Workspace directory
Once you’ve connected Google Workspace or Microsoft Entra ID, Sencai keeps a synced, browsable copy of parts of your directory under Workspace in the sidebar. These screens are mostly read-only reflections of your identity provider - changes you make there are picked up on the next sync, not the other way around, with two exceptions noted below.
Directory - users and groups
Section titled “Directory - users and groups”Settings → Directory (/gravity/workspace/directory) lists synced
directory users and groups, with Users/Groups tabs and filter chips (All /
Active / Suspended / Admins) plus an email/name search box.
This view is populated by the hourly Google Workspace sync. If you’ve also connected Microsoft Entra ID for license sync, note that Entra directory sync (as opposed to license data) doesn’t have a self-service trigger in the app today - some fields shown here (organizational unit, admin status) are Google Workspace concepts and won’t be populated for an Entra-sourced row even where directory sync has run.
The page is entirely read-only: there’s no “Add user” or “Add group” action here - provisioning goes the other way, from your identity provider into Sencai. If you want Sencai actions (like organization membership) to be driven automatically from user/group changes in your provider, see SCIM provisioning instead, which is a different, write-capable mechanism.
Organizational units
Section titled “Organizational units”Settings → Org Units (/gravity/workspace/org-units, Google Workspace
only) shows your Workspace OU tree and lets you move a member between
units.
- Select Sync from Google to pull the current OU structure on demand, rather than waiting for the next scheduled sync.
- Each OU shows its member and sub-OU counts, last-synced time, and a Move Member action - enter a user’s email (and, optionally, their current OU) to move them. This is a real, immediate write against your Google Workspace directory, not just a Sencai-side record.
If your organization has more than one Workspace tenant connected, select which one you’re viewing from the tenant dropdown at the top - the sync and move actions apply to whichever tenant is selected.
Licenses
Section titled “Licenses”Settings → Licences (/gravity/workspace/licences, Google Workspace
only) has two parts:
- A seat overview showing your most recent license snapshot - assigned seat counts per SKU, with SKUs that have zero assignments called out first (a paid-but-unused signal worth acting on).
- A table of individual license assignments, with Assign Licence and Revoke actions.
To assign a license, provide the user’s email, the license SKU, and the associated product ID. Assignments show as Active until revoked; there is currently no distinct “pending” state to wait through.
Cloud Identity Premium
Section titled “Cloud Identity Premium”Settings → Cloud Identity (/gravity/workspace/cloud-identity, Google
Workspace only) surfaces your Google Cloud Identity Premium posture, if
your Workspace edition includes it: whether Context-Aware Access and the
Advanced Protection Program are enabled, Security Command Center
integration status, and a list of findings with severity (critical / high
/ medium / low) and a recommendation for each.
What syncs where, and how often
Section titled “What syncs where, and how often”| Screen | Source | Refresh |
|---|---|---|
| Directory (users/groups) | Google Workspace | Hourly, automatic |
| Org Units | Google Workspace | Hourly, or on-demand via Sync from Google |
| Licenses (seat overview) | Google Workspace | Follows the same snapshot cadence as the directory sync |
| Microsoft 365 license counts | Microsoft Entra ID | Nightly - see the MS365 Integration sync overview |
| Cloud Identity Premium | Google Workspace | On-demand via Scan Now (see note above) |
What’s next
Section titled “What’s next”- Single sign-on - connect Google Workspace or Microsoft Entra ID
- Identity watchdog - security events detected across your connected directories
- SCIM provisioning - provider-driven, write-capable membership sync