# Connect Google Analytics, Search Console, Gmail and Drive

Source: https://auditae.app/docs/google

One Google sign-in covers analytics, Search Console, Gmail and Drive. Then pick a GA4 property and a Search Console site for each site.

## Steps

### 1. Grant Google access for the workspace

1. Go to [Integrations](https://auditae.app/dashboard/integrations).
2. Click **Connect** on any of the four Google connectors. They all share the same grant, so one click covers all four. In a team workspace, only an admin can connect or disconnect Google.
3. Sign in with the Google account that owns your analytics data and the address you'd like AEBOT to send from.
4. On the consent screen you'll see **four scopes**. Approve them all to enable the full feature set:
   - `analytics.readonly`: GA4 traffic data. **Read-only.**
   - `webmasters.readonly`: Search Console queries and clicks. **Read-only.**
   - `gmail.send`: compose and send mail from your address. **Cannot read existing mail, drafts, or labels.**
   - `drive.file`: create new Google Docs or Markdown files in your Drive. **Restricted by Google to files AuditAE itself created**, so we can't see anything else in your Drive.

Connected before we shipped Gmail and Drive? You'll see a **Reconnect** banner on [Integrations](https://auditae.app/dashboard/integrations). One click re-grants the missing scopes without affecting your saved GA4 and Search Console picks.

### 2. Pick a GA4 property and a Search Console site for each site

1. Open the site from [Sites](https://auditae.app/dashboard/sites).
2. Open the site's **Settings** (gear icon) → **Connections**.
3. Pick a GA4 property and a Search Console site from the dropdowns.
4. Click **Save selection**. Real data shows on the site's **Traffic** → **Search & analytics** tab on next load, and the overview's status bar adds a Search Console clicks chip that links there.

Repeat for each site. Each one can point at its own GA4 property if you track several brands. Gmail and Drive don't need this step; they apply to whatever site or report AEBOT is working with at the time.

## How the connection works

One Google connection unlocks four capabilities: read analytics, read Search Console, send mail from your address, and save reports to Drive. They all share a single OAuth grant: you approve every scope on Google's consent screen up front and can disconnect everything in one click later.

Setup has two layers: a **one-time workspace-level OAuth grant**, then (for GA4 and Search Console only) a **per-site property pick**. Gmail and Drive are workspace-wide, with no per-site setup.

The same connection powers the free GA4 and Search Console tools for AI agents (`query_google_analytics` and `query_search_console`), so there's no Google Cloud project to set up. See [Connect Claude, ChatGPT or Cursor](https://auditae.app/docs/mcp) and the [Google Analytics MCP page](https://auditae.app/google-analytics-mcp).

## Action scopes: abilities and risks

Two of the four scopes let AEBOT take real actions in your Google account. Both are narrow on purpose, but the consequences are real: sent mail can't be unsent, and a Drive doc inherits whatever sharing rules you put on its parent folder. AEBOT always confirms recipients and content in chat before calling either tool.

### Gmail (gmail.send)

- **Can:** compose, send, CC and BCC mail (plain text or HTML). The message's `From:` is your Google address, so recipients see your name and email.
- **Cannot:** read your inbox, search threads, see drafts, modify labels, or view sent mail beyond the message AEBOT just sent.
- **Risks to know:** sent mail is final; there is no "undo" from our side. AEBOT shows the recipient list and full body before pressing send and waits for an explicit yes. Treat the first send as a test and CC yourself.

### Drive (drive.file)

- **Can:** create new Google Docs or `.md` files in your Drive, including reports AEBOT writes, optionally inside a specific folder you name.
- **Cannot:** see, read, edit, list, or delete any file it didn't create. `drive.file` is the most restricted Drive scope Google offers, and Google enforces the boundary, not us.
- **Risks to know:** a saved report inherits the sharing rules of its parent folder. New files default to private (only your Google account can see them); if you ask AEBOT to put one inside a folder shared with your team, the team sees it.

Both action scopes can be revoked instantly with the **Disconnect** button on [Integrations](https://auditae.app/dashboard/integrations). We call Google's revoke endpoint and drop the refresh token, after which any future tool call refuses until you reconnect.

## What we store

- A **refresh token** at the workspace level, used to mint short-lived access tokens for each API call. Encrypted at rest.
- Your Google email (Integrations shows it next to the Google connectors) and the granted scope list.
- For GA4 and Search Console: the selected property and site identifiers on each site.
- For Gmail: nothing per message. Sent mail lives in your Sent folder, not ours.
- For Drive: nothing per file. Saved reports live in your Drive only.

Disconnecting calls Google's revoke endpoint and deletes the workspace token. Reconnecting replaces it with a fresh grant.

## Troubleshooting

- **"Google access was revoked":** Google stopped accepting AuditAE's access (for example, access was removed in your Google account or the password changed), so GA4, Search Console, Gmail and Drive are paused. Click **Reconnect Google** on [Integrations](https://auditae.app/dashboard/integrations).
- **"API has not been used in this project":** enable the named API in the Google Cloud Console (the error message includes the exact URL). Wait about a minute after enabling for it to take effect.
- **"Not enough data" on the Traffic chart:** GA4 needs a couple of days of recorded sessions before the daily series fills in.
- **Empty top query in Search Console:** Search Console data lags about two days, and a query needs a minimum number of clicks before it appears.

## What to do next

- Share the same traffic, search and conversion data with a client: [Share a client portal](https://auditae.app/docs/client-portal).
- Ask AEBOT about your traffic, or have it email or save a report: [Using AEBOT](https://auditae.app/docs/aebot).
