Stack Internal Support

Configure the Google Docs Source

How to connect to your Google workspace.

ADMIN PRIVILEGES REQUIRED

Google Docs Source

Stack Internal helps your organization find trusted knowledge across the tools your teams already use. The Google Docs source brings selected Google Docs content into Stack Internal so employees can discover relevant answers through Stack Internal search and chat alongside content from other connected sources.

What the Google Docs Source does

The Google Docs source ingests approved Google Docs content into Stack Internal's knowledge layer. Once connected, Stack Internal can index selected documents, normalize their content, and make relevant information available to users through Stack Internal's knowledge experiences.

With the source enabled, Stack Internal can:

  • Ingest Google Docs from approved Google Drive folders.
  • Read document metadata and document content for indexing.
  • Keep Google Docs content represented as Stack Internal knowledge objects, so it can be retrieved alongside other connected sources.
  • Preserve stable references to source documents so answers can be traced back to the original Google Doc where available.

Current permissions and scope

By default, the Google Docs source operates on an opt-in basis, meaning Stack Internal will not ingest any content until an administrator actively enables and configures it. This setup is governed entirely by administrators, who control the scope of ingestion by supplying an allowlist of specific Google Drive folder IDs or URLs. Only files within these designated directories will be evaluated for ingestion.

The integration primarily targets documents marked as unrestricted under general Google Docs settings, which means restricted items might not be pulled into the system. If the source encounters issues locating or accessing a configured folder, Stack Internal is designed to flag this discrepancy during setup validation or connection testing.

As a result, it is highly recommended to audit the sharing settings of your intended folders and documents prior to enabling the source. The exact content exposed to Stack Internal users will ultimately depend on the folders you allowlist and the specific access model utilized by your deployment.

Before you begin

You’ll need:

  • A Google Workspace super administrator
  • The Stack Internal service-account client ID: [SERVICE ACCOUNT CLIENT ID]
  • A dedicated Google Workspace user for the integration
  • The IDs of the shared drives or folders you want to connect

The dedicated user must have access to every shared drive or folder you want Stack Internal to ingest. Stack Internal can only access content that this user can access.

Setup Instructions

(Optional) Creating a delegated user: We recommend creating a dedicated Google Workspace user for the integration instead of using an employee’s account. Add this user to each shared drive or folder that Stack Internal should access. Confirm that the user can open the intended Google Docs. Using a dedicated user makes the connection easier to manage and prevents it from being interrupted when an employee changes roles, loses access, or leaves your organization.

Create or choose a Google Cloud project

  1. Open Google Cloud Console.
  2. Create a new project, or select an existing project you want to use for this integration.
  3. Give it a clear name such as Stack Internal Google Connector.

Enable the required APIs

  1. Open APIs & Services then Library.
  2. Search for Google Drive API and click Enable.
  3. Search for Google Docs API and click Enable.
  1. In Google Cloud Console, open Google Auth Platform then Branding.
  2. If prompted, click Get started.
  3. Enter:
    • App name: something clear, such as Stack Internal Google Connector
    • User support email: an admin-owned mailbox
    • Contact email: an admin-owned mailbox
  4. Choose the audience:
    • Internal if the app will only be used inside your Google Workspace organization and that option is available
    • External if Internal is not available
  5. Review and create the consent configuration.

If you use External

Add the account that will complete the Stack Internal connection as a test user until the app is ready for broader use.

Add data access scopes

In Google Auth Platform then Data Access, add the scopes Stack Internal needs:

  • https://www.googleapis.com/auth/documents.readonly
  • https://www.googleapis.com/auth/drive.readonly

documents.readonly is a sensitive scope and drive.readonly is a restricted scope. If your project is external, Google may require additional verification and policy review before broad rollout.

Create an OAuth 2.0 Client ID

  1. In Google Cloud Console, open Google Auth Platform then Clients.
  2. Click Create Client.
  3. Choose Web application.
  4. Give the client a clear name, such as Stack Internal Web Client.
  5. Under Authorized redirect URIs, add the exact URI provided by Stack Internal.
    • If Stack Internal gives you more than one redirect URI, add all of them.
    • The value must match exactly, including https, path, and trailing slash if present.
  6. Click Create.

Copy the Client ID and Client secret

  1. After the client is created, copy the OAuth credentials.
  2. Use whichever Google view is available in your console:
    • copy the values directly from the client details page, or
    • download the OAuth client JSON file and copy:
      • [client_id]
      • [client_secret]
  3. Keep the client secret secure.
  4. Enter the credentials in Stack Internal and click Connect.

Once configured, Stack Internal will ingest content from the approved folders and make it available through Stack Internal's knowledge experiences.

Finding Google Drive folder IDs

You can provide either a Google Drive folder URL or the folder ID itself, depending on your Stack Internal setup experience.

A folder URL typically looks like this:

https://drive.google.com/drive/folders/1XkavvlQkGYbPa6URTxDqaYdRhgC97UNL

In this example, the folder ID is:

1XkavvlQkGYbPa6URTxDqaYdRhgC97UNL

You can copy and paste the full URL directly from Google Drive.

Troubleshooting

Unauthorized client

Confirm that the service-account client ID was entered correctly in Google Admin and that domain-wide delegation has been authorized.

Missing scope

Open the client in Manage Domain Wide Delegation and confirm that both required scopes are listed exactly as shown above.

Invalid delegated user

Confirm that the email address belongs to an active user in your Google Workspace organization.

Drive or folder access denied

Confirm that the delegated user has access to the configured shared drive or folder and that the supplied ID is correct.

The connection was authorized recently

Wait a few minutes and test again. Google advises that domain-wide delegation changes can occasionally take up to 24 hours.

What users can expect

After the source is configured and synced, users can ask questions in Stack Internal and receive answers informed by content from connected Google Docs, where relevant. Google Docs content can be retrieved alongside other knowledge sources connected to Stack Internal. Longer documents may take more processing and may be broken into smaller knowledge units for retrieval.

Ongoing administration

Administrators should periodically review:

  • The list of connected Google Drive folders.
  • Whether folder sharing settings still match the organization's expectations.
  • The last successful sync time.
  • Any folders or documents that fail ingestion.
  • Whether new knowledge areas should be added to the allowlist.

If a folder should no longer be ingested, remove it from the source configuration. If the source is disabled, Stack Internal will stop future ingestion from Google Docs.

Revoke access

To disconnect Stack Internal at any time:

  1. In the Google Admin console, go to Security → Access and data control → API controls → Manage Domain Wide Delegation.
  2. Find the Stack Internal service-account client.
  3. Select Delete.

Deleting the authorization immediately prevents the Google Docs source from accessing your Workspace data. You can also remove the dedicated user from the applicable drives or folders to revoke access to specific content.

When the source is disabled:

  • Stack Internal stops future Google Docs ingestion.
  • New content from the selected folders is no longer synced.
  • Previously ingested content may remain available in Stack Internal.

If your organization needs previously ingested content removed, please contact support.

If you have any questions or need help, please open a ticket on our help center or email us at support@stackoverflow.com.

https://doc-automation.netlify.app/pdfs/docs/internal/for_admins/sources/configure_google_source.pdf

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article