Skip to main content

After this article…

You’ll be able to connect Gong to Lumos to sync Gong users and their permission profiles (groups), with last-activity data for visibility and Access Reviews.

Capabilities

Activity tracking is supported. Lumos tracks each user’s last activity, excluding logins and views, by parsing Gong audit logs for the past 6 months.

Required plan & roles

  • Lumos plan: no minimum plan requirement is documented for this integration.
  • Gong role: the connecting user needs the Technical Administrator role in Gong, and API access must be enabled in Gong settings.
  • Gong configuration: SCIM provisioning must be enabled in your Gong settings. Lumos reads users and groups through Gong’s SCIM API, and Gong returns an error on those endpoints when SCIM provisioning is disabled.
  • OAuth scopes (Gong connects through OAuth, all read-only):
    • api:provisioning:read: read users and groups through the SCIM protocol
    • api:workspaces:read: list all workspaces
    • api:users:read: read user data (ID, name, phone number)
    • api:logs:read: read audit logs for last-activity tracking
    • api:permission-profile:read: read permission profiles
  • Permission scoping: this is a read-only integration. Lumos syncs users and groups but doesn’t provision or deprovision anything in Gong.

Read-only access vs provisioning

Is read-only possible? Yes, and it’s the only mode Gong supports here. All of the OAuth scopes Lumos requests (api:provisioning:read, api:workspaces:read, api:users:read, api:logs:read, api:permission-profile:read) are read-only, and Lumos syncs users and groups without provisioning or deprovisioning anything in Gong. What read-only requires. A Gong user with the Technical Administrator role, API access enabled in Gong settings, and SCIM provisioning enabled in Gong settings (Gong’s SCIM API is what Lumos reads users and groups through, despite the name). Then complete the OAuth authorization in the steps below. Watch out for. Despite the setting’s name, “SCIM provisioning” in Gong must be enabled for the Lumos read-only sync to work at all. Gong returns an error on the SCIM endpoints if it’s disabled, which can look like a Lumos-side problem. Activity tracking only covers the past 6 months of audit logs and excludes logins and views.

Instructions

Phase 1: Get your API Base URL in Gong
  1. In the Gong UI, go to Company settings → API → API Keys and copy the Base URL assigned to your account (for example https://us-40132.api.gong.io).
Phase 2: Connect in Lumos
  1. Click the Gong card in your Lumos integrations. Reconnect an existing card or add a new one.
  2. Enter the API Base URL, including the https:// protocol.
  3. Click Connect.
  4. Follow the instructions in the pop-up to complete the OAuth authorization.

API Endpoints Used

Troubleshooting

401 Unauthorized. Verify the OAuth authorization is still active, that API access is enabled in Gong settings, and that the OAuth application hasn’t been revoked in Gong. 403 Forbidden. Verify the connecting user has the Technical Administrator role, that the OAuth application was granted all required scopes, and that the Gong account can access all resources. “Provisioning users using SCIM is disabled for your company” (400). Lumos reads users and groups through Gong’s SCIM endpoints. Enable SCIM provisioning in your Gong settings and retry. This is a Gong-side configuration requirement, not a Lumos error. 429 rate-limit errors (“Access key API calls limit exceeded”). The connector throttles requests to stay within Gong’s access-key API limits. Transient 429s during large syncs resolve on retry. Users aren’t syncing. Verify the users have active, fully onboarded Gong accounts and that email addresses match between systems. Workspaces are missing. Verify the workspaces are active in Gong, that the api:workspaces:read scope was granted, and that each workspace has at least one member.