> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Activate SaaS Discovery

> Discover all SaaS applications used across your organization by activating SaaS Mapping via Google Workspace or the Primo Chrome Extension.

SaaS Discovery gives you a complete map of the applications used in your company — which apps, by which users, and with which identities. It helps you identify shadow IT, detect unused licences, and get full visibility into your SaaS stack.

Primo supports two discovery methods:

| Method               | Coverage                            | Requirements               |
| -------------------- | ----------------------------------- | -------------------------- |
| **Google Workspace** | Apps accessed via Google sign-in    | Google Workspace connected |
| **Chrome Extension** | All apps accessed with a work email | MDM deployed via Primo     |

<Info>
  SaaS Discovery via Microsoft Entra is not yet available.
</Info>

***

## Activate via Google Workspace

If Google Workspace is connected, SaaS Mapping is enabled automatically. Primo maps every application for which your Google Workspace is used as a sign-in provider.

1. Connect Google Workspace if you haven't already — see [Connect your email provider](/saas/get-started/connect-email-provider).
2. Go to **SaaS > Directory** to see discovered applications.

No additional configuration is required. Discovery runs continuously in the background.

**What is captured:**

* The list of SaaS apps accessed using Google sign-in with a work account
* The associated work identity (user email) for each app
* No message content, files, passwords, or browsing history

***

## Activate via Chrome extension

The Chrome Extension extends SaaS Discovery beyond Google sign-in to capture any SaaS application accessed with a work email address — regardless of the login method.

### Requirements

* MDM deployed via Primo (the extension is deployed via MDM profiles)
* Google Workspace connected (required for the SaaS Management subscription)
* An active SaaS Management subscription

### Deploy the Chrome extension

<Steps>
  <Step title="Go to MDM Profiles">
    In the Primo cockpit, navigate to **Devices > Profiles**.
  </Step>

  <Step title="Select the profile for your workforce">
    Choose the profile applied to the devices where you want to deploy the extension.
  </Step>

  <Step title="Enable the Chrome Extension">
    Open the **Chrome** card and activate the extension toggle.
  </Step>

  <Step title="Select target devices">
    Choose which device groups should receive the extension.
  </Step>

  <Step title="Save and deploy">
    The extension is pushed silently to targeted devices. Allow a few minutes for deployment.
  </Step>
</Steps>

### What the extension captures

* SaaS applications accessed with the professional email address
* The associated work identity for each app

**The extension does not capture:**

* Personal Chrome profiles or personal email activity
* Passwords, message content, or browsing unrelated to work
* Any activity outside the managed Chrome profile

### Verify discovery is working

1. Go to **SaaS > Directory** in the Primo cockpit.
2. Check that applications and identities appear for recent activity.
3. Use device group filters to review targeted rollouts.

***

## Troubleshoot SaaS Discovery

### No apps appear after activation

* Confirm Google Workspace is connected and the SaaS Management subscription is active.
* For the Chrome Extension, verify that the target devices are included in the profile and that the Chrome card is enabled.

### The extension isn't installing

* Check that the device is included in the targeted device group.
* Allow a few minutes for Chrome policy sync to complete.

### A user has multiple Chrome profiles

Only the managed Chrome profile you targeted is in scope. Ask the user to switch to their managed work profile.

***

## Related articles

* [Connect your email provider](/saas/get-started/connect-email-provider)
* [Add a SaaS from catalog](/saas/connect-apps)
* [Track a manual SaaS](/saas/manage-tracked-apps)
