Integration options for Google Workspace and Microsoft 365
29 min
ashby integrates with google workspace and microsoft 365 to provide features that enhance hiring speed and efficiency these integrations increase the risk profile of ashby as a vendor, but provide significant benefits to your talent team ashby requests access to the emails and calendars of your team members involved in the hiring process and stores a subset of this data to provide a fast and reliable user experience our database is encrypted at rest, logically separated by organization, and behind a virtual private cloud (vpc) ashby encrypts all data transmitted between your it systems, ashby's servers, and ashby's clients in transit for more information, read our security overview https //www ashbyhq com/resources/security this article covers the access ashby requests for each platform integration, the controls in place to protect sensitive data, and the lower privilege configuration options available to your it or security team for information on google sign in, microsoft sign in, and single sign on, see signing in to ashby docid\ vh7b6oap3cirsfehtcyoa and sso and scim docid\ xjhagvxjeduakq cn6eue benefits of access (with examples) this section explains the benefits ashby provides for the access it requests without this access, the functionality described is not available email sync when ashby can send email through your email provider (e g , gmail), your talent team and hiring managers can send emails using predefined templates in ashby this creates a consistent candidate experience, from standardizing rejection explanations to how offers are made send emails on behalf of another user for instance, this can be used to automatically email a candidate from the hiring manager or recruiter upon moving them to a certain stage when ashby can read emails through your email provider, your talent team and hiring managers can send sequences of emails to attract passive candidates the sequence is paused when the candidate replies; this requires reading the email of the sequence sender most talent teams make a significant percentage of hires from passive candidates display communication with a candidate on the candidate's profile this allows a hiring team to coordinate communication (e g , not repeat things already shared with the candidate, make sure the hiring team reaches out to congratulate the candidate on their offer) and not have to transcribe notes from their email communication (e g , determine what links or information were already shared with the candidate) scheduling your talent team needs to schedule interviews in ashby to request and capture interviewer feedback when ashby can create calendar events, your talent team can schedule interviews in ashby without copying that information to your calendar provider (e g , google calendar) when ashby can read the calendars of interviewers and their calendar events, it allows your talent team to schedule with a more efficient interface manually and even automate scheduling with candidate booking links, candidates can pick an interview time convenient for them based on the availability of potential interviewers this saves your talent team the back and forth of requesting availability and cross referencing it with interviewers' calendars specific event titles can be considered free or soft conflicts with our scheduling keywords feature this saves your talent team from contacting the meeting owner to determine if a meeting can be overbooked for instance, most organizations consider one on ones (e g , using the keywords "1 1" or "1 1") to be easily reschedulable and consequently a free or soft conflict for scheduling interviews in some cases, your team needs to schedule a candidate manually ashby provides a more efficient interface than calendar clients to cross reference multiple calendars, the candidate's availability, and consider recruiting specific information like interviewer load ashby can only integrate with one platform integration at a time see does ashby support integrating with both google and microsoft at the same time? docid 92txkuc2vvmorzxeptmkj for more details select the links below for more information on the platform integration you plan to use integration options for google workspace and microsoft 365 docid\ va3yotx41ykdvfb8o0 3 microsoft 365 docid\ va3yotx41ykdvfb8o0 3 google workspace platform integration this section details the google workspace integration that powers email and calendar sync functionality it does not include ashby's google sign in or sso/scim integrations see google workspace docid 9nushnd uiv8wigz ypam for more details about setting up the email and scheduling integration what does it do? ashby integrates with google workspace to enable key features like displaying your conversations with candidates in the candidate profile feed and scheduling interviews directly in ashby the integration supports the following user sync google workspace users to automatically provision/de provision them as ashby users email sync emails between candidates and users (based on inspecting to/from headers) send emails and email sequences from within ashby scheduling sync employee calendars send event invites sync meeting rooms none of these options are required, but all are recommended for the best user experience with ashby what access controls are in place? ashby understands that email and calendar data are