Google Workspace

As a Capacity Admin user, you can configure SAML 2.0 single sign-on (SSO) using Google Workspace as your identity provider. This article walks you through configuring Google Workspace as your identity provider (IdP), what to share with Capacity to complete setup, and what your users will see once SSO is enabled.


How it Works

In this configuration, Capacity is the service provider (SP) and Google Workspace is the identity provider (IdP). You'll add Capacity as a custom SAML app in your Google Admin console, configure it with the SAML values Capacity requires, and then share your IdP metadata with Capacity so we can complete the connection on our end.


Before You Begin

Before you can configure SAML 2.0 SSO in Google Workspace, you'll need:

  • An admin account within your CI environment.
  • A super admin user within Google Workspace to create and configure SSO applications.

Configure Google Workspace

Add SAML App

  • Sign in to the Google Admin console (admin.google.com) as a super administrator.
  • Go to Apps >> Web and mobile apps.
  • Select Add App >> Add custom SAML app.
  • Enter an app name (we recommend Capacity Conversation Intelligence
    1. Optional - upload a logo (you can request this from Capacity, or choose your own)
  • Select Continue.

Download Metadata

  • On the Google Identity Provider details page, download the IdP metadata XML file.
  • Select Continue.

Complete Basic SAML Configuration

On the Service Provider Details page, enter the values below, then select Continue.

FieldValue
ACS URLhttps://{your-environment-url}/AuthServices/Acs
Entity IDhttps://{your-environment-url}/AuthServices
Start URL (optional)https://{your-environment-url}/

Confirm Name ID

  • Leave Name ID set to its default (Primary email). Capacity identifies users by email address, so no custom Name ID mapping is needed for a standard setup. 
  • Select Continue through the attribute mapping screen β€” no attribute mappings are required
  • Select Finish.

Turn On App & Assign Users

  1. From the app settings page, select User access.
  2. Turn the app On for everyone, or scope it to specific organizational units
  3. Select Save.
  4. Confirm that the email addresses your users sign in to Capacity with match the email addresses they use in Google Workspace.

Account Activation and Sign-In Experience

When a Capacity user needs to be activated and they're using SSO, they should use the Sign in with... button rather than the Activate account button. Once SSO is enabled for your organization, your users' login page will include this option alongside standard sign-in.


What to Share with Capacity

ItemDescription
IdP metadata (XML)​The metadata file downloaded in step Download Metadata
Sign-in button label preference (Optional)Defaults to "Sign in with Google" unless you request otherwise.

Was this article helpful?