The Google Workspace SaaS connector uses the OAuth 2.0 protocol for authentication and authorization of the Google Workspace APIs. It supports the following OAuth 2.0 scenarios:
For overall visibility it’s good to list which scopes are required for which operation so users can pick and choose but I’d propose keeping a single list of required scopes for full basic functionality + scopes required for CIEM.