Falaah Falaah AI

Connect a Google Workspace mailbox

Connect a work Google Workspace mailbox to Muin via OAuth so inbound Gmail lives in the comms hub alongside donor receipts. Read-only — Muin does not send from your address.

Connect a Google Workspace (work) Gmail account to Muin so messages you already receive in Gmail show up alongside donor receipts and replies in the unified comms inbox. Connection is per-user — each teammate connects their own mailbox.

Read-only. Muin syncs mail in. It does not send from your Gmail address, and you can’t reply to a synced thread from inside Muin yet — reply from Gmail as usual. Only new mail is synced; messages received before you connect stay in Gmail.

Workspace vs personal Gmail. This guide is for Workspace accounts (Gmail at your organization’s custom domain, managed by an admin in Google Admin). If you have a personal @gmail.com address, see Connect a personal Gmail account — the flow is different and protects more of your privacy.

Prerequisites

  • A Google Workspace account on Business Standard or higher (the editions that allow third-party app trust).
  • Your Workspace super-admin must trust Muin’s OAuth client once. Step-by-step for them: Workspace admin setup. Until they trust Muin, you’ll see “unverified app” warnings during the consent flow.
  • Muin tier: any tier with the Communications Hub enabled.

Step-by-step

  1. Sign in to Muin and go to SettingsCommunicationsConnected mailboxes, or open the wizard directly at /settings/communications/mailbox/connect.
  2. Choose Google Workspace on the provider-select step.
  3. If your admin hasn’t trusted Muin yet, the wizard shows you the Workspace admin trust step. Click Send admin instructions to email your IT admin a one-page guide. You can pause and resume the wizard once they confirm.
  4. Once trust is in place, click Connect with Google. Google signs you in and shows the permissions screen. Review and click Allow.
  5. Pick which Gmail labels Muin syncs (default: INBOX). You can change this from the connected-mailboxes page later.
  6. Muin starts a one-time backfill of the most recent 100 messages, then syncs new mail every 5 minutes via Gmail history delta polling.

What Muin can see

Scope Why we ask for it
gmail.readonly (selected labels) Show your inbound mail in the unified comms inbox; thread replies; let AI suggest drafts.
email, openid Identify which mailbox connected.

We do not request gmail.send. Muin never sends from your address, so we don’t ask for permission to.

We do not request access to Drive, Calendar, Contacts, Chat, or any other Workspace service.

Privacy

  • Tokens are encrypted at rest with our platform KMS.
  • Mailbox connections are per-user. Your colleagues never see your connected messages unless your tenant admin opens the admin-only team-mailbox view (read-only).
  • We never log full message bodies. PII is masked in audit/observability.
  • Disconnect any time — tokens are cleared immediately.

Troubleshooting

Symptom Action
“App is blocked: this app’s request is invalid” Workspace admin hasn’t trusted Muin yet. See Workspace admin setup.
“Unverified app” warning persists after admin trust Token cache — re-trigger the in-app flow. If the warning stays >1 hour, click Get help to open a tagged ticket.
Connected but no messages Check Sync status on the connected-mailboxes page. The email-mailbox-sync-error runbook covers each error code.

Disconnecting

SettingsCommunicationsConnected mailboxesDisconnect clears tokens and stops syncing. You choose whether to delete already-synced messages.

Next steps