GEM
GEM gives MSPs and IT admins one Google-verified console to manage Google Workspace across every client — identity lifecycle, onboarding, license reclamation, and cleanup automation. Run it fully managed as GEM Cloud, or self-host the open-source core.
Inventory every user across every environment. Suspend, archive, offboard with Drive handoff, and move between OUs and groups — individually or in bulk.
Provision new hires from reusable templates: account, OU, groups, licenses, and a branded welcome email. Single, bulk CSV, or scheduled for a start date.
Find inactive accounts still burning licenses, reclaim them safely, and see assigned licenses per environment at a glance.
Activity-driven hygiene: an assisted daily review queue, and opt-in automation that suspends or archives accounts inactive past your thresholds.
Assemble dashboard sections into a PDF carrying your brand — or your client's — for QBRs and handoffs.
Per-environment least-privilege OAuth. No domain-wide delegation, no impersonation. Credentials encrypted at rest, mandatory MFA, full audit log.
Each environment's super-admin grants GEM a single, revocable OAuth consent — no domain-wide delegation, no service-account keys to manage. GEM requests only sensitive (not restricted) scopes: the Admin SDK (Directory, Reports, Data Transfer) and the Enterprise License Manager API. GEM never reads Gmail or Drive content. Disconnecting an environment revokes the grant at Google. The full scope-by-scope explanation ships with the source.
GEM Cloud (managed). The fastest way to get started: a dedicated, isolated instance run for you — your own database and encryption keys, in the region you choose — with Google-verified OAuth, automatic upgrades, and encrypted offsite backups. Free during early access.
Self-hosted (open source, AGPL-3.0). Prefer to run it yourself? One
docker compose up on your own infrastructure — you hold the keys, and your data
never touches ours. Request source access.
GEM Cloud is in free early access. Request access — we review each request and email your setup link once your instance is ready. Questions? Discord or [email protected].