# Set up SSO with Google Workspace

> Connect Google Workspace to Privatus Analytics with a custom SAML app for single sign-on, including the ACS URL, entity ID, Name ID and provisioning options.

1. In the Google Admin console go to **Apps → Web and mobile apps → Add
   app → Add custom SAML app**. Name it "Privatus Analytics".
2. On **Google Identity Provider details**, copy the **SSO URL**, **Entity
   ID** and **Certificate** (or download the metadata). Continue.
3. **Service provider details:**

   | Google field | Value |
   |---|---|
   | ACS URL | `https://privatusanalytics.com/users/auth/saml/callback` |
   | Entity ID | `https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_…` |
   | Name ID format | EMAIL |
   | Name ID | Basic Information › Primary email |

4. **Attribute mapping** (optional): map *First name* and *Last name*, or
   add `name`.
5. Finish, then turn the app **ON for everyone** or for selected
   organizational units or groups.
6. In Privatus Analytics, **Workspace settings → SSO → SAML**: paste the
   SSO URL, entity ID and certificate, list your email domains, and save.
7. **Test** in Privatus Analytics, then **Activate**.

Google Workspace doesn't offer SCIM for custom SAML apps. Use
just-in-time provisioning and remove members in Privatus Analytics when they leave,
or connect provisioning through another directory.

Everyone can also use **Sign in with Google** without SAML, if Google
sign-in is allowed in your workspace's security settings.
