Browse every Google Group and request access in one place
A searchable catalog of every group in your company, with a request form, an owner approval queue, and a full record of who got access and why.
Build me an app the whole company opens whenever someone needs access to something: a searchable catalog of every Google Group we have, with a request desk sitting behind it. Today the answer is to find the owner, email them and hope, so I want discovery and asking to happen in the same place, and I want IT to end up with a running access log as a side effect. Identify the signed in viewer by their work email address and use that everywhere the app needs to know who me is.
The landing view is the catalog. Load the full list of groups with List Groups under our customer, and back the search box with Search Groups so typing a name, an email or a word from a description runs a CEL query rather than filtering one stale page. Each row shows the group's display name, its email address, its description, its member count, and badges for restricted and for you are already in this. Give it sorting by name and by size, and filters for groups I am in, groups I can ask to join, and restricted groups.
Opening a group opens its page. Show the description, the owners and managers pulled from List Memberships by role, and the current member list from the same call, paginated and searchable. Above the member list, show the viewer's own standing with this group. Run Check Transitive Membership for the signed in viewer against the group, and when it comes back true but they are not a direct member, use Get Membership Graph to name the parent group that grants it and show a line like you already have this through engineering-all, replacing the Request Access button with a note explaining they do not need to ask. Also show how many members sit on email domains outside ours, since a group with outside members deserves a second look before anyone joins it.
A My Groups tab lists the groups the signed in viewer belongs to directly, from Search Direct Groups on their work email. Each row has a Leave button that resolves the membership with Lookup Membership and then calls Delete Membership. Leaving is the one thing a person can do without approval, so confirm it first, and warn them when they are an owner of the group they are about to leave. This tab is also where the viewer sees their own open requests, so they always know where things stand.
Request Access opens a short form: the group, a reason in the person's own words, and how long they need it, chosen from a week, a month, a quarter or permanent. Submitting stores the request in the app with the requester's name and email, the group, the reason, the requested duration, the timestamp and a status of pending.
The approval queue is a separate view that only group owners and the IT approvers named in settings can open. Everyone else does not see the tab at all. Each pending request is a card showing the requester, the group, the reason, the requested duration, how long it has been waiting, and the recommendation once one exists. Approve runs Create Membership to add the requester as a member. Decline closes the request and requires a short note that the requester can read. Both decisions stamp the approver and the time onto the record.
Create Membership and Delete Membership both return long running Operations, so never assume instant success. Put the affected row into a pending state as soon as the call is made, keep polling the operation until it reports done, then flip the row to added, removed or failed with the error message shown inline on that row. This applies to approvals in the queue and to Leave on the My Groups tab.
When a request is approved, post confirmations with Send a Message in Slack: one to the requester telling them they now have access and how long it was granted for, and one to the group owner recording that it was approved and by whom. Also post to the access channel named in settings so IT sees the flow without opening the app. Resolve direct message channels with Open a Conversation using the Slack member ids the app keeps in settings, and fall back to mentioning the person in the access channel when there is no id on file.
Every pending card gets a Check this request button that kicks off a background agent, and the whole point of it is that the approver decides in seconds instead of guessing. The agent pulls the group's current members with List Memberships, checks whether the requester already holds the access indirectly by running Check Transitive Membership and, when that comes back true, Get Membership Graph to name the path, and pulls the requester's existing groups with Search Direct Groups. From those groups it works out who the requester's teammates are by listing the members of the groups they already sit in, then checks how many of those teammates are already in the group being requested, because a request from someone whose whole team is already in is a routine one. It also counts members on email domains outside ours and calls that out as a risk note. It writes a short recommendation back onto the request card, three or four sentences plus a one line verdict such as looks routine, already has this access, or worth a closer look. The agent never approves or declines anything itself.
Every request, decision, reason, approver and timestamp stays in the app on an access log page, filterable by person, group, date and outcome, so IT has a running record of who asked for what and what happened without keeping a spreadsheet. Any group can be marked restricted by an IT approver from its group page, and a restricted group's requests always need an owner or IT sign off even when the group itself is open to join, with the badge showing in the catalog. Nothing in this app runs on a schedule, so surface time bound grants that have passed their end date in an Expiring section at the top of the queue, each with a Remove button that runs Delete Membership. Lapsed access then gets cleaned up the next time someone opens the app rather than quietly sticking around forever.
A settings page holds our company email domains, the list of IT approvers, the Slack channel for confirmations, the Slack member ids used for direct messages, and the access durations people can choose from in the request form.
What does this prompt do?
- Gives everyone a searchable catalog of your company's groups, each showing its description, its owners, who is already in it and whether you can already reach it through another group.
- Lets people ask for access in seconds with a reason and how long they need it, instead of emailing owners and waiting for someone to notice.
- Sends every request to an approval queue only group owners and IT can see, adds the person to the group once it is approved, and confirms it in Slack.
- Puts a Check this request button on every pending card so an assistant can look into it and write a short recommendation before anyone decides.
What do I need to use this?
- A Google Workspace account with permission to see your organization's groups and manage who is in them.
- A Slack workspace and the channel where access confirmations should land.
- The names of the people on your IT team who should see every request alongside the group owners.
- Your company email domains, so members from outside your company stand out in the catalog.
How can I customize it?
- Mark individual groups as restricted so they always need an owner's sign off, even when the group is otherwise open to join.
- Set the access lengths people can pick from, such as a week, a month, a quarter or permanent.
- Choose the Slack channel for confirmations and whether the requester, the group owner or both get a message.
- Decide who counts as an IT approver and can see every request rather than only the groups they own.
FAQs
Do people need admin rights to use this?
Can someone just add themselves to a group?
What does the Check this request button actually do?
Why does a new member show as pending for a moment?
What happens when someone only needed access for a month?
Related templates
Search creators for free, shortlist the best with your team, and spend an audit credit only when you decide someone is worth a closer look.
One screen showing invited, completed, and shortlisted counts for every open role, plus the stalled invites that have quietly gone nowhere.
Open one board each morning to see which of your facilities, suppliers and shipping lanes are sitting near trouble in the news right now.
Pick creators from your saved list and see their best and worst Instagram posts side by side, so your brief is built on what actually lands.
One screen where your hiring team watches every unscored candidate, reads the transcript alongside each answer, and scores and shortlists on the spot.
Drag every new company from your Harmonic saved searches through New, Tracking, Meeting and Passed, with a one click diligence brief on every card.
Stop chasing group owners for access.
Give the whole company one place to find the group they need, ask for it with a reason, and get a real answer the same day.