very sensitive, and puts access controls in place to only show data that is relevant to the hiring process ashby also applies a strict permission system where users are granted access to jobs and candidate records on a need to know basis (see "access control" below) default user access is very limited and does not include access to any candidate or job data employees cannot view their own candidate profile (their candidate profile must be linked to their employee profile in ashby to prevent this) ashby also supports truly confidential jobs that only the creator and those they give access to can see email ashby syncs and displays email when relevant to the hiring process only emails from ashby users with an "elevated access" or "organization admin" role are synced, since these roles are assigned to employees involved in the hiring process from these users, ashby only stores emails sent from ashby or involving a candidate emails containing a to, cc, or bcc with the candidate's email and subsequent emails marked by the email provider as being in the email thread emails sent from ashby and subsequent emails marked by the email provider as being in the email thread if the candidate's domain matches your organization's auth domain, emails are not synced for that candidate if the candidate has two email addresses linked to their profile (one with the organization's auth domain and one without), emails including the email address without the organization's auth domain are still synced ashby provides additional controls within the application to mark emails as private and automatically mark emails during the offer stage as private viewing these emails requires an explicit access role in ashby hide emails when a candidate moves to offer and hired stages stop syncing emails related to a candidate after they are hired stop syncing emails related to a candidate considered for a confidential job calendars ashby syncs all accessible calendars and events on those calendars when visibility controls are enabled on calendars and calendar events, for instance, only showing a specific event as "free" or "busy" or marking an event as a private event, ashby respects such controls and does not display the event details during scheduling ashby supports shared calendars (e g , "interviews" calendar) personal calendars are still used to determine interviewer availability during scheduling what are the options for integrating? ashby currently supports domain wide delegation and individual user oauth ashby recommends using domain wide delegation, but also supports oauth for email and scheduling ashby also offers lower privilege alternatives to these integration options, which you can view below domain wide delegation using domain wide delegation, all users in your workspace are added to ashby, and ashby has the same permissions relative to all users (specifically, their emails and calendars) however, ashby does not sync email from limited access users, even if its permissions technically allow it to the permissions requested through domain wide delegation are permission requested google's description required for feature sync users see info about users on your domain automatically adding users to ashby if turned off, ashby users need to be added, removed, and modified (e g , name updates) manually by ashby admins even if domain wide calendar/email sync is enabled, only users who have logged in to ashby at least once are synced sync meetings rooms view calendar resources on your domain add meeting rooms to ashby scheduling if turned off, ashby users cannot see or view meeting room availability when scheduling read/write shared calendars see, edit, share, and permanently delete all the calendars you can access using google calendar view and edit events on all your calendars shared interview calendars in scheduling if turned off, ashby users cannot see calendars such as shared interview calendars or schedules on shared calendars read/write personal calendars see, edit, share, and permanently delete all the calendars you can access using google calendar view and edit events on all your calendars scheduling interviews through ashby if turned off, ashby users cannot see calendars of potential interviewers when scheduling nor schedule on personal calendars read email read all resources and their metadata; no write operations sequences (sourcing) and communications with candidates using a recruiter's email address if turned off, ashby users cannot see email correspondence; emails and sequences can only be sent from no reply\@ashbyhq com mailto\ no reply\@ashbyhq com this is still possible with oauth but to function properly needs all users corresponding with candidates to oauth as an alternative to disabling this, see limited email sync below send email send messages only no read or modify privileges on mailbox sequences (sourcing) and communications with candidates through ashby using a recruiter's email address if turned off, sequences, offer letters, and one off email cannot be sent from user emails, only no reply\@ashbyhq com mailto\ no reply\@ashbyhq com individual user oauth using oauth, each user can separately authorize ashby for a full list of scopes, provided below (in their personal settings https //app ashbyhq com/settings/personal info ) it is not possible for a given user to only allow some of the scopes; they can accept all or none here is the full list of