Third-Party Apps & Shadow IT
11 checks · 2 sub-categories
Staff connect apps to Google Workspace in two clicks — an AI note-taker, a PDF converter, a CRM trial. Many of those grants include full read access to Gmail and Drive, they never expire, and they survive password changes and offboarding. Shadow IT is usually the largest untracked data-exposure surface in a small business.
OAuth app governance
API access control set to allow-list, not unrestricted
The single most important shadow-IT control: whether unconfigured third-party apps can access Workspace data by default. We report the current stance per OU.
- SCuBA GWS.COMMONCONTROLS
- CIS GW 2.1
- Essential Eight — Application control (spirit)
Inventory of every connected third-party app
A full list of apps with an active grant, how many users authorised each, and when. This is the section clients are most often surprised by.
Apps holding high-risk scopes
We rank connected apps by the sensitivity of the scopes they hold — full Gmail read/send, full Drive, admin directory, calendar write — rather than by name recognition.
- Privacy Act APP 11
Unsanctioned AI and productivity tools
AI assistants that ingest mail and documents are the fastest-growing category of shadow IT. Every AI-category grant is called out explicitly with the data it can reach.
Grants held by suspended or departed users
An OAuth token issued to a departed employee's account can keep working. We list active tokens on inactive accounts.
Domain-wide delegation grants reviewed
Domain-wide delegation lets a service account impersonate any user in the domain. Every delegated client ID and its scopes are enumerated and justified.
- Essential Eight — Restrict administrative privileges
Marketplace, add-ons and scripts
Google Workspace Marketplace install policy
We check whether users can install any Marketplace app themselves, only allow-listed apps, or none without admin approval.
- CIS GW 2.2
Editor add-ons and Apps Script exposure
Apps Script projects can move data on a schedule with no user present. We check script execution policy and flag scripts running with broad scopes.
Less secure app access disabled
Legacy password-only app access bypasses 2SV entirely. We confirm it is off domain-wide.
- CIS GW 1.4
App passwords and service account keys
Standing app passwords and long-lived service account keys are credentials nobody rotates. Both are inventoried.
Chrome extension exposure on managed browsers
Extensions read everything on a page, including webmail. Where Chrome management is in use, we report extension policy and high-risk installed extensions.
Want to know where you actually stand?
Every one of these checks runs as part of a single point-in-time, read-only audit, delivered as a plain-English, risk-prioritised report.