← Google Workspace audit scope

Third-Party Apps & Shadow IT

11 checks · 2 sub-categories

Staff connect apps to Google Workspace in two clicks — an AI note-taker, a PDF converter, a CRM trial. Many of those grants include full read access to Gmail and Drive, they never expire, and they survive password changes and offboarding. Shadow IT is usually the largest untracked data-exposure surface in a small business.

OAuth app governance

  • API access control set to allow-list, not unrestricted

    The single most important shadow-IT control: whether unconfigured third-party apps can access Workspace data by default. We report the current stance per OU.

    • SCuBA GWS.COMMONCONTROLS
    • CIS GW 2.1
    • Essential Eight — Application control (spirit)
  • Inventory of every connected third-party app

    A full list of apps with an active grant, how many users authorised each, and when. This is the section clients are most often surprised by.

  • Apps holding high-risk scopes

    We rank connected apps by the sensitivity of the scopes they hold — full Gmail read/send, full Drive, admin directory, calendar write — rather than by name recognition.

    • Privacy Act APP 11
  • Unsanctioned AI and productivity tools

    AI assistants that ingest mail and documents are the fastest-growing category of shadow IT. Every AI-category grant is called out explicitly with the data it can reach.

  • Grants held by suspended or departed users

    An OAuth token issued to a departed employee's account can keep working. We list active tokens on inactive accounts.

  • Domain-wide delegation grants reviewed

    Domain-wide delegation lets a service account impersonate any user in the domain. Every delegated client ID and its scopes are enumerated and justified.

    • Essential Eight — Restrict administrative privileges

Marketplace, add-ons and scripts

  • Google Workspace Marketplace install policy

    We check whether users can install any Marketplace app themselves, only allow-listed apps, or none without admin approval.

    • CIS GW 2.2
  • Editor add-ons and Apps Script exposure

    Apps Script projects can move data on a schedule with no user present. We check script execution policy and flag scripts running with broad scopes.

  • Less secure app access disabled

    Legacy password-only app access bypasses 2SV entirely. We confirm it is off domain-wide.

    • CIS GW 1.4
  • App passwords and service account keys

    Standing app passwords and long-lived service account keys are credentials nobody rotates. Both are inventoried.

  • Chrome extension exposure on managed browsers

    Extensions read everything on a page, including webmail. Where Chrome management is in use, we report extension policy and high-risk installed extensions.

Want to know where you actually stand?

Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.