base.)

  • To verify the app’s granted status: Google Admin Console > Apps > Google Workspace Marketplace apps > open WiseStamp > permissions Granted.


Part 2 — WiseStamp account roles

WiseStamp roles control what your own team can do inside the WiseStamp app. Each account user has exactly one role. Roles & permissions management is a Platform/Enterprise capability (admin seat caps vary by plan — see Google Workspace IT Admin Guide).

Administrative roles

Role

Description

Permissions summary

Account Owner

Chief account manager. An account has exactly one owner.

Unlimited access.

Admin

Assists the Owner with all aspects of account management.

Access to all components, but cannot perform billing operations.

Organization Manager

Responsible for organization maintenance.

Access to all components except account details. Can be scoped to all or specific organizations.

Specialist roles

More limited roles intended for specialists with specific functions in the account:

Role

Description

Permissions summary

Marketer

Advertising / promotions management.

Access to Campaigns, Analytics, and all aspects of signature design.

HR

Employee management.

Access to employee details, group management, and signature assignments.

Designer

Signature creation, composition, and layout.

Access to signature editing functions, company data, and employee data.

IT

Management of employees and company organizations.

Access to all employee and organization management operations.

Scope assignment

For all roles except Admin, you choose whether the user has access to all organizations or specific organizations when assigning the role. Users with an Admin role are automatically assigned to all company organizations.

Managing roles

  • Assign: Employees > [three-dot] > Assign role (set scope, Save — invite emailed); or Profile > Account users > Add user.

  • Modify: Profile > Account users > hover row > Edit > change role > Save.

  • Transfer ownership: set a user’s role to Account Owner.

  • Remove: from Employees (Remove [role] permissions) or Account users (Delete).

Admins do not consume seats

Admin roles can be assigned without occupying an active employee seat. Seats are consumed by Active employees (people receiving signatures). See Ongoing Admin Guide.


Part 3 — Sign-in methods (admin access)

Admins can sign into WiseStamp via:

Employees do not sign into the main WiseStamp account; they use the Employee Hub.

Related articles


Did this answer your question?