Read Workspace users and groups, then change membership as an approved step
Connect the Google Admin Console and Luumen can answer questions about your Workspace directory directly in the terminal: who a user is, which groups exist, who belongs to them. When a change is needed — a new account, a group membership, a suspension — Luumen shows the exact call first and waits for your approval before it runs.
14 tools: 5 read, 9 write. Reads answer instantly. Writes require approval by default. Everything is logged.
What a governed Google Admin run looks like inside Luumen.
Authorize once with OAuth 2.0. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Read actions answer immediately. Anything that writes — add alias to google workspace user, add user to google workspace group, create google workspace group, create google workspace user, and more — is shown as a plan and requires approval by default, including the 3 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Every call to Google Admin — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.
Connect in minutes. Every action scoped, approved, and audited from day one.