Skip to main content

Overview

Ocean can operate in two permission modes: Read-Only for threat monitoring and reporting, or Read/Write for active threat protection. This guide explains how to upgrade from read-only to read/write mode, enabling Ocean to automatically remediate detected threats by moving or deleting malicious emails.
A Google Workspace administrator account is required to grant the additional permissions.

What Changes with Read/Write Mode

Read-Only Mode

  • Ocean analyzes and reports on threats
  • No emails are moved, deleted, or labeled
  • Full visibility into threat landscape
  • Your team manually handles remediation

Read/Write Mode

  • Automatic threat remediation based on configured policies
  • Malicious emails can be moved to trash or quarantine

Remediation Actions

With read/write permissions, Ocean can perform the following actions based on your configured policies:
ActionDescription
Move to TrashMoves the email to the user’s Trash folder
DeletePermanently removes the email from the user’s mailbox
Do NothingLogs the threat but takes no action (useful for monitoring)
Remediation actions are configurable per threat type (malicious, spam) and can be customized to match your organization’s security policies.

Upgrade Steps

1

Access Integration Settings

In the Ocean portal, navigate to SettingsIntegrations. Locate your Google Workspace integration and click Edit.
2

Select Read & Write Permissions

In the integration wizard, change the permission level from Read to Read & Write.
Select Read & Write permissions
3

Update Domain-wide Delegation

  1. Navigate to the Google Workspace Admin Console
  2. Go to SecurityAPI ControlsDomain-wide Delegation
  3. Find Ocean’s Client ID in the list
  4. Click Edit and update the OAuth scopes with the new scopes provided in the wizard
Update domain-wide delegation
Copy the complete list of OAuth scopes from the Ocean integration wizard. The new scopes include write permissions in addition to the existing read permissions.
4

Save Changes

Once the domain-wide delegation settings are updated, click Save to initiate the permission upgrade
5

Upgrade Complete

Your integration is upgraded to Read/Write mode. Ocean will now actively protect your organization based on your configured remediation policies.

Additional Permissions Required

When upgrading to Read/Write mode, Ocean requests the following additional Google Workspace OAuth scopes:

Gmail Management

Scope: https://www.googleapis.com/auth/gmail.modifyWhat it does: Enables the application to read, send, delete, and manage labels on emails in all mailboxes.Why it’s needed: Allows Ocean to move malicious emails to trash, apply warning labels, and manage email organization as part of automated remediation.
Scope: https://www.googleapis.com/auth/gmail.insertWhat it does: Enables the application to insert messages into users’ mailboxes.Why it’s needed: Allows Ocean to restore quarantined emails back to user mailboxes when released by administrators.
Scope: https://mail.google.com/What it does: Enables full access to Gmail, including reading, composing, sending, and permanently deleting emails.Why it’s needed: Provides comprehensive access for threat remediation actions, including the ability to permanently delete confirmed malicious emails when configured.

Complete OAuth Scopes Summary

Below is the complete list of OAuth scopes for Read/Write mode (includes all read-only scopes plus the additional write scopes):

Read Scopes (base permissions)

https://www.googleapis.com/auth/admin.directory.user.readonly
https://www.googleapis.com/auth/gmail.readonly
https://www.googleapis.com/auth/admin.reports.usage.readonly
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/apps.alerts
https://www.googleapis.com/auth/admin.directory.customer.readonly
https://www.googleapis.com/auth/admin.directory.domain.readonly
https://www.googleapis.com/auth/admin.directory.group.readonly
https://www.googleapis.com/auth/admin.directory.orgunit.readonly
https://www.googleapis.com/auth/contacts.readonly

Additional Write Scopes

https://www.googleapis.com/auth/gmail.modify
https://www.googleapis.com/auth/gmail.insert
https://mail.google.com/

Configuring Remediation Policies

After upgrading to Read/Write mode, you can configure remediation policies in the Ocean portal:
  1. Navigate to SettingsPolicies
  2. Configure actions for each threat category:
    • Malicious emails: Recommended action is Move to Quarantine
    • Spam emails: Recommended action is Move to Trash
  3. Save your policy configuration
We recommend starting with Move to Quarantine for malicious emails, which allows administrators to review and restore emails if needed before they are permanently deleted.

Frequently Asked Questions

No, the upgrade only affects how Ocean handles new threats going forward. Existing emails in user mailboxes are not modified during the upgrade process.
Navigate to the Google Workspace Admin Console, go to Security → API Controls → Domain-wide Delegation, find Ocean’s Client ID, and update the OAuth scopes with the new list from the Ocean integration wizard.
Emails moved to Trash can be restored by users within 30 days. Permanently deleted emails cannot be recovered. We recommend using Move to Trash as the default action to allow for recovery if needed.
Email delivery continues normally even if Ocean services are temporarily unavailable. However, automatic remediation will be paused until services are restored. Threats detected during the outage will be remediated once connectivity is restored.
You can downgrade back to read-only mode by updating the domain-wide delegation in Google Workspace Admin Console, removing the write scopes from Ocean’s Client ID entry.
Ocean is designed to complement existing email security infrastructure. It operates as an additional layer of protection and does not interfere with other security tools like Google’s built-in spam filters or third-party security solutions.

Need Help?

If you encounter any issues during the upgrade process or need assistance configuring remediation policies, contact your Ocean account executive for support.