Google Chat
Beta connector. Google Chat support is being rolled out to early customers. The enrollment steps and scopes below are accurate; your Teleskope contact confirms the final scope list with you during onboarding.
Teleskope classifies Google Chat messages and shared files for sensitive content across 150+ entity types, the same engine used for Google Drive and Slack. Findings appear in the Data Catalog, drive Policy Maker rules, and support remediation actions on violating messages.
Google Chat uses the same Google Workspace domain-wide delegation as the Google Drive connector. If you already enrolled Google Drive, you extend the existing service account rather than creating a new one.
Prerequisites
A Google Workspace administrator who can manage Domain-Wide Delegation.
The unique Teleskope service account ID (shared by Teleskope, or already in use for Google Drive).
Your Teleskope user has the Admin role.
Setup Domain Wide Delegation
In Google Workspace Admin, go to Security > Access and Data Control > API Controls > Domain Wide Delegation (manage domain wide delegation).
Add the Teleskope service account ID, or edit the existing Teleskope entry if Google Drive is already enrolled.
Under Scopes, ensure the following are present (comma-separated). These let Teleskope discover spaces, read message and file content, resolve members, and act on violating messages:
https://www.googleapis.com/auth/chat.spaces.readonly
Discover spaces
https://www.googleapis.com/auth/chat.messages.readonly
Read message content
https://www.googleapis.com/auth/chat.memberships.readonly
Resolve space membership
https://www.googleapis.com/auth/chat.admin.spaces.readonly
Enumerate spaces across the organization
https://www.googleapis.com/auth/chat.admin.memberships
Grant the Teleskope app access to spaces
https://www.googleapis.com/auth/chat.messages
Delete violating messages (Policy Maker)
Classification requires the read scopes plus chat.admin.spaces.readonly and chat.admin.memberships, so Teleskope can discover and join spaces. The chat.messages scope is required only if you enable Policy Maker remediation actions.
The directory scopes used to resolve users and groups (admin.directory.user.readonly, admin.directory.group.readonly) are shared with Google Drive. If Drive is already enrolled, they are already present.
Create Teleskope Super Admin User
Google Chat administrative operations are performed as a licensed Super Admin user that Teleskope impersonates. If you enrolled Google Drive, reuse that user.
In Google Workspace Admin, go to Directory > Users > Add new user and create a user for the Teleskope service account (e.g.
teleskope@company.com).Ensure the user is licensed (cloud identity is sufficient).
Go to Account > Admin roles and assign the user the Super Admin role.
Share the email of the Super Admin user with Teleskope.
Enroll in Teleskope
Navigate to Settings > Connectors > Google Chat.
Click Enroll+.
Confirm the Workspace domain and service account shown.
Click Enroll.
Teleskope discovers spaces across the organization, grants its app access, and begins scanning messages and shared files. Real-time monitoring of new and edited messages begins once enrollment completes.
Remediation
Policy Maker rules can act on Google Chat findings, including deleting violating messages and notifying data owners. The remediation actions available for your workspace are confirmed during onboarding.
Classifications & Filtering Behavior
Teleskope handles certain elements in specific ways. Below is a summary of the filtering logic and the elements not detected, for storage and noise-reduction reasons.
Credit Card Numbers
Credit card numbers must pass post-validation, meaning they pass Luhn Algorithm checks.
Social Security Numbers
While certain SSNs such as 123-45-6789 are structurally valid under SSA assignment rules, Teleskope proactively filters out common test patterns or sequences that are far more likely to be false positives. This reduces noise and inaccurate detections during scanning.
Email Addresses
Teleskope filters out internal and company-specific email addresses during scans, to reduce noise and manage storage, particularly during historical scanning where repeated internal contacts are storage-intensive.
The following elements are also skipped for similar storage and filtering reasons:
WEBSITEFIRST_NAMELAST_NAMEMIDDLE_NAMEUSER_IDENTIFIERLANGUAGEORGANIZATION
Last updated
Was this helpful?
