GONG_ACCESS_KEY, GONG_ACCESS_KEY_SECRET and GONG_BASE_URL) when setup is complete.
Scope of this integration today. ConfigView reads who has a Gong seat and whether their meetings, calls and emails are recorded, the permission profiles that decide who can download, export, share or delete call recordings, and Gong’s audit logs: sign-ins, user and admin activity, impersonation, who played which call, and every time a call shared outside the company was opened. ConfigView only reads. It never downloads recordings or transcripts, and never calls Gong’s AI features (which cost credits).
Step 1: Open the Gong page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/gong
Gong shows the key’s secret once, when you create it, so paste it straight into ConfigView instead of keeping it in a notes file.
Step 2: Create an API key in Gong
You need to be a Technical administrator in Gong. API keys are available on every Gong plan.- In Gong, click Admin center in the left sidebar
- On the Settings tab, click API under Ecosystem
- Copy the base URL shown on that page. It is your company’s own API host and looks like
https://us-12345.api.gong.io. Paste it intoGONG_BASE_URLin ConfigView - Click + Get API key
- Key name:
ConfigView - TTL (days): leave it empty so the key never expires. A key with a TTL stops working on that day without warning, and collection stops with it
- Trusted IPs: either leave it empty, or enter your ConfigView server’s public IP address. If you restrict the key and this server’s address is not on the list, Gong refuses every call with a 403
- Click Get API key. Gong shows an access key and an access key secret
- Paste the access key into
GONG_ACCESS_KEYand the secret intoGONG_ACCESS_KEY_SECRET, each on its own, and click the save icon
Step 3: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/gong, confirm the three credentials show as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check confirms the three secrets, reads one page of users, lists your workspaces, then reads the last hour of the sign-in log.
- 401. The access key or secret is wrong, the key was deleted or reached its TTL, or
GONG_BASE_URLis not your company’s API host. Copy the base URL from the API page again; create a new key if needed. - 403 on every call. The key has Trusted IPs set and this server’s address is not on the list. Add it in Admin center → Settings → API, or clear the list. Changes take up to five minutes.
- 429. Gong’s rate limit is spent for now. See Gong’s daily call limit below.
Data Tables
Once the scripts run, these tables are created in your database. Each includes arun_at column. Users, workspaces and permission tables keep only the newest run; the audit log keeps everything it has ever collected.
*_access columns say how much of the company each profile can see in that area: all, managers-team, report-to-them, own or none. capabilities holds every yes/no permission the profile grants, as JSON, including ones Gong adds later.
log_type is one of AccessLog (sign-ins), UserActivityLog (user and admin actions), UserCallPlay (someone played a call), ExternallySharedCallAccess (a call shared outside the company was opened) and ExternallySharedCallPlay (it was played). log_record holds the rest of the entry as JSON, because each type carries different fields.
impersonator_* is filled in when someone acted as the user, usually Gong support staff with access to your account. impersonator_company_id tells you whose company they belong to.
Things worth knowing
Run Audit Logs every day. Gong keeps the sign-in log (AccessLog) for 14 days only. If the collector is stopped for longer than that, the gap cannot be recovered. ConfigView reports a run that found such a gap with status gap in gong_audit_log_sync and emails the run’s notification address. The other four logs go back years, so they can catch up.
Gong’s daily call limit. Gong allows your whole company 10,000 API calls a day and 3 a second, shared with every other integration you run against Gong (CRM sync, BI exports). ConfigView keeps a normal daily run to a few hundred calls at most and caps each script; the audit log stops at 2,000 calls a run. Ask Gong support if you need the limit raised.
The first audit-log run is a backfill. It reads the full 14 days of sign-ins and the last 90 days of the other four logs, a day at a time. If that does not fit in one run’s call budget, it stops cleanly and the next run carries on from where it got to (gong_audit_log_sync.complete_through). Older history is not collected.
Gong gives log entries no id. ConfigView builds one (event_hash) from the entry’s type, time, user, impersonator and full contents, so re-reading the same hour never creates duplicates.
Avatars are not users. Gong staff who access your account appear as avatars. They are left out of gong_users; when they act as one of your users the audit log records them as the impersonator.
One permission profile per workspace. A user has one profile in each workspace they belong to. gong_permission_profile_users lists them per workspace, so a user in two workspaces appears twice.
What isn’t collected
- Call recordings, transcripts, call summaries and any AI output. ConfigView never calls Gong’s AI endpoints
- Emails, deal and CRM records
- Users’ phone numbers, extensions, personal meeting room links and recording-consent page links
- Call titles, comments and search terms that appear in audit log entries. Keys that hold content are removed from
log_recordbefore it is stored