Connection model
- Each user connects their own Google account. The connection goes through Google’s standard OAuth consent screen and is private to the user who initiated it. Other users in your Profound organization can’t use the same connection.
- No service account, domain-wide delegation, or admin consent. Profound doesn’t use a service account or domain-wide delegation, and a Workspace administrator doesn’t need to grant any permissions for a user to connect. Profound never accesses Drive with an identity other than the connected user’s, and it can’t reach anything that user can’t open.
- Access is narrower than the user’s own access. Profound requests the
drive.filescope, so it can only read files the user picks in the Google Picker and files Profound creates on the user’s behalf. Profound can’t list, search, or read anything else in the user’s Drive, even files that user can open.
OAuth scopes
Profound’s Google Drive integration doesn’t request any restricted Drive scope. See Choose Google Drive API scopes for Google’s classification of every Drive scope.
User flows
Knowledge Base imports
- A user with edit access to a Knowledge Base selects files in the Google Picker. Profound receives the ID, name, and file type of each selected file.
- Profound reads each selected file’s metadata and downloads its content. Google Docs export as
.docx, Google Sheets as.xlsx, and Google Slides and Drawings as PDF. PDF, Word, Excel, plain text, Markdown, and CSV files download as they are. Files larger than 100 MB aren’t imported. - Profound resolves the parent folder names of the selected files so it can recreate the folder structure inside the Knowledge Base.
Cache-Control: no-store.
Auto-sync
If a user turns on auto-sync for an imported Google Drive folder, Profound checks for changes on the chosen cadence using Google’s Changes API. On each run Profound:- re-downloads imported files whose content changed, and skips the ones whose content is unchanged
- removes the Knowledge Base copy of a file that was deleted from Drive, or that Profound can no longer access or download
Agent nodes
The Google Docs, Google Sheets, and Google Slides nodes in Agents use the same Google Drive connection and the samedrive.file grant. The read nodes read only the files the user selected. The create and write nodes (for example, creating a Google Doc or writing rows to a Google Sheet) create new files in the connected user’s Drive or modify files the user selected.
Nodes that accept a file by name search only within the files the drive.file grant covers, and ask for a file ID or URL if the name matches more than one file.
Operations Profound performs with the Drive API
These are the only Drive API operations the Google Drive connection performs. Writes to Drive happen only through the Google Docs and Google Sheets Agent nodes.
Where imported content is stored
Profound stores only the files that users import into a Knowledge Base. Agent read nodes also download the content of the files they read from, but only for that run: the content becomes the node’s output, which Profound keeps in the Agent run’s history like every other node output. For each imported file, Profound stores:- the file content in an Amazon S3 bucket, logically separated in Profound’s AWS account
- the parsed text in the same S3 bucket, and its search embeddings in a managed vector search service, so Knowledge Base search can find it
- the file’s name, path, size, type, source link, and content hash in Profound’s database
Deletion and retention
Profound keeps imported content until one of these happens:- a user deletes the document, the folder, or the Knowledge Base in Profound
- auto-sync detects that the file was deleted from Drive or is no longer accessible
Token storage and handling
- Encryption: Profound envelope-encrypts the OAuth access and refresh tokens with an AWS Key Management Service (KMS) key reserved for customer data and stores the ciphertext in Amazon DynamoDB. The encryption context binds each record to one organization, one provider, and one user, so a record can’t be decrypted under another organization’s or user’s identity. Profound’s main database holds only a reference to the encrypted record, never the tokens.
- Scoping: Every credential read checks that the connection belongs to the requesting user’s organization, and, for personal connections like Google Drive, to the requesting user. Profound records every credential read in an internal audit table, with the integration, the requesting endpoint, the user the read ran for, and a timestamp. This record isn’t visible in the platform.
- Refresh: Profound requests offline access from Google, so it receives a refresh token and can keep Knowledge Base auto-sync running without asking the user to sign in again. When an access token expires, Profound’s backend exchanges the refresh token for a new one. If several requests need the token at the same moment, only one of them contacts Google. The others wait for that refresh to finish and reuse its result.
- What’s stored about the account: Profound stores the Google account’s email address and its subject identifier (the
subkey in the ID token’s payload) alongside the connection. The subject identifier never changes, even when the account’s email address does, so Profound uses it to recognize when a user reconnects the same account.
Revoking access
Users revoke the connection in Profound under Settings > Integrations > Google Drive, from the … action menu on the connected account, by selecting Revoke. When a user revokes:- Profound deletes the encrypted token record and marks the connection as revoked. The deletion isn’t reversible.
- If this is the account’s last remaining Google connection in your organization, Profound also calls Google’s token revocation endpoint for the access token and the refresh token. Otherwise it defers that call, as explained below.
- Knowledge Base auto-sync and Agent nodes that use the connection stop working until the user connects again.
Users can also revoke Profound’s access from their Google account’s third-party access page. Profound’s stored refresh token then stops working, and the user needs to reconnect the account in Profound before using the integration again.
Controls for Google Workspace administrators
- Allow or block Profound as an app. Manage Profound’s access as described in Google’s Control which third-party and internal apps access Google Workspace data. This setup may require Profound’s OAuth client ID. Your Profound account team can provide it.
- Limited access is enough for the Google Drive integration. Google’s Limited access setting allows apps to use unrestricted scopes only.
drive.file,openid, anduserinfo.emailare all unrestricted, so the Google Drive integration works under Limited. - One client covers Profound’s Google integrations. Because Profound’s Google Drive, Gmail, Google Search Console, and Google Ads integrations share one OAuth client (Google Analytics has its own), an allowlist or block applies to all of them.