Before you install

One Windows machine. That's the infrastructure.

ORINEX Workspace installs on a server or workstation you already have and talks to Google through GAM. There is no ORINEX-hosted application server and no additional infrastructure for you to provision.

1Machine to install on
0Servers for us to provision
4 GBRAM to get started
6Google domains to allow
The short list

Three things. If you have all three, you can run it today.

A Windows machine

Windows 10 (64-bit) or later, or Windows Server 2016 or later. A workstation is fine to start; a server is better once more than one administrator needs access.

GAM, installed and authorized

ORINEX Workspace reaches Google through GAM, using your own OAuth credentials and service account. GAM is installed separately and set up once.

Super Admin on the domain

Delegated admin roles do not carry enough API access for most operations. The account you authorize GAM with needs Super Admin.

Plus outbound HTTPS to Google's APIs. No inbound firewall rule for a workstation install, and no VPN or tunnel back to us — details further down.

What you get on it

One Windows machine. Everyone else just opens a browser.

Each ORINEX installation runs on a single Windows server or workstation your district controls. That is the only machine with a platform requirement. Your administrators reach it the way they reach any internal web application — from whatever they already work on.

  • The install: Windows 10 (64-bit) or later, or Windows Server 2016 or later. The application depends on Windows service and system-tray integration, so macOS and Linux cannot host it.
  • The people using it: any operating system. A director on a MacBook, a technician on a Chromebook, and a specialist on Linux all sign in to the same interface with nothing installed on their machine.
  • Runs as a background service with a tray icon, not a window someone has to keep open.
  • Served over HTTPS from the machine it runs on, so it stays inside your network unless you publish it deliberately.
ORINEX Workspace dashboard — user, device, group and storage totals with attention-needed and security alert cards
Hardware

What to give it.

Resource Floor Comfortable
CPU2 cores
RAM4 GB system memory
Disk2 GB free, plus GAM

These are floors. The one thing that genuinely scales is the audit history ORINEX keeps locally: budget 2 GB plus about 500 MB per 1,000 users — roughly 7 GB at 10,000 students, 17 GB at 30,000. That figure is deliberately generous.

Running a large district? Tell us your enrollment and we will size it with you before you provision anything.

Google Workspace

Which editions work.

Edition Support
Education — all tiers
Business Standard / Plus
Enterprise Standard / Plus
Business Starter

Reporting depth follows what your Google edition exposes through the Admin SDK, not a limit we impose.

GAM

GAM7 or GAMADV-XTD3 — both work.

They are the same codebase. GAM7 is the continuation of GAMADV-XTD3: identical commands, the same config, the same credentials.

  • Already running GAMADV-XTD3? It works unchanged. Nothing to migrate.
  • Starting fresh? Use GAM7 — its Windows binaries are code-signed, which makes antivirus and endpoint protection far less likely to quarantine it.
  • GAMADV-XTD3 was retired by its author in favor of GAM7, and its final release is unsigned.
  • GAM must be fully authorized with OAuth credentials and a service account before ORINEX Workspace can do anything.
Browser & network

How you reach it, and what it reaches.

Browser, on any OS

Chrome 90+ (recommended), Edge 90+, or Firefox 90+ with JavaScript enabled — on macOS, Linux, ChromeOS or Windows. The browser is the entire client; nothing is installed on an administrator's machine. Internet Explorer is not supported.

Ports

The local web server binds to 443, falling back to 5000 if something already holds it. A Workstation install listens on that machine only; a Server install accepts connections from your network.

Served over HTTPS

The interface is served over HTTPS from the machine it runs on — not plain HTTP across your network, and not from anywhere else.

Behind a web proxy or a restrictive firewall, these need to be reachable outbound over HTTPS:

  • www.googleapis.com · admin.googleapis.com
  • accounts.google.com · oauth2.googleapis.com
  • cloudresourcemanager.googleapis.com
  • chromedevicemanagement.googleapis.com

Not sure your environment qualifies?

Send us what you're running and we'll tell you straight — including if the answer is no.