Home > Manage App Profiles > Create Custom Apps > Consent to Custom Apps > Consent to a Custom Google App
Export to PDFWhen you consent to a custom Google app, complete the following settings:
App profile name – Enter a name for the profile.
Admin account – Enter the name of the Admin account that has the required privileges/roles. Refer to the table below for the required privileges/roles that vary with different features. For additional details, refer to the Manage Admin Roles and Privileges section below.
| Service | Function/Module | Admin account permissions |
|---|---|---|
| Cloud Backup for Google Workspace | User services protection (including Gmail, Drive, Calendar, Contacts, and Chat) | Admin API privileges: Users > Read |
| Cloud Backup for Google Workspace | Shared drives protection | Admin console privileges: Drive and Docs > Settings |
| Cloud Backup for Google Workspace | Google Vault protection | Admin console privileges:Google Vault >View All MattersGoogle Vault >Manage ExportsGoogle Vault > Manage Holds |
| Cloud Backup for Google Workspace | Google Classroom protection | Super Admin |
| Cloud Backup for Google Workspace | Google Directory protection | Admin console privileges: Security Center > This user has full administrative rights for Security Center > Audit and Investigation > ViewAdmin API privileges:Groups > Create, Read, and UpdateUsers > Create, Read, and Update Custom Attributes |
| Fly | Gmail migration | Admin API privileges:Users > ReadGroups > ReadAdmin console privileges:Calendar > All Settings > Buildings and Resources > Room InsightsReportsMake changes to events permission to the calendar, or assign the Super Admin role to the Admin account. See more details in the Fly user guide. |
| Fly | Google Drive migration | Admin console privileges:Users > ReadDrive and Docs > SettingsReportsContent manager of shared drives See more details in the Fly user guide. |
| Insights | All features for Google Workspace | Super Admin |
| Opus | All features for Google Workspace | Super Admin, or the following privileges assigned to a custom role: Admin API privileges: Users > ReadDomain ManagementAdmin console privileges:Drive and Docs > SettingsReportsData Classification > Manage Labels |
Google service account – Enter the service account email address.
*Note: You can get the email address from the client_email value in the downloaded private key file. For details, refer to Create a Service Account.

Private key – Enter the private key.
*Note: Make sure the private key starts with -----BEGIN PRIVATE KEY----- prefix and ends with the \n-----END PRIVATE KEY-----\n suffix.
Refer to the instructions below to manage roles and privileges for an Admin account:
*Note: The user must have the Super Admin role to manage roles and privileges.
Go to the Google .
Click Manage in the Users section.
Click the user you want to assign the roles. The user details page appears.
In the Admin roles and privileges section, click the Expand (
) button.
If you want to assign a pre-built role such as Super Admin or User Management Admin to the account, toggle the switch to Assigned in the Assigned state column.

Click SAVE.
If you want to create a custom role with required privileges, click CREATE CUSTOM ROLE.
Click Create new role.

The Create role page appears. Enter a role name and click CONTINUE.

In the Select Privileges section, select required privileges by referring to the Admin account table above.
Click CONTINUE.
Click CREATE ROLE. The custom role is successfully created.
You can assign the custom role to the Admin account.