Connecting a Google Workspace lets Cockpit read employees' calendars to switch their status to Meeting automatically, and write their approved absences onto a calendar of their own. One administrator authorizes it once for the whole company.
What it does
Two features, both optional and both switchable per employee:
| Meeting status | While a meeting is running, the employee's Tempus status changes to your chosen meeting status, and reverts to what it was when the meeting ends. |
| Absence events | When an absence is approved it appears on the employee's calendar. Cancel the absence and the event is removed. |
Both require Tempus to be active for the PBX. Neither does anything until you switch them on.
Before you start
You need a Google Workspace super administrator — not just any admin. Individual employees do not have to approve anything, and will never see a consent prompt.
Setting it up
1. Create the integration
Go to Integrations → Add integration and choose Google Workspace. Save it. The edit page then shows everything the customer's administrator needs.
2. Give the administrator two values
The edit page displays, each with a copy button:
- a Client ID — a long number identifying Cockpit's service account
- a scope list — the exact permissions being requested
Both must be pasted exactly as shown. The scope list in particular must be complete; a partial list makes the authorization fail with an error that does not say which scope is missing.
3. The administrator authorizes Cockpit
In the Google Admin console: Security → Access and data control → API controls → Domain-wide delegation → Add new, then paste the Client ID and the scopes.
Google can take a few minutes to apply a new authorization.
4. Fill in the two fields and verify
| Field | What to enter |
|---|---|
| Workspace domains | Every domain your employees' email addresses use, one row each. Include secondary domains: a person at name@subsidiary.com will not be touched unless subsidiary.com is listed. |
| Test user | Any real Workspace account in one of those domains. Cockpit reads its calendar once to prove the authorization works; it does not have to be an administrator. |
Press Verify connection. On success the integration can be activated; until then the Enable Google Workspace integration switch stays disabled.
A Workspace domain can only belong to one PBX. This is a safety rule: the authorization is granted to Cockpit as a whole, so the domain list is what stops one customer's Cockpit reaching another's calendars.
5. Link the employees
Cockpit matches employees to their Google address by email. Addresses that do not match can be linked by hand, and each employee can be switched off individually or opted out of a single feature: the meeting status, absence events, and contact sync each have their own switch.
Where absence events are written
You choose this per company, on the integration page:
-
A separate calendar the employee can hide (recommended) - Cockpit creates a calendar in the employee's own Google account — named Cockpit Calendar unless you rename it — and writes there. The employee can hide it with one click, and nothing Cockpit writes ever touches their personal calendar.
- Trade-off: these appear as ordinary busy entries. Google reserves genuine "out of office" events for the main calendar, so there is no out-of-office badge and invitations are not declined automatically. Colleagues checking the employee's availability also will not see the absence, because Google reads only the main calendar for that.
-
Directly on the employee's main calendar - Real out-of-office behavior: the badge, automatic declining, and visibility to colleagues checking availability.
- Trade-off: the employee cannot hide these, since they sit among their own events.
The event is titled after the kind of absence and the days it covers, for example Sick Leave (Sep 8, 2026), and a note on the absence becomes the event body. Because the title names the category, anyone the employee has granted "see all event details" on that calendar can read that a day off was sick leave. A whole day off is written as an all-day event; a part day carries its clock times.
A published Tempus schedule writes each shift to the same calendar too, titled Shift with the schedule's name. It has no per-employee switch of its own.
What Cockpit does and does not read
The employee's primary calendar always. A secondary calendar they own, or a shared team calendar, is read only where an administrator has ticked it under Extra calendars on their user record, up to five.
Beyond that, only what it needs, and the privacy rules are deliberate:
- A meeting marked private, personal or confidential is never recorded at all — its title never reaches Cockpit's database, rather than being stored and hidden.
- A meeting shown as free, an all-day block, a canceled meeting, one the employee declined, and anything longer than 12 hours are all ignored.
- Only a meeting the employee is actually busy or tentatively booked for can change their status.
Cockpit only ever deletes or edits events it created itself, identified by a record it keeps at the moment of creation. A real meeting cannot be touched.
Turning it off
| One employee | Switch them off in the user mappings table, or opt them out of just one feature. Unlinking them, or switching their contacts off, also takes the contacts Cockpit wrote back out of their account. Events already on a calendar stay. |
| One company | Deactivate the integration, or delete it. Either stops every sync at once and leaves what is already in Google in place, with no cleanup afterwards: to reclaim the contact copies, unlink the employees first, while the integration is still on. |
| The authorization | The administrator removes Cockpit's client ID in the Google Admin console. Deactivating in Cockpit does not withdraw the grant. Cockpit re-checks weekly and deactivates an integration whose grant is gone. |
If something is not working
-
"Google refused the authorization." - The Client ID or the scope list was not pasted exactly, or Google has not applied the change yet. Re-check both values against the edit page and try again in a few minutes.
-
"Google does not recognize that mailbox." - The verification mailbox does not exist in this Workspace. Check for a typo, or use a different real address.
-
"That mailbox is not in one of the allowed Workspace domains." - Add the domain to the allowed list first. This also catches the common case of an employee on a secondary domain.
-
Verification passes but nothing syncs. - Check that the employee is linked in the mappings table and switched on, that Tempus is active for the PBX, and that the meeting status feature is enabled in Tempus → Settings → Meeting status.
-
Messages mentioning our service account or the Calendar API. - These are on Voxbi's side rather than yours. Contact support.