requested scopes https //www googleapis com/auth/userinfo profile https //www googleapis com/auth/userinfo email https //www googleapis com/auth/gmail send https //www googleapis com/auth/gmail readonly https //www googleapis com/auth/calendar https //www googleapis com/auth/calendar readonly https //www googleapis com/auth/calendar events any users without oauth do not have their candidate communication synced with ashby, cannot send emails from ashby, and cannot be automatically scheduled through ashby the permissions available with oauth are, for a recruiter or member of the hiring team who accepts those scopes permission requested google's description required for feature read/write shared calendars see, edit, share, and permanently delete all the calendars you can access using google calendar view and edit events on all your calendars shared interview calendars in scheduling if turned off, ashby users cannot see calendars such as shared interview calendars nor schedule on shared calendars read/write personal calendars see, edit, share, and permanently delete all the calendars you can access using google calendar view and edit events on all your calendars scheduling interviews through ashby if turned off, ashby users cannot see calendars of potential interviewers when scheduling nor schedule on personal calendars (the interviewer has to also accept this in the case of individual oauth ) read email read all resources and their metadata; no write operations sequences (sourcing) and communications with candidates using a recruiter's email address if turned off, ashby users cannot see email correspondence; emails and sequences can only be sent from no reply\@ashbyhq com mailto\ no reply\@ashbyhq com to function properly, this needs all users corresponding with candidates to oauth as an alternative to disabling this, see limited email sync below send email send messages only no read or modify privileges on mailbox sequences (sourcing) and communications with candidates through ashby using a recruiter's email address if turned off, sequences, offer letters, and one off email cannot be sent from user emails, only no reply\@ashbyhq com mailto\ no reply\@ashbyhq com lower privilege alternatives for google workspace while ashby recommends the above integration methods, widely adopted even in sensitive industries like finance and health care, we understand that some security teams may have different risk assessments to address this, ashby offers alternatives with more restricted access, though these come with reduced functionality for your talent team for the full permission details of each integration option, see integration options for google workspace and microsoft 365 docid\ va3yotx41ykdvfb8o0 3 limited email sync for organizations using domain delegation, ashby offers a "limited email sync" option this syncs only email metadata, such as recipient, sender, blind carbon copy (bcc), and subject line, while excluding the email body as a result ashby no longer requires the https //www googleapis com/auth/gmail readonly scope the scope https //www googleapis com/auth/gmail metadata can be used instead ashby cannot reference email content functionality impact email sequences continue to work, as ashby can detect candidate replies however, the talent team needs to contact users directly to view the email body oauth a separate google workspace account for each hiring team member if you prefer not to provide access to internal employee accounts, you can create dedicated email accounts for hiring team members (e g , \[employee name]@\[secondary domain]) under a separate domain within your organization limitations team members must manage two inboxes their primary inbox and the separate hiring account internal calendar access is restricted, impacting ashby's automated and manual scheduling features workaround calendars can be manually shared with these accounts for partial visibility, but ongoing maintenance is required as new accounts or calendars are added sending emails without email read access if your organization wants to send emails from ashby without allowing ashby to read email contents, authorize these google scopes https //www googleapis com/auth/gmail send https //www googleapis com/auth/gmail settings basic the gmail send scope allows ashby to send messages the gmail settings basic scope allows ashby to verify which addresses the google account can send from this scope does not grant ashby access to read email contents do not grant the https //www googleapis com/auth/gmail readonly scope if your organization does not want ashby to read email contents this configuration supports sending email, but does not provide the email sync functionality that depends on reading email oauth a shared google workspace account alternatively, you can create a shared email/calendar account (e g , hiring@\[your domain]) for the talent team to use this account can be shared in ashby for sending emails and managing scheduling limitations candidate experience is compromised emails do not show the recruiter's name communication cannot be visually separated by role (e g , recruiter vs hiring manager) restricting access to interviewer calendars prevents the use of automated and manual scheduling features calendars can be shared with the shared account to enable partial visibility microsoft 365 platform integration this section details the microsoft 365 integration