This is a one-time setup your Workspace super-admin does so SGNAL can push signatures across your domain. After this is done, every signature edit in SGNAL flows into Gmail automatically — no copy-paste for your team.
Go to admin.google.com and sign in with a super-admin account. Then navigate to:
Scroll down the API controls page. Under Domain wide delegation, click MANAGE DOMAIN WIDE DELEGATION. On the next screen, click Add new.
In the Client ID field, paste:
⚠️ This placeholder will be replaced with the real Client ID once SGNAL's Google Cloud service account is configured.
In the OAuth Scopes field, paste the line below. These are the minimum permissions SGNAL needs to push signatures — read your user directory and update Gmail settings. Nothing else.
.../admin.directory.user.readonly
|
Read the list of mailboxes in your domain. SGNAL never modifies users — only reads them. |
.../gmail.settings.basic
|
Update each user's Gmail SendAs signature. Cannot read mail, cannot send mail, cannot change any other Gmail setting. |
Google confirms the new delegation. The next screen shows SGNAL in your list of authorised API clients with the two scopes attached.
In your SGNAL Integrations page, click Connect Workspace. You'll be redirected to Google to authenticate (this confirms which domain you're connecting and gives SGNAL the access tokens it needs). After consent, you're back on the Integrations page with a list of mailboxes ready to sync.
Open SGNAL Integrations →You're probably not signed in as a Workspace super-admin. Delegated admins, even with extensive privileges, can't see this page. Have a true super-admin do this step. (You can check by going to Account → Admin roles and confirming your user has the Super Admin role.)
Google takes up to 15 minutes to propagate delegation changes. Wait ten minutes, then click Push to all mailboxes again in SGNAL. If failures persist beyond an hour, check that the Client ID and scopes were pasted exactly as shown above — a single extra space breaks the match.
Yes, anytime. Back in API controls → Domain Wide Delegation, find the SGNAL client and click Remove. SGNAL will stop pushing new updates immediately. Signatures that have already been installed will remain in users' mailboxes until they manually change them.
Two things: read the list of mailboxes (names + emails) in your domain, and set/update the SendAs signature on each mailbox. SGNAL cannot read, send, delete, search, or forward any mail. The Gmail Settings Basic scope explicitly excludes message content access.
Yes. SGNAL respects whatever Google considers a primary email for each user. For aliases, SGNAL updates the signature on the primary SendAs address — which is the one Gmail uses by default when composing new mail.
Currently SGNAL pushes to every active mailbox represented as a member in the app. You control that in SGNAL itself — only members you add show up. Granular OU-based exclusions on the Google side are on our roadmap; in the meantime, just don't add those users to SGNAL.
Stuck? Email us — we'll jump on a call.