Google sign-in lets your team log in to Four/Four with Google Workspace accounts. There is no separate SSO setup: Log in with Google is switched on when an admin connects Google Calendar or Google Mail; either one is enough. You need a Google Workspace admin who can edit Domain-wide Delegation.
How sign-in works
When Google Calendar or Google Mail is connected, Four/Four records the connecting admin's email domain as your Google Workspace domain. People who enter their email on the login page are offered Log in with Google. Four/Four accepts only Google accounts from that domain and matches the person to a Four/Four user by email address. Personal Gmail accounts do not work.
Users must already exist in Four/Four (Settings > Team > Invite user). Google sign-in does not create accounts. Connect while signed in to Four/Four as a member of your Workspace domain, because that account decides which domain is allowed.
Set up
Go to Settings > Connections and scroll to Productivity services.
On the Google Calendar (or Google Mail) card, click Connect.
If Four/Four is not yet authorised, a "Connecting Google Workspace" window explains what to do. A Google Workspace admin opens Domain-wide Delegation in the Google Admin console, clicks Add new for API clients, and enters the Client ID and scope shown in the window.
Click Authorise in Google, then click Connect in Four/Four. Changes in Google can take a few minutes, so retry shortly if it fails.
The card shows Connected. To test, log out, enter your email and click Log in with Google.
Effect on the login page
Once Google (or Microsoft or Okta) sign-in is available, the password box is hidden for people in your workspace.
Log in with Email remains available and sends a one-time login link valid for one hour.
If you disconnect both Google Calendar and Google Mail, Google sign-in goes away.
Troubleshooting
What you see | Cause and fix |
Authentication failed on the card | The Domain-wide Delegation entry is missing or has the wrong scope. Check it in the Google Admin console. |
"An authentication error occurred during Google sign-in" | The Google account is not from your Workspace domain. |
"We were not able to log you in" | The person has no Four/Four user, or the Google email differs from the Four/Four email. |
Permissions
Connecting and disconnecting Google Calendar or Google Mail in Four/Four needs the Manage connections permission. Without it, you cannot connect or disconnect them.