that powers email and calendar sync functionality it does not include ashby's microsoft sign in or sso/scim integrations see microsoft 365 docid eaaljgrtew uoxtk8i7 for more details about setting up the email and scheduling integration what does it do? ashby integrates with microsoft 365 to enable key features like displaying your conversations with candidates in the candidate profile feed and scheduling interviews directly in ashby the integration supports the following user sync microsoft users to automatically provision/de provision them as ashby users email sync emails between candidates and users (based on inspecting to/from headers) send emails and email sequences from within ashby scheduling sync employee calendars send event invites sync meeting rooms none of these options are required, but all are recommended for the best user experience with ashby what are the options for integrating? microsoft 365 can integrate with ashby in the following ways the full documentation on how the integration is set up is available at microsoft 365 docid eaaljgrtew uoxtk8i7 ashby's managed azure application (default and recommended for most teams) custom azure application ashby also offers lower privilege alternatives to these integration options, which you can view below custom azure application with a custom application, your team can fully configure a custom application and integrate it with ashby this option is recommended for teams who want full control over the access granted to ashby from the outset, and is required if their tenants are hosted in microsoft's government community cloud (gcc) see microsoft custom applications (gcc high) docid\ wlpeo48evoa15qd5ty q6 for more details authorization ashby uses a combination of application and delegated permissions to integrate with microsoft 365 application permissions allow an admin to grant access to resources on behalf of all users, while delegated permissions require every user to grant access individually application permissions requested when using ashby's managed azure application, ashby requests the following application permissions permission requested microsoft's description required for feature user read all "allows the app to read user profiles" automatically adding users to ashby if turned off, ashby users need to be added, removed, and modified (e g , name updates) manually by ashby admins even if domain wide calendar/email sync is enabled, only users who have logged in to ashby at least once are synced group readwrite all "allows the app to read group properties and memberships, and read conversations for all groups" shared interview calendars in scheduling if turned off, ashby users cannot see calendars such as shared interview calendars nor schedule on shared calendars mailboxsettings read "allows the app to read user's mailbox settings does not include permission to read \[or send] mail " employee timezone sync allows accurate timezone settings in scheduling mail send "allows the app to send mail" sequences (sourcing) and communications with candidates using a recruiter's email address if turned off, sequences, offer letters, and one off email cannot be sent from user emails, only no reply\@ashbyhq com mailto\ no reply\@ashbyhq com mail readwrite "allows the app to create, read, update, and delete mail does not include permission to send mail " sequences (sourcing) and communications with candidates using a recruiter's email address if turned off, ashby users cannot see email correspondence; emails and sequences can only be sent from no reply\@ashbyhq com mailto\ no reply\@ashbyhq com to function properly, this needs all users corresponding with candidates to oauth as an alternative to disabling this, see limited email sync below calendars readwrite "allows the app to create, read, update, and delete calendar events " does not include events on group calendars scheduling interviews through ashby if turned off, ashby users cannot see calendars of potential interviewers when scheduling nor schedule on personal calendars delegated (oauth) permissions requested when users individually authorize ashby for microsoft office 365, ashby requests delegated versions of the above application scopes, and depending on your intended calendar and video conferencing setup, a few additional scopes that microsoft does not make available as application scopes permission requested microsoft's description required for feature user read all "allows the app to read user profiles" automatically adding users to ashby if turned off, ashby users need to be added, removed, and modified (e g , name updates) manually by ashby admins even if domain wide calendar/email sync is enabled, only users who have logged in to ashby at least once are synced mailboxsettings read "allows the app to read user's mailbox settings does not include permission to read \[or send] mail " employee timezone sync allows accurate timezone settings in scheduling mail send "allows the app to send mail" sequences (sourcing) and communications with candidates using a recruiter's email address if turned off, sequences, offer letters, and one off email cannot be sent from user emails, only no reply\@ashbyhq com mailto\ no reply\@ashbyhq com mail readwrite "allows the app to create, read, update, and delete mail does not include permission to send mail " sequences (sourcing) and communications with candidates using a recruiter's email address