# Set up SSO with Google Workspace (/docs/support/security/single-sign-on/set-up-sso-with-google-workspace)

You can connect Google Workspace to Circleback by creating a custom SAML app in the Google Workspace Admin Console.

You need access to manage apps in Google Admin and to be an admin of your Circleback workspace.

1\. In Circleback, go to Settings → General (under Workspace).

2\. Under **Single sign-on**, select **Connect**. Choose **SAML**, then select **Continue**. Keep this form open.

3\. In another tab, open the Google Admin console and go to **[Apps](https://admin.google.com/ac/apps/unified)**[ → **Web and mobile apps**](https://admin.google.com/ac/apps/unified).

4\. Select **Add app** → **Add custom SAML app**.

Google Admin: Add custom SAML app

5\. Enter _Circleback_ as the app name, then select **Continue**.

Google Admin: enter an app name

6\. On the Google identity provider details page, select **Download Metadata**.

7\. In Circleback, under **Metadata source**, choose **Upload XML file** and upload the file you downloaded.

8\. Return to Google Admin and select **Continue**.

Google Admin: download identity provider metadata

9\. Copy the **ACS URL** and **Entity ID** from the open Circleback form into Google's **Service provider details** page, and set the Name ID fields as shown below:

| Field          | Value                                      |
| -------------- | ------------------------------------------ |
| ACS URL        | `https://circleback.ai/api/sso/oauth/saml` |
| Entity ID      | `https://circleback.ai/api/sso/metadata`   |
| Name ID format | EMAIL                                      |
| Name ID        | Basic Information → Primary email          |

10\. Select **Continue**, then add these attribute mappings:

| Google Directory attribute | App attribute |
| -------------------------- | ------------- |
| Primary email              | `email`       |
| First name                 | `firstName`   |
| Last name                  | `lastName`    |

Google Admin: email and name attribute mappings

11\. Select **Finish**.

12\. Open the Circleback app in Google Admin and select **User access**.

Google Admin: open User access

13\. Turn the service on for everyone or for the organizational units that should use Circleback.

14\. Select **Save**.

Google Admin: turn the service on for your team

15\. Return to the open Circleback form and select **Continue**. Leave **No directory sync** selected, then select **Connect**.

To require everyone in your workspace to log in with SSO, follow [Enforce SSO for your workspace](/docs/support/security/single-sign-on/sso).

This setup connects sign-in, not SCIM provisioning. To revoke someone's workspace access, [deactivate the member in Circleback](/docs/support/workspace-and-teams/deactivate-a-workspace-member).