Integrations
What to set up at the provider first
Organization install starts in the provider console, not in Telara. Complete the steps below, then paste the values into Install for the whole organization.
How it works
One admin action, per-user data
An admin connects once for the whole organization. Each person's requests still run under their own provider identity — Drive, Gmail, OneDrive, and the rest return only that person's data. Telara never reimplements the provider's ACLs.
The install alone can mint a token for any user. Nobody else signs in. Google Workspace, Box, Dropbox Business.
Admin consent removes the approval screen. Each person still completes one silent sign-in the first time. Microsoft 365 / Entra, Slack, Atlassian.
Google Workspace
Domain-wide delegation
Prefer a service account in your own GCP project for early installs — it stays internal to your organization and avoids Google's OAuth verification queue. The Marketplace listing and workload identity federation paths are also supported in the product form when you want no key stored in Telara.
Create a project and enable APIs
Create a service account and download a key
Copy the numeric Client ID
Register domain-wide delegation
unauthorized_client.Hand the values into Telara
delegated_subject — Telara derives the caller per request.Marketplace domain install and workload identity federation skip pasting a private key but still need the domain and the scopes the install is allowed to use. Use whichever method the product form offers for your tenant.
Microsoft 365 / Entra
App registration + admin consent
Entra has no domain-wide delegation equivalent. Use delegated permissions with admin consent so tokens stay per-user. Do not use application permissions that read every mailbox as one app identity.
Register an app
Create a client secret
Add delegated Graph permissions
User.Read, Files.Read, Mail.Read, offline_access), then Grant admin consent for your tenant.Hand the values into Telara
Verify
Confirm per-user scoping
After the install is recorded, have two different people run the same tool call. Each should see only their own data. If both see the same data, stop and escalate — that is the failure mode this design exists to prevent.