if turned off, ashby users cannot see email correspondence; emails and sequences can only be sent from no reply\@ashbyhq com mailto\ no reply\@ashbyhq com to function properly, this needs all users corresponding with candidates to oauth as an alternative to disabling this, see limited email sync below calendars readwrite "allows the app to create, read, update, and delete calendar events " does not include events on group calendars scheduling interviews through ashby if turned off, ashby users cannot see calendars of potential interviewers when scheduling nor schedule on personal calendars (the interviewer has to also accept this in the case of individual oauth ) group readwrite all "also allows the app to read and write calendar, conversations, files, and other group content for all groups the user can access " shared interview calendars in scheduling if turned off, ashby users cannot schedule on shared calendars onlinemeetings readwrite "allows the app to read and create online meetings on your behalf " microsoft teams video links in meeting invites in scheduling if using microsoft teams meetings with your microsoft 365 account and this is turned off, ashby cannot automatically add meeting links to scheduled interviews details on microsoft 365 email access and metadata handling ashby's microsoft 365 integration enables organizations to sync user inboxes and calendar data for recruiting workflows such as candidate replies, sourcing sequences, and interview scheduling this section outlines what data ashby accesses, how it is processed, and what is stored when using the microsoft graph api with mail readwrite permissions summary of email processing when a user connects their microsoft 365 account in ashby, ashby registers change notifications (webhooks) for that user's inbox and sent items folders when a new or updated message is detected, ashby fetches the message using microsoft graph evaluates a defined set of metadata fields determines whether the message is relevant to an active candidate or job application (e g , by matching the sender or recipient to a known candidate email address) if the message is relevant, ashby retrieves and stores the full email body if not, ashby discards the message and does not persist it metadata fields accessed ashby uses the microsoft graph api's $select parameter to restrict the fields it accesses when evaluating a message these fields include bccrecipients ccrecipients conversationid conversationindex from id internetmessageheaders internetmessageid isdraft receiveddatetime replyto sender sentdatetime subject torecipients ashby uses these fields exclusively to determine whether the email should be associated with an active candidate record data that is stored ashby only stores the full content of an email if it determines the email is related to a candidate or sourcing activity otherwise, ashby evaluates the email in memory and discards it this selective access pattern ensures that ashby only persists recruiting relevant communications while operating within the broader constraints of microsoft's graph api (which does not offer more granular email scopes like google's metadata ) access scope ashby uses the mail readwrite permission scope as required by microsoft to access messages this permission enables reading, writing, updating, and deleting emails; however, ashby only uses it to read and associate relevant emails with candidate workflows and does not write or delete messages in user inboxes compliance notes ashby does not store or process non recruiting related emails ashby does not fetch the full email body unless the message is recruiting relevant this behavior applies across both standard microsoft 365 and gcc tenants lower privilege alternatives for microsoft 365 while ashby recommends the above integration methods, widely adopted even in sensitive industries like finance and health care, we understand that some security teams may have different risk assessments to address this, ashby offers alternatives with more restricted access, though these come with reduced functionality for your talent team for the full permission details of each integration option, see integration options for google workspace and microsoft 365 docid\ va3yotx41ykdvfb8o0 3 oauth a separate microsoft 365 account for each hiring team member if you prefer not to provide access to internal employee accounts, you can create dedicated email accounts for hiring team members (e g , \[employee name]@\[secondary domain]) under a separate domain within your organization limitations team members must manage two inboxes their primary inbox and the separate hiring account internal calendar access is restricted, impacting ashby's automated and manual scheduling features workaround calendars can be manually shared with these accounts for partial visibility, but ongoing maintenance is required as new accounts or calendars are added oauth a shared microsoft 365 account alternatively, you can create a shared email/calendar account (e g , hiring@\[your domain]) for the talent team to use this account can be shared in ashby for sending emails and managing scheduling limitations candidate experience is compromised emails do not show the recruiter's name communication cannot be visually separated by role (e g , recruiter vs hiring manager) restricting access to interviewer calendars prevents the use of automated and manual scheduling features