WiseStamp for IT › Google Workspace › Step 8 of 12 — Permissions Reference
Part 1 — Google permissions WiseStamp uses
WiseStamp accesses your Google Workspace through a Marketplace app (domain-wide) and, for individual setups, Google Connect (per-user OAuth).
Mechanism | Where granted | What it’s used for |
Google Workspace Marketplace app | Installed domain-wide by a super admin ("Everyone at your organization") | Import employees, sync employee details from the directory, auto add/remove based on directory status, and inject signatures into Gmail (Auto-Inject) |
Google Connect | Per-user OAuth consent | Write one signature into one user’s Gmail signature settings |
Chrome Extension | Per-user sign-in (email + OTP) | Insert/select signatures in Gmail and Outlook web from the browser |
WiseStamp states its Google integration mechanisms adhere to the Google API Services User Data Policy, including the Limited Use requirements, and that it does not access, store, or read email content.
What the super admin sees on the consent screen
When the super administrator installs the Marketplace app, Google shows a consent screen listing the permissions WiseStamp requests. These are used only to sync employees and deploy their signatures:
See, edit, create, or change your email settings and filters in Gmail (install and update employee signatures).
Manage your sensitive mail settings, including who can manage your mail.
Manage the email settings of users on your domain (apply signatures across the organization, not just one account).
See info about users on your domain (import the employee directory).
See your primary Google Account email address (identify the account completing the integration).
See your personal info, including any personal info you have made publicly available (populate signature fields such as name).
Google OAuth scopes:
Scope | Reference | WiseStamp reason |
To retrieve users/aliases from the Google Workspace directory | ||
To set an individual inbox’s signature HTML | ||
Requested during installation but no longer in use in the product — previously used in a now-deprecated product behavior |
For security reviewers
The Marketplace app is installed domain-wide; to limit which users are actually managed, use selective sync by OU/department (Scope Employee Sync) rather than expecting a narrower grant.
WiseStamp’s stated compliance posture includes SOC 2 Type II, ISO 27001, GDPR, and HIPAA, with TLS in-transit encryption. (See the Data Security material in the knowledge base.)
To verify the app’s granted status: Google Admin Console > Apps > Google Workspace Marketplace apps > open WiseStamp > permissions Granted.
Part 2 — WiseStamp account roles
WiseStamp roles control what your own team can do inside the WiseStamp app. Each account user has exactly one role. Roles & permissions management is a Platform/Enterprise capability (admin seat caps vary by plan — see Google Workspace IT Admin Guide).
Administrative roles
Role | Description | Permissions summary |
Account Owner | Chief account manager. An account has exactly one owner. | Unlimited access. |
Admin | Assists the Owner with all aspects of account management. | Access to all components, but cannot perform billing operations. |
Organization Manager | Responsible for organization maintenance. | Access to all components except account details. Can be scoped to all or specific organizations. |
Specialist roles
More limited roles intended for specialists with specific functions in the account:
Role | Description | Permissions summary |
Marketer | Advertising / promotions management. | Access to Campaigns, Analytics, and all aspects of signature design. |
HR | Employee management. | Access to employee details, group management, and signature assignments. |
Designer | Signature creation, composition, and layout. | Access to signature editing functions, company data, and employee data. |
IT | Management of employees and company organizations. | Access to all employee and organization management operations. |
Scope assignment
For all roles except Admin, you choose whether the user has access to all organizations or specific organizations when assigning the role. Users with an Admin role are automatically assigned to all company organizations.
Managing roles
Assign: Employees > [three-dot] > Assign role (set scope, Save — invite emailed); or Profile > Account users > Add user.
Modify: Profile > Account users > hover row > Edit > change role > Save.
Transfer ownership: set a user’s role to Account Owner.
Remove: from Employees (Remove [role] permissions) or Account users (Delete).
Admins do not consume seats
Admin roles can be assigned without occupying an active employee seat. Seats are consumed by Active employees (people receiving signatures). See Ongoing Admin Guide.
Part 3 — Sign-in methods (admin access)
Admins can sign into WiseStamp via:
Email address + password
Continue with Google
Continue with Facebook
SSO (SAML 2.0) — Platform/Enterprise; see SSO with Google Workspace (SAML)
Employees do not sign into the main WiseStamp account; they use the Employee Hub.