Skip to main content
Profound uses the Google Drive connection in Knowledge Bases and in Agents. Every request runs with the connected user’s token, and every request first checks that the connection belongs to the requesting user’s organization and to that user.

Connection model

  • Each user connects their own Google account. The connection goes through Google’s standard OAuth consent screen and is private to the user who initiated it. Other users in your Profound organization can’t use the same connection.
  • No service account, domain-wide delegation, or admin consent. Profound doesn’t use a service account or domain-wide delegation, and a Workspace administrator doesn’t need to grant any permissions for a user to connect. Profound never accesses Drive with an identity other than the connected user’s, and it can’t reach anything that user can’t open.
  • Access is narrower than the user’s own access. Profound requests the drive.file scope, so it can only read files the user picks in the Google Picker and files Profound creates on the user’s behalf. Profound can’t list, search, or read anything else in the user’s Drive, even files that user can open.

OAuth scopes

Profound’s Google Drive integration doesn’t request any restricted Drive scope. See Choose Google Drive API scopes for Google’s classification of every Drive scope.
Profound requests these scopes when a user connects Google Drive:

User flows

Knowledge Base imports

  • A user with edit access to a Knowledge Base selects files in the Google Picker. Profound receives the ID, name, and file type of each selected file.
  • Profound reads each selected file’s metadata and downloads its content. Google Docs export as .docx, Google Sheets as .xlsx, and Google Slides and Drawings as PDF. PDF, Word, Excel, plain text, Markdown, and CSV files download as they are. Files larger than 100 MB aren’t imported.
  • Profound resolves the parent folder names of the selected files so it can recreate the folder structure inside the Knowledge Base.
To open the Google Picker, Profound’s web app requests the connected account’s access token from Profound’s backend and passes it to Google’s Picker library in the user’s browser. The response carrying the token is marked Cache-Control: no-store.

Auto-sync

If a user turns on auto-sync for an imported Google Drive folder, Profound checks for changes on the chosen cadence using Google’s Changes API. On each run Profound:
  • re-downloads imported files whose content changed, and skips the ones whose content is unchanged
  • removes the Knowledge Base copy of a file that was deleted from Drive, or that Profound can no longer access or download
Profound performs these actions as the user who turned auto-sync on, using that user’s connection. Auto-sync only tracks files that were imported. It can’t see files the user didn’t select.

Agent nodes

The Google Docs, Google Sheets, and Google Slides nodes in Agents use the same Google Drive connection and the same drive.file grant. The read nodes read only the files the user selected. The create and write nodes (for example, creating a Google Doc or writing rows to a Google Sheet) create new files in the connected user’s Drive or modify files the user selected. Nodes that accept a file by name search only within the files the drive.file grant covers, and ask for a file ID or URL if the name matches more than one file.

Operations Profound performs with the Drive API

These are the only Drive API operations the Google Drive connection performs. Writes to Drive happen only through the Google Docs and Google Sheets Agent nodes.

Where imported content is stored

Profound stores only the files that users import into a Knowledge Base. Agent read nodes also download the content of the files they read from, but only for that run: the content becomes the node’s output, which Profound keeps in the Agent run’s history like every other node output. For each imported file, Profound stores:
  • the file content in an Amazon S3 bucket, logically separated in Profound’s AWS account
  • the parsed text in the same S3 bucket, and its search embeddings in a managed vector search service, so Knowledge Base search can find it
  • the file’s name, path, size, type, source link, and content hash in Profound’s database
Profound uses imported content only as a source of information for the features you use it in, such as Knowledge Base search, Agents, and FactCheck. Profound doesn’t use your files to train models.

Deletion and retention

Profound keeps imported content until one of these happens:
  • a user deletes the document, the folder, or the Knowledge Base in Profound
  • auto-sync detects that the file was deleted from Drive or is no longer accessible
Deleting a document removes the stored file, its parsed text, and its search embeddings. Revoking the Google Drive connection doesn’t delete files that were already imported. Delete them from the Knowledge Base if you need them removed.

Token storage and handling

  • Encryption: Profound envelope-encrypts the OAuth access and refresh tokens with an AWS Key Management Service (KMS) key reserved for customer data and stores the ciphertext in Amazon DynamoDB. The encryption context binds each record to one organization, one provider, and one user, so a record can’t be decrypted under another organization’s or user’s identity. Profound’s main database holds only a reference to the encrypted record, never the tokens.
  • Scoping: Every credential read checks that the connection belongs to the requesting user’s organization, and, for personal connections like Google Drive, to the requesting user. Profound records every credential read in an internal audit table, with the integration, the requesting endpoint, the user the read ran for, and a timestamp. This record isn’t visible in the platform.
  • Refresh: Profound requests offline access from Google, so it receives a refresh token and can keep Knowledge Base auto-sync running without asking the user to sign in again. When an access token expires, Profound’s backend exchanges the refresh token for a new one. If several requests need the token at the same moment, only one of them contacts Google. The others wait for that refresh to finish and reuse its result.
  • What’s stored about the account: Profound stores the Google account’s email address and its subject identifier (the sub key in the ID token’s payload) alongside the connection. The subject identifier never changes, even when the account’s email address does, so Profound uses it to recognize when a user reconnects the same account.

Revoking access

Users revoke the connection in Profound under Settings > Integrations > Google Drive, from the … action menu on the connected account, by selecting Revoke. When a user revokes:
  • Profound deletes the encrypted token record and marks the connection as revoked. The deletion isn’t reversible.
  • If this is the account’s last remaining Google connection in your organization, Profound also calls Google’s token revocation endpoint for the access token and the refresh token. Otherwise it defers that call, as explained below.
  • Knowledge Base auto-sync and Agent nodes that use the connection stop working until the user connects again.
The Google Drive, Gmail, Google Search Console, and Google Ads integrations identify themselves to Google with the same OAuth client (Google Analytics uses a separate one). Google treats all permissions a Google account has granted to that client as a single grant, and revoking any token invalidates every token Google issued to that account for Profound. This is why revoking one connection deletes its stored tokens in Profound immediately, but Profound asks Google to revoke the grant only when the account’s last remaining connection is revoked. Connections made with other Google accounts aren’t affected.
Users can also revoke Profound’s access from their Google account’s third-party access page. Profound’s stored refresh token then stops working, and the user needs to reconnect the account in Profound before using the integration again.

Controls for Google Workspace administrators

  • Allow or block Profound as an app. Manage Profound’s access as described in Google’s Control which third-party and internal apps access Google Workspace data. This setup may require Profound’s OAuth client ID. Your Profound account team can provide it.
  • Limited access is enough for the Google Drive integration. Google’s Limited access setting allows apps to use unrestricted scopes only. drive.file, openid, and userinfo.email are all unrestricted, so the Google Drive integration works under Limited.
  • One client covers Profound’s Google integrations. Because Profound’s Google Drive, Gmail, Google Search Console, and Google Ads integrations share one OAuth client (Google Analytics has its own), an allowlist or block applies to all of them.