Skip to main content
Pria integrates with Google Workspace to give your Digital Twin access to Gmail, Google Drive, Calendar, Sheets, Docs, Slides, Meet, Classroom, and Maps. Users can ask their Digital Twin to read emails, search files, create calendar events, and more — all within the conversation interface.

Available Services

What you can say:
  • “Show me my unread emails from this week”
  • “Search my inbox for messages from jane@example.com about the budget”
  • “Send an email to the team with a summary of today’s discussion”
  • “Find emails with attachments from the last 30 days”
  • “List my recent Google Meet recordings”
  • “Get the transcript from yesterday’s team meeting”

Authorization Models

Pria supports two authorization models that can be used independently or together.

Personal Authorization

Each user connects their own Google account through their Profile settings. They select which services to enable, authorize through Google’s consent screen, and the tokens are stored securely per-user.

Shared Authorization — one Google account for the whole Digital Twin

An administrator can connect one Google account for a whole Digital Twin. Everyone who uses that twin then reaches the connected Google services straight away, without each person having to sign in to Google and grant permission. Key use cases:
  • Departmental access — Share a department’s Google Drive, Gmail, or Calendar with all students and staff
  • Simplified onboarding — Users can access Google services immediately without going through OAuth consent
  • Centralized control — Administrators choose exactly which services are available
Where: the Digital Twin editor, Configuration and Integrations › Google Services:
  • Enable Access — turns Google services on for the twin’s members. While it is off, members are not offered Google tools, even with their own Google account connected. (A personal account with no Digital Twin doesn’t need it.)
  • Use Digital Twin identity — everyone uses the Google account connected to the twin. Leave it off to let each person connect their own account.
  • Service selection — with both switches on, choose which Google services the twin’s account covers, then connect it. Only the selected services are available through it; to change the selection later, Disconnect and connect again.
  • Conservative permissions by design — Drive, Sheets, Docs, Slides, Meet and Classroom are read-only; Gmail can also send email and Calendar can also create events, so grant those services deliberately on a shared account.

Authorization Priority

When both personal and shared credentials exist, Pria uses them in this order:
  1. Shared credentials (when an administrator has connected a Google account to the twin and turned on Use Digital Twin identity)
  2. Personal credentials (the user’s own Google account)
This means shared credentials take precedence for the services they cover. If an admin connects a shared Gmail, all users will use that shared Gmail rather than their personal one — even if they’ve also authorized their personal account.

Google Maps

Google Maps does not require OAuth authorization. It uses a server-side API key managed by the platform, so users can ask their Digital Twin for place search and geolocation without any personal authorization or setup.

Service Dependencies

Some Google services require parent services to function: When a user enables a dependent service, the parent service is automatically enabled as well.

Permissions Pria Asks Google For

Every connection asks for openid, profile and email, plus the scopes of the services selected (all under https://www.googleapis.com/auth/). Use this list when your Google Workspace administrator needs to approve the app. Google Maps uses no Google permission from the user.

Troubleshooting

During the OAuth consent screen, Google may display a warning that the application is not yet verified. This is expected — the Pria middleware is currently undergoing CASA Tier 2 compliance verification with Google. To proceed, click Advanced and then Go to [app name] (unsafe) to continue the authorization. This warning will be removed once verification is complete.
If a connected service starts failing after working initially, the stored refresh token may have been revoked or expired. Disconnect the service in Profile settings (or the admin panel, for a shared account) and reconnect it — the fresh consent flow issues a new refresh token.
  • Check that the Google connection is configured for the Digital Twin (or that users have connected their own accounts)
  • Verify the corresponding APIs are enabled in Google Cloud Console
  • In a Digital Twin, confirm Enable Access is on; for a shared account, also check the service was included when the account was connected

  • Google Services User Guide — End-user authorization and usage guide
  • Configuration — Digital Twin settings including Google OAuth
  • Tools — Tool definitions that power Google service interactions
  • IP Vault — Files downloaded from Google Drive are stored here