Sayl Mail · Admin console
Migrate Google Workspace to Sayl Mail
Move mail in from Gmail without asking every user to export anything by hand. One mailbox through a consent screen, or a whole domain — 20, 50, 200 mailboxes — through one CSV upload and no per-user sign-in at all.
Pick the path that matches the job
Both read Gmail over the same official API, with the same minimal scope. The difference is who signs in, and how many mailboxes move in one run.
Single-account OAuth
The mailbox owner clicks New migration, signs into their own Google account, and approves read-only Gmail access on Google’s own consent screen. Best for one mailbox, or testing before a larger run.
Bulk, by domain-wide delegation
A Google service account, authorized once by the Workspace super admin, reads every mailbox named in a CSV. No consent screen per user. This guide is mostly this path.
1Create a Google service account
Done once, in the Google Cloud project your Workspace domain uses.
- 1Open Google Cloud Console → Service Accounts and sign in with an account that can manage the project.
- 2Pick an existing project, or create one.
- 3Create service account → give it a name. Don’t grant it any IAM roles — it needs none for this.
- 4Open the new service account → Keys → Add key → Create new key → JSON. The file downloads once. Store it somewhere secure — never in chat or email.
- 5Copy its numeric Client ID (labelled “Unique ID” on the same page). This is what Workspace authorizes next — not the service account’s email address, and not the JSON file itself.
- 6Enable the Gmail API on the same project, if it isn’t already.
2Authorize domain-wide delegation
Done once, by the Workspace super admin — a different role from whoever manages the Cloud project above.
- 1Open Google Admin Console → Domain-wide delegation.
- 2Add new → paste the numeric Client ID from step 1.
- 3Under OAuth scopes, enter exactly this and nothing else:
https://www.googleapis.com/auth/gmail.readonly - 4Authorize, then confirm the Client ID and scope appear in the list.
gmail.readonly is the minimum this needs. It lets the service account read any Workspace user’s mail during the migration window — it cannot send, delete, or touch Drive, Calendar, Contacts or Admin settings.
3Connect the service account in Sayl
- 1Open admin.sayl.in/migrations.
- 2Find the “Google service account (bulk migrations)” card → Configure.
- 3Upload the JSON key from step 1.
- 4Enter one real Workspace mailbox as the verification address — Sayl uses it once to prove delegation actually works before saving anything.
- 5Save & verify. The card’s badge flips to Configured.
The private key is encrypted at rest. No screen or API response ever shows it again — only the non-secret service account email and project ID are displayed afterward.
4Prepare the destination mailboxes
Sayl never creates a mailbox on its own during a migration — an auto-provisioned account would need a generated password and a forced reset, which is more attack surface than this feature should add. Every destination mailbox has to exist before its row can be included.
- 1Decide the target domain under your Sayl tenant.
- 2Under Mailboxes, create one per Workspace user, ideally with the same local part as their Workspace address (
priya@yourworkspace.com→priya@yourdomain.com). Matching local parts let the next step auto-match every row with no extra column.
5Build the migration CSV
Two columns. Only the first is required.
- source_email
- Required. The Workspace mailbox to read from.
- target_mailbox
- Optional. Overrides the auto-suggested local-part match.
source_email,target_mailbox
priya@yourworkspace.com,
arjun@yourworkspace.com,
meera@yourworkspace.com,sales@yourdomain.com6Run and monitor the batch
- 1Migrations → New bulk migration → pick the tenant and target domain → upload the CSV.
- 2Review the validated table. Every row gets a status — Ready, No mailbox yet, Invalid email, or Duplicate. Edit a cell and click Re-check edited rows to re-validate without re-uploading.
- 3Tick the rows to include and click Start migrating. No consent screen appears — the batch starts immediately, one job per mailbox.
- 4The dashboard that opens polls every few seconds: discovered, imported, skipped and failed counts, summed across the batch, plus a per-user table. Pause all and Resume all control every unfinished job together; Retry failed resets only the messages that failed, never re-importing what already succeeded.
A mailbox whose included folders total more than 500 messages won’t start importing unless a platform backup from the last 48 hours has been proven restorable. It lands in a review state instead of starting, so nothing large moves without a safety net underneath it.
What this does not do
Real constraints, stated here rather than found after a batch has started.
- Only mail moves. Drive, Calendar and Contacts do not. The scope is gmail.readonly, deliberately the narrowest grant that can read a mailbox — a broader grant would ask your Workspace super admin to authorize far more than a mail migration needs.
- A destination mailbox is never created automatically. A row whose target mailbox doesn't exist yet is excluded, not provisioned. Auto-creating one would mean generating a password nobody chose.
- A batch needs the service account; a single migration doesn't. The single-account path signs the mailbox owner in directly. Domain-wide delegation is only for the bulk path, and only a Workspace super admin can authorize it.
- Very large mailboxes can be gated behind a backup check. Above 500 included messages, Sayl requires a recent, restore-tested platform backup before that mailbox starts importing — a deliberate pause, not a failure.
Questions
- How do I migrate Google Workspace to Sayl Mail?
- Create a Google service account, authorize it for domain-wide delegation with the gmail.readonly scope, upload its key in Sayl's Migrations screen, then upload a CSV of the mailboxes to migrate. For a single mailbox, skip the service account entirely and use the OAuth consent screen instead.
- Do my Workspace users need to approve anything?
- Not for a bulk migration — domain-wide delegation removes the per-user consent screen entirely. The single-account path does need the mailbox owner to sign in and approve read-only access once.
- How many mailboxes can I migrate in one batch?
- There's no fixed cap in the product. The practical limit is how many destination mailboxes you've created and how large each source mailbox is — a batch of 20 to 50 runs the same way as a batch of 200.
- Does this migrate Google Drive, Calendar or Contacts?
- No. The scope requested is gmail.readonly only, which covers mail alone. Drive, Calendar and Contacts need a separate export.
- What happens if some messages fail to import?
- They're marked failed with a specific reason, visible per user and in a downloadable combined report. Retry failed resets only those messages and re-imports them without touching anything that already succeeded.
- Is the migration read-only on the Google side?
- Yes. The gmail.readonly scope cannot send, delete or modify anything in the source mailbox — it only reads messages to copy them into Sayl Mail.
